On Пан, 24 чэр 2024, Ronald Wimmer via FreeIPA-users wrote:
Is there a way for preventing AD domain-local groups from being mapped into IPA? From time to time colleagues try to use AD groups with scope 'domain local'. Personally, I do not see a use case for these groups mapped into IPA...
There is no way to prevent those, at least right now. SSSD does not give us a type of a group when group is requested. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
