Skip to main content
Question

Problem restricting policy scope by Active Directory group

  • April 4, 2011
  • 1 reply
  • 0 views

Forum|alt.badge.img+5

I'm working on setting up a self-service policy that I'd like to have scoped by machine group and Active Directory group — more specifically, a list of machines (created via JSS) allowed to have the package installed, and a list of users (pulled from Active Directory) allowed to install the software.

Everything works properly as long as no AD group is specified. Everything works properly as long as a small AD group is specified. But when the group passes a certain undetermined size, the policy no longer works, and Self Service doesn't show the package. For instance, it'll work if I specify that only the AD group for lab administrators is allowed to install it. But if I broaden it to our "all employees" group, it fails.

Have I missed something obvious, or is there something I should be doing another way?

Brian

1 reply

bentoms
Forum|alt.badge.img+35
  • Legendary Contributor
  • 4331 replies
  • April 4, 2011

Sadly the jss will not see nested AD groups. I.e groups within groups.

So this could be the issue for you?

Regards,

Ben.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings