How to Synchronize Nested AD Group Users from an RSA SecurID Access Identity Source
Originally Published: 2017-11-27
Article Number
Applies To
Issue
For example, say the search filter is:
(&(objectCategory=Person)(sAMAccountName=*)(objectClass=user)(mail=*)(memberOf=CN=ParentGroup,CN=Users,DC=example,DC=com))
and ParentGroup contains a nested group. The users in the nested group will not be synchronized.
Resolution
(&(objectCategory=Person)(sAMAccountName=*)(objectClass=user)(mail=*)(memberOf:1.2.840.113556.1.4.1941:=CN=ParentGroup,CN=Users,DC=example,DC=com))
Notes
Related Articles
The RSA Identity Governance & Lifecycle AD Collector and AD ADC authentication source fail to establish a TLS 1.2 SSL conn… 643Number of Views The Active Directory Account Collector does not collect the AD Domain Users Group in RSA Identity Governance & Lifecycle 223Number of Views Incomplete Collection of AD Groups in RSA Identity Governance & Lifecycle 52Number of Views Access Fulfillment Express (AFX) AD LDAP connector fails to remove AD account with error "Not Allowed On Non-leaf" in RSA … 188Number of Views Cannot synchronize token in RSA Authentication Manager 8.1. 222Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device How to check Microsoft Windows Group Policy Objects (GPOs) for RSA MFA Agents RSA MFA Agent 2.5 for Microsoft Windows Group Policy Object Template Guide RSA-2026-10: RSA Authentication Manager Security Update for Third-Party Component Vulnerabilities RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?