Feature Request / Dynamic Membership – Request for Refine Results and Custom Reports Support in Set Rule

Feature Request / Dynamic Membership – Request for Refine Results and Custom Reports Support in Set Rule

Subject: Dynamic Membership – Request for Refine Results and Custom Reports Support in Set Rule

Dear Support Team,

We are currently evaluating and implementing the Dynamic Membership feature for security groups in ManageEngine ADManager Plus, using the following path:

Management > Group Management > Create Single Group > Dynamic Membership > Set Rule

However, we have identified a significant functional limitation in the currently available rule configuration mechanism.

When configuring a rule under:

Dynamic Membership > Set Rule > Add Conditions

the available attributes and filtering criteria are considerably more limited than those available under:

Reports > Custom Reports

In our environment, we need to create dynamic security groups whose membership is based, among other criteria, on the location of objects within the Active Directory Organizational Unit (OU) structure.

However, attributes/options that are available in Custom Reports, such as:

  • Distinguished Name;
  • OU Name;
  • other criteria available under Refine Results;

are not available under:

Dynamic Membership > Set Rule > Add Conditions.

We also noticed that although the following option is available within Dynamic Membership:

Advanced Filter > Filter from Report

it does not allow Custom Reports to be selected as a filtering source.


Impact on our environment

Our Active Directory OU structure is an integral part of the operational and administrative architecture of our environment.

For certain security groups, we need dynamic membership to be determined directly based on the object's location within Active Directory, including scenarios where:

  • users located in a specific OU must become members of a specific group;
  • users located in multiple OUs must be included;
  • hierarchical OU and sub-OU structures must be considered;
  • moving a user between OUs should automatically affect the user's applicable group memberships.

The absence of attributes such as Distinguished Name and OU Name, as well as the filtering capabilities available through Refine Results, significantly limits our ability to implement these scenarios using only native ADManager Plus functionality.

There are technical alternatives outside the product, such as PowerShell scripts, scheduled tasks, specific LDAP queries, or external group membership synchronization mechanisms. However, these approaches would represent workarounds and would introduce additional components outside the ManageEngine platform.

For our organization, this approach is not viable within the operational and governance scope of our environment.

Implementing an external workaround would introduce additional complexity, including:

  • development and maintenance of custom code;
  • creation and protection of additional service accounts;
  • additional delegated permissions in Active Directory;
  • credential management;
  • additional infrastructure for execution and scheduling;
  • monitoring and failure handling;
  • logging and auditing mechanisms;
  • handling service or infrastructure outages;
  • testing and validation following Active Directory or ADManager Plus updates;
  • additional internal support responsibilities;
  • increased attack surface;
  • creation of a parallel technical dependency for functionality that we expect to use natively within the licensed product.

Furthermore, an external PowerShell-based or similar solution would need to implement its own group membership synchronization logic, including member additions and removals, state management, idempotency, exception handling, and failure recovery.

In other words, we would effectively be required to implement and maintain externally a significant part of the Dynamic Membership functionality, even though Dynamic Membership is already a feature provided by the product we have licensed.

Within the scope of our operational model and MPT, this additional complexity is not viable.


Primary request

We would like ManageEngine to evaluate implementing, within:

Management > Group Management > Create Single Group > Dynamic Membership > Set Rule

the same filtering capabilities currently available under:

Reports > Custom Reports.

Ideally, we would like the Set Rule interface to include functionality equivalent to:

Refine Results

allowing administrators to use the same attributes, operators, and filtering criteria currently available in Custom Reports.

This would allow Dynamic Membership rules to use criteria such as:

  • Distinguished Name;
  • OU Name;
  • Canonical Name;
  • and other attributes and criteria available through Refine Results.

We believe this would be the most appropriate implementation because it would provide functional consistency between ADManager Plus modules.


Technical rationale

From a software architecture and development best-practices perspective, the filtering logic required to query objects using these attributes and criteria already appears to be implemented and operational within the Custom Reports module.

Therefore, wherever technically feasible, it would be highly beneficial for the Dynamic Membership functionality to reuse this existing capability rather than maintaining different filtering limitations across modules that operate on the same Active Directory objects.

Reusing existing components and logic is an established software development best practice and can provide benefits such as:

  • functional consistency;
  • reduced code duplication;
  • lower maintenance effort;
  • reduced risk of inconsistencies between features;
  • improved administrator experience;
  • simpler future product evolution.

Naturally, we understand that the internal implementation and architecture of these features may differ. However, from a functional perspective, having these criteria available in Custom Reports but unavailable in Dynamic Membership creates a significant limitation for group governance scenarios based on the Active Directory organizational structure.


Second option / alternative implementation

If implementing functionality equivalent to Refine Results directly within:

Dynamic Membership > Set Rule

is not feasible in the short term, we would request the following as an alternative:

Please allow:

Advanced Filter > Filter from Report

to support the selection of Custom Reports.

Under this model, an administrator could:

  1. Create and validate a Custom Report;
  2. Configure all required filters and criteria;
  3. Use that Custom Report as the object source for a group's Dynamic Membership.

This approach would allow the existing ADManager Plus reporting and filtering capabilities to be reused directly.


Preferred implementation order

Our preferred implementation would be:

Option 1 — Preferred

Add functionality equivalent to:

Refine Results

directly within:

Management > Group Management > Create Single Group > Dynamic Membership > Set Rule

with access to the same attributes and filtering criteria currently available in Custom Reports.

Option 2 — Alternative

Allow:

Advanced Filter > Filter from Report

to support Custom Reports as a source for Dynamic Membership.


We kindly request that this issue be evaluated both as a support inquiry and as a Feature Request / Enhancement Request for the product.

We would also appreciate clarification on the following points:

  1. Is this limitation intentional in the current Dynamic Membership design?
  2. Is there an officially supported method to use OU-based criteria, Distinguished Name, or equivalent attributes within Dynamic Membership?
  3. Is there any planned enhancement on the ADManager Plus roadmap to expand the filtering capabilities available for Dynamic Membership?
  4. Can ManageEngine evaluate adding Refine Results or Custom Reports support to this workflow?

We are available to provide additional examples of our OU structure and membership requirements if they would assist with the technical evaluation.

Kind regards,