The incremental sync with AD does not play well with duplicate groups. For example:
- Set up an AD with multiple groups with the same CN.
- Do a full sync. Note the group is ignored because the sync detects multiple groups (as was implemented in
- Add a user to one of the groups and do and sync again.
- (BUG) The group you changed will now appear in Crowd.
The problem is that the incremental sync will only see the group that changed and incorrectly assume that there is now only one group.
- Restart crowd and sync again. This will be a full sync.
- The group will have again disappeared from Crowd because the full sync again detects the duplicate groups.
So basically when Crowd does a full sync it will make a duplicate group disappear. However, the duplicate group may appear if one of the two groups is changed before an incremental sync.