Manual Chapter : About AD Group Lookup

Applies To:

Show Versions Show Versions

BIG-IP APM

  • 15.0.0
Manual Chapter

About AD Group Lookup

An AD Group Lookup item can branch based on Active Directory group. The item provides one default advanced branch rule expression,
expr
{ [
mcget
{
session.ad.last.attr.primaryGroupID
}] ==
100
}
, as an example.
A branch rule expression can include any populated session variable, such as
session.ad.last.attr.primaryGroupID
,
session.ad.last.attrmemberOf
,
session.ad.last.attr.lastLogon
,
session.ad.last.attr.groupType
,
session.ad.last.attr.member
, and so on. As an example,
expr
{ [
mcget
{
session.ad.last.attr.memberOf
}] contains
"CN=Administrators"
is a valid expression.
An AD Query action can populate the session variables.