LDAP Group Membership as Criteria for Smart Group

mhatch14
New Contributor

Is that possible? I’m looking for a way to scope a policy based on computer or users in a group. Seems like you can do it by creating a group and adding computer names manually, but can you do this by referencing members of an LDAP group? Members being computers or users.

2 REPLIES 2

mm2270
Legendary Contributor III

If your Casper Suite server is connected to your LDAP environment, then when creating your policies, under the "Limit this Policy to the following Users" section, there is a series of radio buttons, One of them states "Assign to Specific User Groups" with a blue link below it to select the User Groups (LDAP) you'd like to limit the policy to. You can choose "Assign to All Computers" for the main computer scope and I believe the LDAP group setting will become the scope limit for it.

Edit: If the above isn't what you're looking for, you may need to explain a little more what you're looking to do.

tkimpton
Valued Contributor II

possibly means this

https://jamfnation.jamfsoftware.com/featureRequest.html?id=2056

i would like to not only limit LDAP user group membership but also MACHINE ldap group membership.

To stop Joe Bloggs from logging in to Self Service on multiple machine and installing the licensed software allocated only for him and not others