Skip to content

Commit

Permalink
MAN: Add note about AD Group types
Browse files Browse the repository at this point in the history
Linux admins/users may not know that the AD distribution group type
is intended only for email. Per microsoft: Distribution groups are
not security enabled, which means that they cannot be listed in
discretionary access control lists (DACLs).
  • Loading branch information
justin-stephenson committed Jul 14, 2022
1 parent f9d3658 commit fe284e7
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions src/man/sssd-ad.5.xml
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,10 @@ ldap_id_mapping = False
case-insensitive in the AD provider for compatibility with Active
Directory's LDAP implementation.
</para>
<para>
SSSD only resolves Security-enabled Active Directory group types.
(e.g. Not <quote>distribution</quote> groups)
</para>
</refsect1>

<refsect1 id='configuration-options'>
Expand Down

0 comments on commit fe284e7

Please sign in to comment.