Table 7-3 Group entry attribute mapping between Directory Server and Active Directory (continued)

Directory Server

Active Directory

ntGroupId

cn

 

name

 

sAMAccountName

 

 

ntGroupType

groupType

 

 

Table 7-4 Group entry attributes that are the same between Directory Server and Active Directory

cn

member

description

ou

l

seeAlso

7.3.4 Group schema differences between Directory Server and Active Directory

Although Active Directory supports the same basic X.500 object classes as Directory Server, there are a few incompatibilities of which administrators should be aware.

Nested groups (where a group contains another group as a member) are supported and for WinSync are synchronized. However, Active Directory imposes certain constraints as to the composition of nested groups. For example, a global group contain a domain local group as a member. Directory Server has no concept of local and global groups, and, therefore, it is possible to create entries on the Directory Server side that violate Active Directory's constraints when synchronized.

102 Designing synchronization