No way to exclude contractors from dynamic groups (employeeType not usable?)

Posted by CoffeeAndPowershell@reddit | sysadmin | View on Reddit | 20 comments

Just hit a pretty annoying limitation with dynamic groups.

There’s no straightforward way to exclude freelancers/contractors, because you can’t use the employeeType attribute in the rule.

So even if your directory is clean and employeeType is properly populated (Employee vs Contractor), it’s basically useless here. You end up relying on hacks like domains, departments, or random attributes… which isn’t great and definitely not scalable.

Am I missing something obvious, or is this just how everyone deals with it?