Jenkins is able to resolve individual users from AD and can see external groups, but cannot resolve external group membership. For example,
user1is part of the
User1can be added individually, and the
Developergroup appears to be resolved(shows external group icon in RBAC, for example). When assigning permissions to the
Developergroup, they are not reflected for its members, such as
CloudBees Jenkins Enterprise
Navigate to the AD plugin configuration under
Manage Jenkins -> Configure Global Security. The option Remove irrelevant groups needs to be unchecked. This feature was added in Active Directory plugin version 1.39. It is incompatible with RBAC, as RBAC needs to see every group a user is a member of.