I have an AD group and an application which is AD authenticated. Collecting entitlements for accounts is easy, but in case that I want to collect entitlements for groups I have to define the membership. From the Application DB I can only get the name of the group and the entitlement for it.(There can be multiple entitlements for one group.)
For a workaround I have an idea to create an interface which insert this data to a custom table in the AVDB and after that I'd collect from that table and from T_GROUP_MEMBERSHIP.
Is there any best practice for this case?
Thanks in advance,