Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

How to identify AD-imported groups in SFOS?

Is it somehow possible to identify which groups in SFOS have their source in Active Directory?

To me local and AD groups all look the same on SFOS. Even after export of them as entities.tar.

That makes managing larger environments with local groups and groups imported from AD unnecessarily complicated.



This thread was automatically locked due to age.
Parents Reply Children
  • just wanted to get AD groups, not users. but thanks!

    so SFOS tries to query all local groups against AD and if that does not work, it remains just a local group?

    normally other systems I use make it transparent what are LDAP groups and what are local ones.

    Just find that strange.

  • Essentially we are not sending groups to the AD. We are looking up users. AD will give us the result of all AD groups. And we match those results against the Groups on the firewall. The advantage is, we can move groups and objects between all facilities without locking it. 

    __________________________________________________________________________________________________________________