This example scenario describes how to set up an Active Roles Synchronization Service server that will perform hourly updates from an HR system (involving a total number of 80,000 users) to Active Roles.
To create a job server for Active Roles Synchronization Service
-
Create a new IP subnet.
-
Install or move a domain controller (DC) to this new subnet.
-
Install Active Roles and Synchronization Service on a new host in this new subnet. The database configuration can either be a new subscriber or it can use an existing database.
-
Prevent Active Roles from publishing its Service Connection Point to ensure no users connect to this instance. For more information, see Knowledge Base Article 4216122 on the One Identity support portal.
-
Configure this Active Roles instance to only use the DC.
-
Navigate to Configuration > Server Configuration > Administration Services, then select the server.
-
Right-click Properties.
-
Select DirSync Servers > Change.
-
Select Only specified Domain Controller and choose the DC that you installed or moved to the subnet.
-
-
Configure Synchronization Service to use this Active Roles instance to perform all workflow steps as required.