Working with Central Directory Service (CDS) Account Groups

University resources are provisioned to groups, not individual accounts, wherever possible. Pitt runs two group systems: Central Directory Service (CDS) groups in Enterprise Active Directory, and Office 365 groups in Microsoft 365. Both appear in the global address list, but they're managed very differently — CDS groups are set up by your unit's RC Administrator and stay centrally governed, while Office 365 groups are created and managed by any student, faculty, or staff member. Pitt Digital recommends CDS groups as the default for most access and collaboration needs; this article covers how to work with each and when a self-service Office 365 group is the right exception.

Choose Your Group Type

RECOMMENDED

CDS Group

Pitt Digital's default for access and collaboration — file shares, network zones, the PittNet VPN, Outlook resources, mailing lists, and SharePoint, OneDrive, or Teams permissions. Centrally governed by your unit's RC Administrator, and still visible in Office 365 (e.g., the global address list).

Find Your RC Administrator

USE SPARINGLY

Office 365 Group

Self-service, created by any student, faculty, or staff member. Reach for this only for short-lived, low-stakes collaboration, or when you need to add members from outside the University.

Create an Office 365 Group

Still not sure which one you need?
Start with a CDS group from your RC Administrator — it covers file shares, network zones, VPN, Outlook resources, mailing lists, and can be granted SharePoint, OneDrive, and Teams permissions too. Reach for a self-service Office 365 group only when the collaboration is short-lived and low-stakes, or when you need to add people from outside the University, since CDS groups are limited to University accounts.

CDS Groups vs. Office 365 Groups at a Glance

Comparison of CDS groups and Office 365 groups by management, access, and membership
Aspect CDS Group Office 365 Group
Managed By Your unit's RC Administrator, via the Accounts Administration service Any student, faculty, or staff member — self-service
Setup Time Depends on RC Administrator availability Immediate
Provisions Access To PittNet VPN (GlobalProtect), file shares and printers on department servers, Enterprise Web Infrastructure shares, Outlook shared calendars and resource accounts, mailing aliases, and SharePoint, OneDrive, or Teams permissions SharePoint, OneDrive, Teams, Delve, and a mailing list
External Members Not supported — University accounts only Supported — members need any Office 365 account, institutional or personal
Best For Default choice for most access and collaboration — centrally governed and auditable over its lifetime Short-lived, low-stakes collaboration, or projects that must include people outside the University
Note: CDS groups aren't limited to on-premises resources.
Both group types appear in the global address list and can receive mail. Beyond that, a CDS group can also be granted SharePoint, OneDrive, and Teams permissions directly — ask your RC Administrator to add the group to the site, library, or team. Pitt Digital recommends defaulting to a CDS group for most access and collaboration needs, since it's centrally governed by an RC Administrator and stays auditable over time. Reach for a self-service Office 365 group only for short-lived, low-stakes collaboration, or when you need to add members from outside the University.

Managing Each Group Type

Select a group type below for setup and management details.

Just Need to Share Files?

Use OneDrive, not a group.
If your collaboration is limited to sharing files and gathering feedback or comments, you don't need either group type — use Microsoft OneDrive. The University ended its enterprise Box license in August 2022; Box and Dropbox are not University-supported services. See Getting Started with Microsoft OneDrive to get started. If the collaboration grows to need a shared Teams or SharePoint space, ask your RC Administrator for a CDS group rather than creating a separate Office 365 group.

Group Governance Is a Security Control

A group is a standing grant of access. Treat every membership change accordingly — this is what keeps access auditable and prevents unused groups from becoming attack surface.

Treat membership changes as access changes. Adding someone to a CDS or Office 365 group that provisions resource access is an access grant, not a housekeeping task — confirm the requester has authority to add or remove the named individual.
Review membership periodically. Group owners and RC Administrators should review who's still in a group at least annually, and remove anyone whose role no longer requires access.
Remove groups that have outlived their purpose. An orphaned group with stale membership is a routine target once its purpose is forgotten. If a project or team is winding down, decommission its groups instead of leaving them in place.

Troubleshooting

My CDS group doesn't work the way I expected inside Teams, SharePoint, or OneDrive.
A CDS group can be granted SharePoint, OneDrive, and Teams permissions directly — ask your RC Administrator to add the group to the site, library, or team. What a CDS group can't do is stand in for a native Microsoft 365 Group, the object type Teams creates when you build a brand-new Team from scratch, which also drives Planner and the unified group experience. If you're troubleshooting a permission on an existing resource, start with your RC Administrator and the CDS group before assuming you need a separate Office 365 group.

I need a group to include people outside the University.
CDS groups are limited to University accounts. Use an Office 365 group — external members need an Office 365 account of some kind, institutional or personal, but not a University Computing Account.

Print Article

Related Articles (1)

How the University Computing Account governs access to Pitt technology resources through two directory services — the Central Directory Service (CDS) and Enterprise Active Directory. Covers what each service does, who administers them, the Find People directory, and single sign-on to external sites like NIH and Educause via Pitt Passport.