<html><body><font face=".AppleSystemUIFont"><span style="font-style:normal">I see some short discussions from years past, but am hoping for updates with greater clarity.</span></font><div><font face=".AppleSystemUIFont"><span style="font-style:normal"><br></span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">Do you search nested groups in Active Directory to obtain all group memberships for users?</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">2017 exchange in this list described use of <span style="color:rgb(36,39,41)">LDAP_MATCHING_RULE_IN_CHAIN matching rule (OID 1.2.840.113556.1.4.1941)</span> </span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">(<a href="https://shibboleth.1660669.n2.nabble.com/AD-nested-groups-td7634561.html">https://shibboleth.1660669.n2.nabble.com/AD-nested-groups-td7634561.html</a>)</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">but noted “it’s very slow”, a verdict echoed in multiple other sites.</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal"><br></span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">I have one service asking to receive group memberships including memberships implied by nested AD groups,</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">but am wary of using <span style="color:rgb(36,39,41)">1.2.840.113556.1.4.1941 from the sparse information I have found.</span></span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal"><span style="color:rgb(36,39,41)">e.g., </span></span></font><a href="https://stackoverflow.com/questions/6195812/ldap-nested-group-membership">https://stackoverflow.com/questions/6195812/ldap-nested-group-membership</a></div><div>       <a href="https://stackoverflow.com/questions/40024425/1-2-840-113556-1-4-1941-ldap-matching-rule-in-chain-has-performance-problems">https://stackoverflow.com/questions/40024425/1-2-840-113556-1-4-1941-ldap-matching-rule-in-chain-has-performance-problems</a></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal"><br></span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">Are IdP’s regularly using this technique to retrieve implied group members?</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">An alternative strategy (explicit iteration in some script, say)?</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">Relying only on direct group memberships or eduPersonEntitlement or other “flattened” source for entitlements?</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal"><br></span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">If you do return implicit group memberships via LDAP query to AD, can you provide details?</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">(My attempt to implement in Apache Directory Studio robustly returns no results.)</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal"><br></span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">David St.Pierre Bantz</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal">UA OIT IAM</span></font></div><div><font face=".AppleSystemUIFont"><span style="font-style:normal"><br></span></font></div><div><br></div></body></html>