Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 16 Next »

 

The Active Directory Sync will pull computer names and users into Arellia Management Server (AMS). To sync the Active Directory, do the following steps:

  1. Define Credentials
  2. Select Active Directory Domains
  3. Sync Active Directory

Define Credentials

Back to top

Verify that the Default User Credential account has access to read from the domain. If it does not, then create a new user credential that has access by doing the following steps:

  1. In the Arellia Security Manager, click the Configuration tab.
  2. In the file library in the left pane, navigate to Settings > Foreign Software Systems > User Credentials.
  3. In the right pane, click New > User Credential.
  4. In the New User Credential dialog box, enter an Account name and domain Password.
  5. Click Save.

Select Active Directory Domains

Back to top

To select Active Directory Domains, do the following steps:

  1. In the Arellia Security Manager, click the Configuration tab.
  2. In the file library in the left pane, navigate to Settings > Foreign Software Systems > Foreign Software System Types > Active Directory Domains.
  3. In the right pane, click New > Active Directory Domain.
  4. In the Create Item dialog box, enter a DNS name and domain Password.
  5. Click Save.

  6. Then specify the FQDN of the Domain and select the Default User Credential, or a custom credential to use to access the domain.

Sync Active Directory

Back to top

The LDAP Directory Synchronize Task will import and synchronize Active directory resources such as users, computers, containers, and organizational units into AMS. 

Default Synchronize Directory

The Default Synchronize Directory task will import and synchronize users, containers, and organizational units into AMS. 

  1. Open the Tasks tab in Arellia Security Manager console.
  2. On the left expand the Jobs and Tasks section.
  3. In the tree navigate to Jobs and Tasks > Server Tasks > Directory Services > Default Synchronize Directory.
  4. On the right click the Run Now... button.
  5. Select a directory to sync and optionally a directory partner and click Run Now to begin.

 

When left empty the default Query value is (|(&(objectclass=user)(objectcategory=person)(!(sAMAccountType=805306370)))(objectcategory=group)(objectCategory=container)(objectCategory=organizationalUnit))

Active Directory Organizational Views

After the Default Synchronize Directory executes and is closed you can view the imported and synchronized objects. 

  1. Open the Resources tab in Arellia Security Manager console.
  2. On the left expand the Resources section.
  3. In the tree navigate to Organizational Views > Active Directory Domains > (Your Domain).

[[smg 08/04/2015 - The image below shows our domain name, names of computers in our domain, some group names, and my name.  May want to run this by Kevin and Michael to see if this is OK to disclose publicly.]]

 

To avoid excessive data only top-level containers such as Computers and Users are imported.

Default Synchronize Directory Computers

The Default Synchronize Directory Computers task will import and synchronize Active Directory computers into AMS.

  1. Open the Tasks tab in Arellia Security Manager console.
  2. On the left expand the Jobs and Tasks section.
  3. In the tree navigate to Jobs and Tasks > Server Tasks > Directory Services > Default Synchronize Directory Computers.
  4. On the right click the Run Now... button.
  5. Select a directory to sync and optionally a directory partner and click Run Now to begin.

After the task executes and is closed you should find Active Directory computers in the Organization Views as described above. 

You can create a new LDAP Directory Synchronize Task by right-clicking the Directory Services folder and selecting New > Tasks > LDAP Directory Synchronize Task.

  • No labels