AD User SID Resolution
Active Directory Planning
Resolving Active Directory SIDs to friendly user and group names relies on the PowerScale Authentication providers configured on each cluster. This same resolution mechanism is used by every Superna product that runs on the ECA — it's not specific to any single feature.
For how AD group membership and multi-domain trust relationships affect lockout scope specifically, see AD Lockout Planning.