Active Directory group lists a member user, user's entry does not mention the group
I have group G and user U. The entry for G includes U as a "member" record. The entry for U does not include G as a "memberOf" record. (I am querying the entries programmatically, in C#, and viewing them in Softerra LDAP Browser). Can anybody explain this paradox?
memberOfattribute is not authoritative. Whether a group is listed there depends on the "Scope" of the group. It will only include:
- Universal groups in the same AD forest
- Global groups from the same domain as the user
- Domain Local groups on the same domain as the server you are reading from (which may or may not be the same domain as the user)
If you need to find groups that
memberOfdoesn't list, I also wrote an article called Finding all of a user's groups with code samples.