This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Unable to use multiple AD groups for web filtering.

We have created two AD groups 'Allow gmail' & 'Allow facebook' and imported both into Sophos. The user U1 is the member of both groups and the primary group is 'Domain Users' in AD. Then we created two separate web filter policies for  'Allow gmail' & 'Allow facebook'. When the user U1 logon only the 'Allow gmail' is applied and access to facebook is blocked. If we remove U1 from either of the groups, the remaining policy works fine. So, How can keep U1 member of multiple AD groups and apply the corresponding web-filter policy for each group. 



This thread was automatically locked due to age.
  • I added the users to the groups in AD so the XG automatically imports them via STAS and sets group.

     

    Then the web policies kick in as they are applied to the groups.

    The only part you might need to monitor is if a user needs an elevation to a new group as STAS will think he stays in the old so you need to remove the user from Users and get them to log out and back in then STAS picks up the new setting.