Directory groups

Use directory groups as the audience for signatures, policies and licences. Nested groups are resolved in full.

A directory group can be linked to a group in Conbool. The agent then keeps the members current, and everything attached to a Conbool group applies to the right people: a signature template per department, a policy per site, a licence assignment per team.

Pick, do not type

On every run the agent reports the catalogue of existing groups. In Conbool a group is picked from that list, nobody has to type a name or know a DN. The catalogue is a selection list only, and only linked groups are actually synchronised.

Nested groups

Nesting is the rule in practice: a group contains other groups, and those contain the people. The agent resolves this in full. A group with three direct entries can therefore yield seven people.

In Active Directory the domain controller does the resolving, in other LDAP directories the agent does it level by level.

Order within a run

Members are transferred only after the people sync has completed. A run held by the deletion limit therefore writes nothing to groups either.

If the agent cannot find a linked group, it does not report it at all instead of sending an empty list. An empty list would be indistinguishable from "has no members any more" and would silently empty the audience.