Adding Role Conditions Based on an Active Directory Property
You can add an include or exclude role condition based on an Active Directory property.
To create a new role based on Active Directory property:
- Perform the steps in Creating a New Role.
- Open the Conditions tab of the Role Properties dialog box. The Group and OU subtab opens.
- Open the AD Property tab.
- Click Add Condition . The Conditions dialog box opens.
- Select an AD property from the first list, such as Department .
- In the Search field, enter a search term, such as Sales .
- Click Search .
- Select item(s) in the search results list,
- Select either Include Properties or Exclude Properties .
- Click Select .
- Close the Add Conditions dialog box. On the Conditions > AD Property tab, the selected properties are listed.
- In the Operator column, select one of the following options to configure this condition:
- Equal To
- Greater Than
- Less Than
- Contains
- Starts With
- Ends With
- In the Enforcement column, select either Include Property or Exclude Property .
- If desired, select the Apply to OU and child OUs option.
- Click Save Role .
See Also