Synchronize Users in Windows and Blackbaud Groups
When you select Synchronize on the Groups tab, the program gathers a complete list of users in all specified groups and LDAP query results. The role is then updated by adding the users who are not currently assigned to the role and removing users who were previously synchronized but who are not currently in the query results or part of the specified Active Directory group.
Note: Even though you can manually remove a synchronized user, the user is re-added during synchronization if nothing else changes about the user’s membership in the list of Active Directory groups and LDAP queries defined for the system role.
This process can be automated with the RoleSync.exe utility (available in the AdminUtils folder of your program installation) which is a simple command line application that can be used from all common administrative tools (batch files, wscript, at command, etc.). You can use the Windows Scheduled Task Wizard to schedule regular synchronizations via the RoleSync utility.