question

FAUSSADIERKvin-9090 avatar image
0 Votes"
FAUSSADIERKvin-9090 asked LeoErlandsson commented

Add a user to an non-managed AD Group

Hi

Is it possible to add a user to a non-MIM-managed AD group?

@LeoErlandsson :)

microsoft-identity-manager
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LeoErlandsson avatar image
0 Votes"
LeoErlandsson answered FAUSSADIERKvin-9090 commented

Hi,

Ah, a classic question :) I take it you want to be able to add non managed users to a group managed by MIM?


Well, the first answer is "no". All members that MIM should handle also needs to be managed by MIM.

That being said, there are a couple of work arounds or other best practises:

  • If possible, nest the MIM managed group in another group (that is actually used), and then manually manage the non-managed members in that "parent" group

  • Write a really complex Rule Extension to make MIM ignore non managed users (otherwise, MIM will remove non managed users from the group).

  • Manage the users using e.g. a Workflow from the portal that adds and removes users (this is the way to go if neither user nor group is managed by MIM, but I advice you not to do it).

I advice you to not go the workaround road, trust me, I've been there. It works, but it's tedious.

Actually, the best solution is to start managing the users and the groups in MIM.

Happy Easter!

Br,
Leo


· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thank you Leo :)

0 Votes 0 ·
khajanjoshi avatar image
0 Votes"
khajanjoshi answered LeoErlandsson commented

Cant we use the Generic LDAP Connector to the the user to an AD group if we have the correct privilege's. I haven't explored this but can be tried.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi,

Perhaps this question could use it's own Thread, but yes you can.

But I don't think you should. When connecting to AD use the built in AD Connector preferably.

Br,
Leo

1 Vote 1 ·