If you create a new AD user account, and the account belongs to a group account that is mapped to Crystal Enterprise, ensure that you update the user list by clicking Update in the Windows AD tab found in the Authentication management area. Note that you must click Update to ensure that new users are imported properly. For information on viewing AD users and groups, see Viewing mapped AD users and groups in Crystal Enterprise.
User accounts are automatically created for AD users who are added to an AD group when these users successfully log on to Crystal Enterprise.
Adding an AD group account to a mapped AD group
When you add an AD group account to an AD group that was previously mapped to Crystal Enterprise, and you would like the users of this nested group to get imported into Crystal Enterprise, you need to click Update in the Windows AD tab (found in the Authentication management area).
Note: The nested AD group will not get mapped to Crystal Enterprise by this operation.
Disabling an AD user account
If you disable an AD user account (using Windows Administrative Tools), and that AD user account is mapped to Crystal Enterprise, the user will not be able to log on to Crystal Enterprise. However, if the user has any other valid alias or aliases, the user can log on using the respective authentication method (for example, Enterprise authentication).