limit access to active users

Hi Team,

I have set-up birth right AD group at root location so all users who are on-boarded getting added to that group but while applying the setting AD group was added to all inactive users as well.

How can we limit this to only active users?

Parents
  • Former Member
    0 Former Member over 2 years ago

    Hi Ayan,

    Several ways of accomplishing this. First, how and where did you add the AD Group? To a root department, location?

    All in all, I would add the AD group to a business role instead,  then attach a dynamic role to that BR with a query that would exclude inactive users. Or, if you still prefer to stick to the root location solution, I would then check the inheritance setting of inactive users and prevent their AD accounts from group membership.  As I said, there are several approaches.

    Hth!

Reply
  • Former Member
    0 Former Member over 2 years ago

    Hi Ayan,

    Several ways of accomplishing this. First, how and where did you add the AD Group? To a root department, location?

    All in all, I would add the AD group to a business role instead,  then attach a dynamic role to that BR with a query that would exclude inactive users. Or, if you still prefer to stick to the root location solution, I would then check the inheritance setting of inactive users and prevent their AD accounts from group membership.  As I said, there are several approaches.

    Hth!

Children
No Data