Applies to: All supported Windows platforms.
Question: Can AD builtin groups be used to provision Centrify zone groups? For example, CN=Users,CN=Builtin,DN=domain,DN=com
Answer:Builtin groups cannot be used to provision zone groups as their SIDs are non-domain specific.
Access Manager does not allow zone group provisioning using builtin groups, and they are not displayed in the object picker. If the Centrify ADUC plug-in is enabled, you can attempt to use a builtin group to provision a zone group, however, it will fail with the following error:
Unhandled exception has occurred in your application. If you click Continue, the application will ignore this error and attempt to continue.
Index was out of range. Must be non-negative and less than the size of the collection.
Parameter name: startIndex
This is an expected behavior, since builtin groups cannot be used to provision Unix groups as described above.