You should look at something called LDAP filters. Take a look at the Qlik help page https://help.qlik.com/en-US/sense/3.0/Subsystems/ManagementConsole/Content/use-additional-LDAP-filter-to-retrieve-specif…
Personally I tend not to sync over users to Sense that have not already accesses the system. I only sync ad info on real Qlik Sense users. With this approach I don't need to configure filters on the AD and I don't clutter my user directory with to many users. You can still set your security rules using your Qlik AD groups as all groups and ad information will be fetched when the user logs in the first time.
I have a filter that is limiting which users I sync back from the AD. So that is not the issue.
The question was of those that I do sync is there a way to limit how many groups come back into Qlik?
User A is a member of 40 groups in the AD. Only 3 of those groups are QLIK groups that I care about. Can I do something in the sync that recognizes only the Qlik groups and updates the user in Qlik with only 3 groups instead of all 40?
Hope that makes better sense.
Oh, then I missunderstood your question.
I listened to conversation with a colleague a couple of months ago and I got the impression that it is not possible to limit the AD-group lookups as you are suggestin.
Correct me if I'm wrong joachim.boivie