Cross-Domain Group Membership Requirements in Active Directory for CA Identity Manager
search cancel

Cross-Domain Group Membership Requirements in Active Directory for CA Identity Manager

book

Article ID: 219428

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article explains a product limitation when managing cross-domain group membership in CA Identity Manager. When domains belong to the same forest, specific Active Directory (AD) group types are required to allow users to be added to groups in different domains.

Environment

Identity Manager 14.x

Cause

In a cross-domain configuration (where domains belong to the same AD forest), CA Identity Manager has a technical limitation regarding group membership management. Specifically, Active Directory requires the use of Universal groups for cross-domain group membership.

Resolution

  1. Identify Requirement: Ensure the AD group you are attempting to modify across domains is configured as a Universal group.
  2. Unsupported Configuration: Global AD groups are not supported for cross-domain membership within the same forest in this scenario.
  3. Verify AD Scope: If you are unable to add/remove a user from a group, verify the group scope in Active Directory Users and Computers (ADUC) to ensure it is set to Universal.
  4. Product Support: If your business requirements necessitate the use of Global groups across domains, please submit an Enhancement Request via the Broadcom Product Management portal.