You can maintain users in nested groups in the LDAP directory service. You may want to use nested groups for organizational purposes and to group similar types of users. Attributes that you maintain at the group level apply to all users within the group.
You may want to group users by the types of privileges they should have in Data Archive. Then, you can assign roles to the group. By default, all users in the group inherit the role assignment. Assigning roles to groups saves time as you avoid individually assigning roles to every user. Note that LDAP security groups are equivalent to Data Archive roles.
Data Archive synchronizes users based on the group that you provide as a parameter when you run the Sync with LDAP Server job. The job reviews all users under the group, including users in nested groups. There is no limit to the number of nested groups that you can have in one group.
For example, you create the following structure in the LDAP directory service:
The ILM Users group includes User 1, User 2, and the ILM Administrator Users nested group. The ILM Administrator Users group includes User 3 and User 4.
When you synchronize the ILM Users group, Data Archive synchronizes User 1, User 2, User 3, and User 4.