cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
893
Views
0
Helpful
4
Replies

Users in multiple AD groups

fermendo
Level 1
Level 1

Hi all,

I have this scenario, hope you can help.

Users in AD, may be members of several groups. I need to create an access policy to users that belong to two groups. For example, if a user belongs to \Internet AND \Privilege then one policy needs to be applied. But if the user only belongs to \Internet then the Global Policy should apply.Also if the user ONLY belongs to \Privilege the Global Policy should be applied. Is there a way to do this?

Also I have a couple of questions:

- If a user is member of several groups, which one is matched when assigning to an access policy?

- If I have a cluster of S360, all appliances must be joined to the domain, is there a problen with all the appliances trying to create the wsa$ account?

Thanks a lot!!!

2 Accepted Solutions

Accepted Solutions

mart.pirita
Level 1
Level 1

As far I know, You can't use multiple AD groups as one identity.

And the higher policy mathes first.

View solution in original post

jowolfer
Level 1
Level 1

All group membership is based on OR not AND, so you are correct that there is no way to do this.

View solution in original post

4 Replies 4

mart.pirita
Level 1
Level 1

As far I know, You can't use multiple AD groups as one identity.

And the higher policy mathes first.

jowolfer
Level 1
Level 1

All group membership is based on OR not AND, so you are correct that there is no way to do this.

Ok, thought so, thanks a lot!!!

pfalgowski
Level 1
Level 1

Hi all.

 

I will be appreciated if someone would tell if something changed in this matter in the new versions of AsyncOS.

Is it possible to achieve such scenario now?

 

Regards,

Peter Falgowski

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: