- Free Edition
- Quick Links
- MFA
- Microsoft Entra ID Security
- Self-Service Password Management
- Single Sign-On
- Password Synchronizer
- Password Policy Enforcer
- Employee Self-Service
- Reporting and auditing
- Integrations
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- Exchange Reporter Plus Exchange Server Auditing & Reporting
- EventLog Analyzer Real-time Log Analysis & Reporting
- M365 Manager Plus Microsoft 365 Management & Reporting Tool
- DataSecurity Plus File server auditing & data discovery
- RecoveryManager Plus Enterprise backup and recovery tool
- SharePoint Manager Plus SharePoint Reporting and Auditing
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools
AD group membership controls what users can access, including: shared resources, applications, and email distribution lists. Most organizations route every membership change through the help desk. For example, an employee joins a project and emails IT to get on the distribution list, a role changes and a new set of security group permissions are needed, a contractor's engagement ends but their access persists. These requests accumulate into a constant queue that consumes IT time while leaving group memberships increasingly out of sync with reality. ADSelfService Plus eliminates that bottleneck by letting users subscribe or unsubscribe from AD security and distribution groups on their own, within boundaries IT admins define and control.
What is self-service AD group membership management?
Self-service AD group membership management gives end users a portal to join or leave AD groups without submitting a ticket. Admins retain full control through mail group subscription policies—configurations that specify exactly which groups are visible and available to which users, scoped by domain, OU, or group membership. No user can access a group outside the policy's boundaries.
ADSelfService Plus supports both AD group types eligible for self-service subscription:
Security groups: Used to assign access control permissions to shared resources such as file shares, printers, and applications. When a user joins an AD security group, they gain the user access permissions associated with that group.
Distribution groups: Mail-enabled groups used by Exchange Server to route email to a set of recipients. Self-service subscription lets users opt in to relevant mailing lists and opt out of ones no longer relevant to their role.
Streamlined self-service Active Directory group subscription with ADSelfService Plus
Mail group subscription policies
Admins create named subscription policies that determine which AD groups are available for self-service enrollment. Each policy is scoped to specific domains, OUs, or groups, acting as a security barrier that prevents unauthorized access. Users only see the groups their assigned policy permits. Multiple policies can be configured within a domain; where a user falls under more than one, the highest-priority policy applies.
MFA-protected access
ADSelfService Plus can require users to pass MFA before accessing self-service group management. MFA for self-service actions supports all authenticators available in ADSelfService Plus—including biometrics, FIDO passkeys, TOTP, push notification, and YubiKey—and is configured per policy, so MFA requirements can vary by OU, domain, or group.
Group member visibility
Admins can optionally allow users to view the current members of any group they are eligible to join. This gives users enough context to choose the right group before subscribing, reducing erroneous requests. The setting is toggled per subscription policy and is off by default.
Optional approval workflow
For organizations that want governance over group membership changes without routing every request back through IT, ADSelfService Plus integrates with ManageEngine ADManager Plus to enable an approval-based workflow. When enabled, a user's subscription or unsubscription request is raised as a ticket in ADManager Plus rather than applied directly to AD. The approval workflow gates self-service rather than eliminating it, the user experience remains intact, but each change takes effect only after a help desk technician reviews and approves it in ADManager Plus.
Group membership change records
When the approval workflow is enabled, ADManager Plus records every group membership request, who submitted it, which group was involved, who approved or rejected it, and when. This audit trail supports IAM governance requirements and periodic access reviews relevant to compliance frameworks such as ISO 27001:2022. For organizations not using the approval workflow, the policy configuration itself serves as a documented access control record, defining which groups each user segment is permitted to subscribe to.
How self-service group membership management works
Self-service Active Directory group membership can be enabled in ADSelfService Plus through the admin portal. Following configuration users can self-subscribe or unsubscribe from groups through simple steps:
- The user accesses the ADSelfService Plus user portal by completing MFA with the configured authenticators.
- The user then navigates to the Groups tab. If MFA has been configured for self-service actions, the user is required to verify their identity before the Groups tab is accessible.
- The user sees only the groups their assigned policy permits and clicks Subscribe or Unsubscribe on the relevant group.
- If no approval workflow is configured, the group membership is updated immediately and the user gains the associated user access permissions and email routing without delay. If the approval workflow is enabled, the request is queued in ADManager Plus for a help desk technician to review before the change is applied to AD.
Benefits of self-service group subscription with ADSelfService Plus
- Fewer help desk tickets: Users subscribe themselves to the security and distribution groups they need without calling or emailing the help desk.
- Faster access to resources: Once a subscription is active, AD group membership is updated immediately and users gain the associated user access permissions and email routing without delay.
- Group memberships that reflect current roles: Users can join or leave groups as their role changes, reducing access drift without IT having to audit manually.
- Controlled, policy-governed access: Subscription policies ensure users can only join groups they are explicitly authorized for, and the optional approval workflow keeps user access permissions aligned with current roles by routing each request through a help desk technician before any change reaches Active Directory.
- Less inbox noise: Users can unsubscribe from distribution groups that no longer match their role without involving IT.
Frequently asked questions
Policies can be scoped by domain, OU, or group membership. This lets admins precisely target which users see which groups; for example, exposing project-specific distribution groups only see users in the relevant department OU. Policies can also be filtered by user attributes such as department or location. Where a user falls under more than one policy due to overlapping scope, the policy with the highest priority takes effect.
In Active Directory Users and Computers, open a user account and navigate to the Member Of tab, or open a group object and view the Members tab. From PowerShell, Get-ADGroupMember -Identity "GroupName" returns all members of a group, and Get-ADPrincipalGroupMembership -Identity "username" returns all groups a user belongs to. In ADSelfService Plus, users can view their available groups and, where the admin has enabled group member visibility, the current members of those groups, directly from the self-service portal.
Active Directory groups are on-premises objects used to control access to local resources—file shares, printers, and internal applications with membership assigned manually by administrators. Entra ID groups are cloud-native, used to manage access to Microsoft 365 and SaaS applications, and support dynamic membership rules that add or remove users automatically based on user attributes. In hybrid environments the two coexist, with AD groups governing on-premises access and Entra ID groups governing cloud access. ADSelfService Plus's self-service group subscription applies to on-premises AD groups only.
Admins can enable an option on each mail group subscription policy that allows users to view the current members of groups they are eligible to join. This setting is off by default and is configured per policy.
Self-service group membership management is one component of an organization's identity and access management approach. By delegating routine membership decisions to users, within IT-defined policy boundaries, it reduces help desk load, keeps user access permissions current, and gives IT teams more visibility and control over access control permissions across the organization, without requiring them to process every individual request.