Dynamic Group Generation2017-05-24 16:40:02
Features Group as Group Sync UnitySync
Do you want to generate Destination Groups or Group Membership based on a Source LDAP single or multi-valued attribute? Here’s how:
- Create a standard LDAP to LDAP connection
- Go to the Custom tab and click on the Raw Config button
- The field-group parameter identifies the source attribute on which to base the dynamic Groups
- You may only specify one attribute, but it may be single valued or multi valued
- If it is multi valued, all values will generate a Destination Group
- Set the field-group attribute:
- The dyn-group-context parameter is used to stamp structure on the dynamically generated Group record in the ldif.txt
- The DN specified must be a valid structure appearing within the scope of Selection DN
- Or if there is no Selection DN, then a valid structure that exists anywhere on the Source
- Set the dyn-group-context attribute:
- On the Source tab, if Source Objects Type ‘Groups’ is not already selected, enable it now
NOTE: Groups must be selected in order to sync a dynamically generated Group. However, this will also sync Source Groups that exist within the scope of the sync. If you do not want other Groups synced, add the following Optional LDAP Query Filter on your Source tab for Group(s) to avoid pulling any Source Groups:
Because the above filter will always be false, no groups will be synced from the source.
- Enable Discovery and Simulation, then run the Connection.
- Review the resulting ldif.txt file.
- The end of the ldif.txt should contain the dynamically generated Group object(s)
- Enable Discovery and Synchronization, then run the connection
- The Sync phase should Add the desired Group(s) with all applicable membership
Of course, if you have any questions about this feature, please contact our Technical Support Team.