# AD Group Domain user every refresh keep adding group

**URL:** <https://developer.sailpoint.com/discuss/t/ad-group-domain-user-every-refresh-keep-adding-group/77112>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [August 19, 2024, 3:20am UTC](https://developer.sailpoint.com/discuss/t/ad-group-domain-user-every-refresh-keep-adding-group/77112 "2024-08-19T03:20:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkumar22](https://avatars.discourse-cdn.com/v4/letter/p/7ea924/32.png) [@pkumar22](https://developer.sailpoint.com/discuss/u/pkumar22)\
**Post date:** [August 19, 2024, 3:20am UTC](https://developer.sailpoint.com/discuss/t/ad-group-domain-user-every-refresh-keep-adding-group/77112/1 "2024-08-19T03:20:39Z")

</div>

HI,

We have below roles and it attached to 3 access profiles, but in AD Network Access profile in side that access we have Domain users entitlement.

As part of birthright role we are assign this role to user, but in Domain users group keep adding into user every refresh, but it is not getting assign to users.

I can see under domain users group parent entitlements list of other groups. Any idea why this groups keep adding.

---

<div class="post-metadata">

**Author:** ![shaileeM](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/shaileem/32/15314_2.png) [@shaileeM](https://developer.sailpoint.com/discuss/u/shaileeM)\
**Post date:** [August 19, 2024, 4:22am UTC](https://developer.sailpoint.com/discuss/t/ad-group-domain-user-every-refresh-keep-adding-group/77112/2 "2024-08-19T04:22:48Z")

</div>

Hi Prasantha,

Please check this post - [Access Profile with Domain Users only - Identity Security Cloud (ISC) / ISC Discussion and Questions - SailPoint Developer Community](https://developer.sailpoint.com/discuss/t/access-profile-with-domain-users-only/56686/5).

It seems this is an observed behavior for Domain User Group. When you are assigning the Role, Domain User group might be set in Primary Group which is not part of the memberOf values. So, every Identity Refresh tries to re-apply the Role/Access Profile.

---

<div class="post-metadata">

**Author:** ![KevinHarrington](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/kevinharrington/32/6776_2.png) [@KevinHarrington](https://developer.sailpoint.com/discuss/u/KevinHarrington)\
**Post date:** [August 19, 2024, 5:02am UTC](https://developer.sailpoint.com/discuss/t/ad-group-domain-user-every-refresh-keep-adding-group/77112/3 "2024-08-19T05:02:10Z")

</div>

In general, don’t add “Domain Users” to a role. It’s typically a primary group for the user so it can’t be removed through a standard removal process, which means you need to do something custom to remove the role from users.

---

<div class="post-metadata">

**Author:** ![schattopadhy](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/schattopadhy/32/8854_2.png) [@schattopadhy](https://developer.sailpoint.com/discuss/u/schattopadhy)\
**Post date:** [August 19, 2024, 5:25am UTC](https://developer.sailpoint.com/discuss/t/ad-group-domain-user-every-refresh-keep-adding-group/77112/4 "2024-08-19T05:25:14Z")

</div>

@pkumar22 you can remove the domain group as it will be added automatically while user gets provisioned

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [October 18, 2024, 5:25am UTC](https://developer.sailpoint.com/discuss/t/ad-group-domain-user-every-refresh-keep-adding-group/77112/5 "2024-10-18T05:25:38Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
