CalGroups to Active Directory (AD) Sync
Table of Contents
Overview and Requirements
The CalGroups-AD Sync feature allows groups to automatically appear in Active Directory (AD) at UC Berkeley. This integration is useful for managing access to Windows-based resources or applications that rely on AD authentication.
Note: SPAs (Special Purpose Accounts) and CalNet Sponsored Guests are not eligible for AD sync.
- Admin Access: You must have administrative access to a CalGroups Org or App folder to manage sync settings.
- Provisioning Request: Access must be enabled for your specific folder space. Request this by emailing calnet-admin@berkeley.edu.
- Member Limit: Standard sync is limited to groups with 3,500 members or fewer. For larger groups, contact CalNet support for a feasibility review.
How to Sync Your CalGroup to AD
- Navigate to your specific group within the CalGroups interface.
- Click the More Actions button in the top right.
- Select Edit Provisioning Info from the dropdown menu.
- Change the selection for Sync to AD Groups to Yes.
- Click Update to save your changes.
Technical Details and Timing
Syncing from CalGroups to AD is "flat." This means the resulting AD group will contain a list of all direct and indirect members, but nested group IDs themselves will not appear as objects within AD.
- Sync Delay: Changes made in CalGroups generally take at least 15 minutes to reflect in Active Directory.
- Identification: When verifying the sync in AD, look for the Group ID rather than the Group Name, as they may differ.
- Removal: To remove a group from AD, toggle the Sync to AD Groups setting back to No.
- Exclusions: Title Code groups are generally excluded from this sync feature.
Privacy and Visibility
Any group synced to Active Directory is visible to anyone with a valid account in AD. Because AD is a shared environment, group memberships can be viewed by other users and administrators.
Privacy Tip: If you need to obscure the purpose of a group for privacy reasons, change the CalGroups Group ID before enabling the sync. The Group ID (not the display name) is what populates the cn and samAccountName fields in AD.