Manifest and Active Directory Group Guidelines

Manifest groups are available to be consumed within Active Directory Services. The purpose of this document is to discuss the differences between Active Directory and Manifest groups, and to explain the benefits of originating your groups in the Manifest system.

Background

A thorough explanation of groups in Active Directory, including group types, scope and best practices, can be found in Campus Active Directory - Security Group Management Recommendation.

Manifest groups that are pushed to Active Directory Services are of the AD global group type.

Benefits of Using Manifest Groups

When to Use Active Directory Groups

Groups that require a scope other than Global should be created in Active Directory. Domain local and Universal groups pertain exclusively to Active Directory security and resource management; as such it is not appropriate to use Manifest groups to fulfill these purposes.

Example Usage

To provision access to a shared resource connected to Active Directory Services, you might follow a procedure like the one below.

  1. Join the resource (i.e. printer, file share) to Active Directory Services
  2. Within Active Directory, create a domain local group
  3. Configure the shared resource within Active Directory to allow access by members of the newly created domain local group
  4. Create a group in Manifest with the users or data-driven groups you wish to access the resource and choose the option to push the group to Active Directory Services
  5. Once the Manifest group has been delivered to Active Directory, add it as a member of the domain local group

By following this procedure, anyone who is a member of the Manifest group will flow into the Active Directory, and will have access to the shared resource. If I new user needs access to the resource, they need only be added to the Manifest group. By taking advantage of Manifest's delegated administration functionality, anyone with the Manifest group's Manager or Administrator role may add new members to the group via the easy-to-use web interface.