CalGroups AD/Active Directory Sync Guide

A knowledge base article about CalGroups AD/Active Directory Sync Guide provided by the UC Berkeley IT Service Hub - Knowledge Portal

CalGroups to Active Directory (AD) Sync

Table of Contents

Overview and Requirements

The CalGroups-AD Sync feature allows groups to automatically appear in Active Directory (AD) at UC Berkeley. This integration is useful for managing access to Windows-based resources or applications that rely on AD authentication.

Note: SPAs (Special Purpose Accounts) and CalNet Sponsored Guests are not eligible for AD sync.

How to Sync Your CalGroup to AD

  1. Navigate to your specific group within the CalGroups interface.
  2. Click the More Actions button in the top right.
  3. Select Edit Provisioning Info from the dropdown menu.
  4. Change the selection for Sync to AD Groups to Yes.
  5. Click Update to save your changes.

Technical Details and Timing

Syncing from CalGroups to AD is "flat." This means the resulting AD group will contain a list of all direct and indirect members, but nested group IDs themselves will not appear as objects within AD.

Privacy and Visibility

Any group synced to Active Directory is visible to anyone with a valid account in AD. Because AD is a shared environment, group memberships can be viewed by other users and administrators.

Privacy Tip: If you need to obscure the purpose of a group for privacy reasons, change the CalGroups Group ID before enabling the sync. The Group ID (not the display name) is what populates the cn and samAccountName fields in AD.