# Sync about 1000 users from AD with nested groups

**URL:** <https://forum.keycloak.org/t/sync-about-1000-users-from-ad-with-nested-groups/31318>\
**Category:** Miscellanaeous\
**Created:** [March 29, 2026, 3:23am UTC](https://forum.keycloak.org/t/sync-about-1000-users-from-ad-with-nested-groups/31318 "2026-03-29T03:23:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreehari\_tummala](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/sreehari_tummala/32/11104_2.png) [@sreehari\_tummala](https://forum.keycloak.org/u/sreehari_tummala)\
**Post date:** [March 29, 2026, 3:23am UTC](https://forum.keycloak.org/t/sync-about-1000-users-from-ad-with-nested-groups/31318/1 "2026-03-29T03:23:22Z")

</div>

Hi All,

1. Keycloak will not show AD nested groups as “child groups” under the parent in the Groups page. AD represents nesting by putting a group’s DN inside another group’s member attribute; it is not an OU/tree hierarchy. Keycloak’s “child groups” view only reflects hierarchical group containers (e.g., OU → CN trees), not AD’s member-of nesting.

2. AD provides a special matching rule that expands nested memberOf references: 1.2.840.113556.1.4.1941 (also called LDAP\_MATCHING\_RULE\_IN\_CHAIN), which can be added to the LDAP filter.

3. Confirmed the new LDAP filter works using ldapsearch, and imported well over 1000 users, however, it also did not work consistently due to timeout issues on the AD side it appears.

4. It managed to import once or twice in keycloak, but sync performance is poor, and does not always work.

Please help us on how to get this working smoothly with optimal performance

thanks in advance!

---

<div class="post-metadata">

**Author:** ![robson90](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/robson90/32/12479_2.png) [@robson90](https://forum.keycloak.org/u/robson90)\
**Post date:** [March 31, 2026, 4:37pm UTC](https://forum.keycloak.org/t/sync-about-1000-users-from-ad-with-nested-groups/31318/2 "2026-03-31T16:37:57Z")

</div>

Hey,

1. Check your LDAP Config and group-to-group mapper Config. There should be a radio button for “preserve inheritance” or “preserve hierarchy”

2. probably your LDAP is then the bottleneck

3. I got this also for a customer. LDAP is slow as they are syncing 20k groups. Group Membership is calculated on the fly.

Dump question, can you bump up the resources of your LDAP?

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/free1/uploads/keycloak/original/1X/eb342909d95cf32cbb7517610022c6a0046a9ffb.png) [@system](https://forum.keycloak.org/u/system)\
**Post date:** [September 27, 2026, 4:38pm UTC](https://forum.keycloak.org/t/sync-about-1000-users-from-ad-with-nested-groups/31318/3 "2026-09-27T16:38:25Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
