Updating Group logins on SharePoint 2013 using Active Directory Sync


I am using on-premises SharePoint 2013. We are currently using Active Directory Profile Sync. We are using security groups in AD to manage our security in SharePoint 2013. I am trying to rename a group in AD and found that this does not rename a group in SharePoint 2013. I would rather rename the group rather than having to change over 100 entries across SharePoint.

I attempted using the command stsadm -o migrategroup -oldlogin DOMAIN\Username -newlogin DOMAIN\Username

It reports Completed Successfully, but alas! no change.

What am I missing?
Who is Participating?
Walter CurtisSharePoint AEDCommented:
Thanks for the expanded explanation. Here is a quick overview. It is hard to give a full answer in the space allowed here.

The quickest way is to simply use people picker and add the AD group (again) with the new name. Depending on your site structure, if you have inherited or granular permissions, this could be easy, complicated or someone in between. As far as profile editor, that might not be the level you want to manage user permissions at.  

Hope that helps some
Walter CurtisSharePoint AEDCommented:
An AD group is just a member of a specific SharePoint group. The AD security group and the SharePoint group can have different names. There are no links between the groups, so if one name changes the other one does not automatically change. You can manually change either group name as you see fit.

A little deeper, the SharePoint group name is actually a description field. SharePoint uses a group ID for internal processes. As far as the stsadm command, unless I misunderstand your questions, is not necessary.

Hope that helps
ALC-ITOfficerAuthor Commented:
Thank you for your comments.
let me clarify. I have a Group for example called DOMAIN\Group1 (group1@email.com)
I want to change it to DOMAIN\Group2
I rename the Group in AD, by right clicking the name and selecting rename
So I change to DOMAIN\Group2 (group2@email.com).

But When I return to SharePoint, I find that nothing has changed at all. meaning if I open the user group Group1 it still has all group1 details assigned to it. When I go in to SharePoint and attempt to edit the record, I can only change the display name.

If I use the Central admin profile editor (grasping at straws) and I cant find either group.

Does that clarify it for you ?
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.