Nested group restriction configuration

    Applies to:
  • Legacy SecureAuth IdP
Deployment model:
  • On Premises
  • SecureAuth IdP Version Affected: All


    How to configure a SecureAuth Realm that has a Group Restriction enabled to use the Nested group feature.


    Under the data tab Profile Provider Settings section. Select False for “Same As above”

    1. On the Profile Connection Settings section, configure data store connection. The data store
    should contain user information (use the same settings from your Realm 1).
    2. Advanced AD User Check set to True if you wish to check blocked accounts and expired passwords.
    2. Make sure Include Nested groups is checked and “allowed user’s groups” field blank.
    3. Under the Profile Fields section, make sure the “MemberOf” is in the Field column.



    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.


    0 out of 0 found this helpful


    1 comment
    • Hi Justin,
      is this possible for Web Service (Multi Datastore ) ??

      Thank you,

      Comment actions Permalink

    Please sign in to leave a comment.