Restoring a deprovisioned user account
Active Roles provides the ability to restore deprovisioned user accounts. The purpose of this operation, referred to as the Undo Deprovisioning operation, is to roll back the changes that were made to a user account by the Deprovision operation. When a deprovisioned user account needs to be restored (for example, if a user account has been deprovisioned by mistake), the Undo Deprovisioning operation allows the account to be restored to the state it was in before the changes were made.
How to restore a deprovisioned user account
You can restore previously deprovisioned Active Directory user accounts with the Active Roles Console.
To restore a deprovisioned user account
-
In the Console tree, locate and select the folder that contains the user account you want to restore.
-
In the details pane, right-click the user account, then click Undo Deprovisioning.
-
In the Password Options dialog, choose the options to apply to the password of the restored account, then click OK.
For information about each option, open the Password Options dialog, then press F1.
-
Wait while Active Roles restores the user account.
When you click the Undo Deprovisioning command, the operation progress and results are displayed. When the operation is completed, Active Roles displays the operation summary, and allows you to examine the operation results in detail. You can view a report that lists the actions taken during the restore operation. For each action, the report informs about success or failure of the action. In the event of a failure, the report provides a description of the error situation.
Managing user certificates
You can use Active Roles to add or remove digital (X.509) certificates from user accounts in Active Directory. By adding a certificate to a user account you make the certificate (including the public key associated with the certificate) available to other Active Directory users and to Active Directory-aware applications and services.
The certificates added to Active Directory user accounts are referred to as published certificates. Published authentication certificates are used by Active Directory domain controllers during certificate-based authentication. Published encryption certificates can be used to enable access to encrypted contents. For instance, in the case of e-mail encryption, the sender retrieves the recipient’s certificate from the Active Directory user account and uses that certificate to encrypt the email message so that the recipient could decrypt the message by using the private key associated with the certificate. A similar process occurs when you want to allow a given user to read an encrypted file. The certificate retrieved from the user account is used to encrypt the file encryption key so that the file encryption key could be obtained by using the private portion of the user’s certificate to decrypt the encrypted key material.
To view or change the list of digital certificates for a particular user account, open the Properties page for that user account in the Active Roles console or Web Interface and go to the Published Certificates tab. From the Published Certificates tab, you can perform the following tasks:
-
View the list of the certificates published for the user account in Active Directory.
-
Examine each of the published certificates in detail.
-
Add a certificate from the local certificate store (available in the Console only).
-
Add a certificate that is saved in a certificate file.
-
Remove a certificate from the user account.
-
Copy a published certificate to a certificate file.
For each of the certificates that are listed on the Published Certificates tab, you can view the following information:
-
The purposes that the certificate is intended for (available in the Console only).
-
The name of the person or company to which the certificate was issued.
-
The name of the certification authority that issued the certificate.
-
The time period for which the certificate is valid.
-
Additional information about the certification authority that issued the certificate, if available.
-
The list of all X.509 fields, extensions, and associated properties found in the certificate.
-
The hierarchy of certification authorities for the certificate (available in the Console only).
How to manage user certificates
In the Active Roles Console or Web Interface you can use the Published Certificates page to view or change the list of digital certificates that are assigned to a given user account in Active Directory. Digital certificates are used for authentication and secure exchanges of information. A certificate securely binds a public encryption key to the entity that holds the corresponding private key. The Published Certificates page allows you to add or remove digital certificates from the user account.
To add or remove a certificate for a user account using the Active Roles Console
-
Open the Properties dialog for the user account and click the Published Certificates tab.
-
Do the following:
-
Click Add from Store to add a certificate from the local certificate store.
-
Click Add from File to add a certificate that is saved in a certificate file.
-
Select a certificate from the list on the tab and click Remove to remove the certificate.
From the Published Certificates page in the Active Roles Console, you can also view or export any of the certificates listed on that page. Select a certificate from the list, then click View Certificate to examine the certificate in detail or click Copy to File to save a copy of the certificate to a file.
To access the Published Certificates page in the Web Interface, open the General Properties page for the user account and click the Published Certificates tab. From the Published Certificates page in the Web Interface you can:
-
View any of the certificates listed on that page. Click View Certificate to examine the certificate in detail.
-
Add a certificate to the user account from a certificate file. Click Add from File and select the desired certificate file.
-
Remove a certificate from the user account. Select the certificate from the list on the page and click Remove.
-
Save any of the user’s certificates to a file. Select the desired certificate from the list on the page and click Copy to File.