Trend Micro Automation Center is a central hub for APIs and documentation across Trend Micro products. It offers searchable cross-product APIs and use cases for IT and security teams to automate tasks and improve efficiency.
The Education Portal is a comprehensive learning hub for Trend Micro customers, designed to deepen product and technology expertise through a wide range of curated training modules. Partners are advised to access the Education Portal through the Partner Portal.
The Trend Micro Online Help Center provides customers with comprehensive product information and troubleshooting guidance. It offers general product usage information and in-depth solutions for complex issues.
Trend Micro Service Status Portal provides real-time information on the performance of Trend Micro products. It offers up-to-date incident reports and historical data for monitoring system health.
TrendConnect is a mobile application that provides users with real-time insights into their Trend Micro security environment, including threat alerts and system health assessments.
Cannot query membership information for Domain Users group in Active Directory (AD) server
Views:
This issue is a limitation of Microsoft AD. Instead of using Domain Users as LDAP group, we recommend you to create policies based on User-defined LDAP groups in IWSVA.
Keywords: domain user does not have memberof attribute,ldap query not applicable in domain users,domain users membership info unavailable ,ms ad domain users,LDAP query for domain
Cannot query membership information for Domain Users group in Active Directory (AD) server
Product / Version includes:
Interscan Web Security Virtual Appliance 6.0
,
Interscan Web Security Virtual Appliance 6.5
Last updated:   2025/05/08
Solution ID:   KA-0004553
Category:  
SPEC
,
Configure
,
Troubleshoot
Summary
When you use Microsoft AD as LDAP server to do user authentication, you can set the Domain Users group in policy account.
The Domain Users is a special group in AD. This group can be found through a LDAP query. However, InterScan Web Security Virtual Appliance (IWSVA) cannot obtain membership information for the Domain Users group through LDAP search.
Using the LDAP query tool, you can verify the Domain Users’ LDAP attribute. You will find out that there is no “memberOF” attribute for the Domain Users group.
This issue is a limitation of Microsoft AD. Instead of using Domain Users as LDAP group, we recommend you to create policies based on User-defined LDAP groups in IWSVA.