Previous Topic: Exclude a User or Group from a Policy

Next Topic: Specify AND/OR Relationships between Users/Groups

Allow Nested Groups in Policies

Your LDAP user directories may contain groups that contain other groups. In very complex directories, groups nested in a hierarchy of other groups is one way to organize tremendous amounts of user information. If you enable a policy to search for users in nested groups, any groups contained in a group you add to a policy will be searched when the Policy Server processes the policy. If you do not enable a policy to search nested groups, the Policy Server will only search in the group you specify in the policy, regardless of any nested groups that may exist.

To allow nested groups in a policy that contains an LDAP user directory

  1. In the Policy Dialog, click on the Users tab.

    If the current policy domain contains more than one user directory, the directories appear as tabs contained in the User tab. In the image above, three user directories (Sample WinNT, Sample ODBC, and Sample LDAP) have been included in the policy domain that contains the policy.

  2. Select the Allow Nested Groups check box to enable nested groups searching for the policy.

More information:

Policy Dialog