[resolved I think] 2sv/mfa group inheritance

alexgrutza
Contributor III

For peace of mind, we have an mfa bypass group for users to be in temporarily if they miss the deadline for enforcement of mfa. 

I click on the root of the directory, and the group shows up under the group sections. Does the group permission trickle down to all sub ou's?

I know it can take 24 hours, but just want to make sure I'm not crazy since it wasn't allowing my test account to log in after 5 minutes...

--
CISSP | LinkedIn | @Phyxiis
1 REPLY 1

alexgrutza
Contributor III

I guess you have to go to the specific ou and add the mfa bypass group there and turn the service off. Sub ou's appear to not inherit the mfa bypass group setting at the root

--
CISSP | LinkedIn | @Phyxiis