# LDAP auth - nested groups

**URL:** <https://forums.suse.com/t/ldap-auth-nested-groups/5927>\
**Category:** General\
**Created:** [March 22, 2017, 12:58pm UTC](https://forums.suse.com/t/ldap-auth-nested-groups/5927 "2017-03-22T12:58:00Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bails08](https://avatars.discourse-cdn.com/v4/letter/b/a587f6/32.png) [@bails08](https://forums.suse.com/u/bails08)\
**Post date:** [March 22, 2017, 12:58pm UTC](https://forums.suse.com/t/ldap-auth-nested-groups/5927/1 "2017-03-22T12:58:00Z")

</div>

We want to have an “all users” AD group to allow access to the site. The “all users” group has several sub groups as members. Users are members of appropriate sub groups.

The sub groups will be used to provide specific access to environments.

Trying to prevent our help desk having to login to rancher each time a new group needs access to the site

---

<div class="post-metadata">

**Author:** ![tfiduccia](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tfiduccia/32/2005_2.png) [@tfiduccia](https://forums.suse.com/u/tfiduccia)\
**Post date:** [March 27, 2017, 10:55pm UTC](https://forums.suse.com/t/ldap-auth-nested-groups/5927/2 "2017-03-27T22:55:49Z")

</div>

Currently we do not support nested groups. I opened and enhancement request in github - [https://github.com/rancher/rancher/issues/8317](https://github.com/rancher/rancher/issues/8317).
