This article explains a product limitation when managing cross-domain group membership in CA Identity Manager. When domains belong to the same forest, specific Active Directory (AD) group types are required to allow users to be added to groups in different domains.
Identity Manager 14.x
In a cross-domain configuration (where domains belong to the same AD forest), CA Identity Manager has a technical limitation regarding group membership management. Specifically, Active Directory requires the use of Universal groups for cross-domain group membership.