Be able to configure multiple Domain Groups and local groups for self-service account elevation such that a requesting identity will have a pick list of allowable groups rather than a single statically defined group from the self-service portion of the web application. *This would be configurable on an identity basis.* On the API side, the user would still be limited to those groups but obviously would not have a pick list to choose form which means the API would need to validate the target group based on user permissions and assignments.
Hi! We think what you are requesting should be possible in the product today. When doing self elevation you have to select the management set that the system containing the group exists in. Once selecting the correct management set then you should be able to elevate the user account to the target group. Additionally when adding user from another domain to a group in a 2nd domain, the target Windows group must be either local or domain local group type.
If you need more assistance please reach out to our support group for additional guidance.
If we have mis-interpreted your request please submit some additional clarification.