Skip to main content

How To Enforce Users to Create Groups in a Specific OU

Applies To:

Netwrix Directory Manager 11

Business Requirement:

Using the Netwrix Directory Manager portal, users can create groups in any OU in the directory. Is there a way to limit users to create groups in a specific OU?

Solution:

In Netwrix Directory Manager, you can apply policies to security roles, so that role members can use Netwrix Directory Manager in keeping with the policy restrictions.

Netwrix Directory Manager’s New Object policy enables you to restrict role members to create new groups in a specific OU only.

Steps:

  1. In the Netwrix Directory Manager Admin Center portal, click the Identity Stores tab.

  2. On the Identity Stores tab, click on the Triple Dot button and then click Edit to open its properties.

  3. On the Security Roles tab, select the security role you would like to apply the New Object policy to (for example, User).

  4. On the Policies tab, click New Object in the left pane.

  5. Select Groups and click Add.

  6. On the Select Container dialog box, select the container in which role members can create groups (this will be the default OU when creating groups).

    The selected OU appears below the Groups option.

    User-added image

    User-added image

  7. Click OK.

  8. Click Update Security Role and then Save.

Now when members of the security role try to create groups, they will be created in the default OU that you specified in the New Object policy.