Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Fixed
-
None
-
None
Description
if a dynamic group is member of group that does not belong to the same IDP (such as e.g. a local group that is not listed in automembership), the ExternalGroupPrincipalProvider will fail to resolve the inherited membership for external users.
Note that resolving the membership of the dynamic group itself works, but for external members of that dynamic group (i.e. external users) the IDP-boundary crossing membership will not be resolved.