How to Synchronize Nested AD Group Users from an RSA SecurID Access Identity Source
Originally Published: 2017-11-27
Article Number
Applies To
Issue
For example, say the search filter is:
(&(objectCategory=Person)(sAMAccountName=*)(objectClass=user)(mail=*)(memberOf=CN=ParentGroup,CN=Users,DC=example,DC=com))
and ParentGroup contains a nested group. The users in the nested group will not be synchronized.
Resolution
(&(objectCategory=Person)(sAMAccountName=*)(objectClass=user)(mail=*)(memberOf:1.2.840.113556.1.4.1941:=CN=ParentGroup,CN=Users,DC=example,DC=com))
Notes
Related Articles
The Active Directory Account Collector does not collect the AD Domain Users Group in RSA Identity Governance & Lifecycle 218Number of Views The RSA Identity Governance & Lifecycle AD Collector and AD ADC authentication source fail to establish a TLS 1.2 SSL conn… 622Number of Views A change request to remove role access from a user tries to remove AD group (indirect access from role) which no longer ex… 137Number of Views How to selectively challenge users and applications with RSA AD FS agent 1.x 130Number of Views How to verify that RSA Authentication Agent for Windows can perform challenge user lookups across different Active Directo… 437Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.8 Setup and Configuration Guide
Don't see what you're looking for?