Chatta subito con l'assistenza
Chat con il supporto

Identity Manager 9.3 - Administration Guide for Connecting to Active Directory

Managing Active Directory environments Synchronizing an Active Directory environment
Setting up initial synchronization with an Active Directory domain Adjusting the synchronization configuration for Active Directory environments Running synchronization Tasks following synchronization Troubleshooting Ignoring data error in synchronization Pausing handling of target system specific processes (Offline mode)
Managing Active Directory user accounts and identities
Account definitions for Active Directory user accounts and Active Directory contacts Assigning identities automatically to Active Directory user accounts Supported user account types Updating identities when Active Directory user account are modified Automatic creation of departments and locations based on user account information Specifying deferred deletion for Active Directory user accounts and Active Directory contacts
Managing memberships in Active Directory groups Login credentials for Active Directory user accounts Mapping Active Directory objects in One Identity Manager
Active Directory domains Active Directory container structures Active Directory user accounts Active Directory contacts Active Directory groups Active Directory computers Active Directory security IDs Active Directory printers Active Directory sites Reports about Active Directory objects
Handling of Active Directory objects in the Web Portal Basic data for managing an Active Directory environment Configuration parameters for managing an Active Directory environment Default project template for Active Directory Processing methods of Active Directory system objects Active Directory connector settings

Active Directory security IDs

The security ID (SID) is used in One Identity Manager to identify user accounts and groups from other domains. This is required, amongst other things, for synchronizing group memberships of two domains. Furthermore, the SID is used to find access permission at file system level.

Example: Group membership assignment by SIDs

Domain A is synchronized with One Identity Manager. Domain B is not synchronized at first. The domains are in a trust relationship. There are user accounts of domain A and domain B in groups of domain A.

Group memberships are identified when domain A is synchronized. User accounts from domain A are assigned based on their identifier. The SIDs are found for user accounts from domain B and entered in One Identity Manager.

If Active Directory domain B is synchronized at later, the user accounts are identified based on their SIDs and the user accounts are assigned directly to the groups in domain B. The SID is removed from One Identity Manager database.

To display security IDs

  • In the Manager, select the Active Directory > Active Directory SIDs category.

NOTE: When you delete an Active Directory object, a SID entry is created in One Identity Manager.

Active Directory printers

All shared printers of a domain are loaded into One Identity Manager during synchronization and cannot be edited.

To display a printer

  1. In the Manager, select the Active Directory > Printer category.

  2. In the result list, select a printer then select the Change main data task.

The following main data is displayed:

Table 55: Printer main data
Property Description

Printer name

Name of the printer.

Driver

Printer driver identifier.

Active Directory computers

Computer or server to which the printer is connected.

Full server name

Full name of the server to which the printer is connected.

Server

Server's short name.

Port

Printer connection.

UNC name

Universal Naming Convention (UNC) address of the printer.

Location description

Text field for additional explanation.

Description

Text field for additional explanation.

Duplex

Specifies whether double sided printing is supported.

Color

Specifies whether color is supported.

Supports sorter

Specifies whether the printer supports sorting.

Pages per minute

Printer speed in page per minute.

Max. resolution [dpi]

Maximum printer resolution in dpi.

Max. horizontal resolution

Maximum printer resolution along the X-axis (width).

Max. vertical resolution

Maximum printer resolution along the Y-axis (height).

Spare field no. 01 ... Spare field no. 10

Additional company-specific information. Use the Designer to customize display names, formats, and templates for the input fields.

Related topics

Active Directory sites

Sites are a group of computers based on networking information. In Active Directory, sites data is used to control replication between domain controllers.

The information about Active Directory sites is loaded into One Identity Manager during synchronization and cannot be edited.

To display site information

  1. In the Manager, select the Active Directory > Sites category.

  2. Select the site in the result list.

  3. To display a site's server, select the Location overview task.

  4. To display a site's main data, select the Change main data task.

The following main data is displayed:

Table 56: Site main data
Property Description

Name

Site name.

Canonical name

The site's canonical name

Description

Text field for additional explanation.

Location description

Text field for additional explanation.

Forest

The name of the Forest to which this site belongs.

Subnets

IP address range at this site.

Related topics

Reports about Active Directory objects

One Identity Manager makes various reports available containing information about the selected base object and its relations to other One Identity Manager database objects. The following reports are available for Active Directory.

NOTE: Other sections may be available depending on the which modules are installed.

Table 57: Data quality target system report

Report

Published for

Description

Show overview

User account

This report shows an overview of the user account and the assigned permissions.

Show overview including origin

User account

This report shows an overview of the user account and origin of the assigned permissions.

Show overview including history

User account

This report shows an overview of the user accounts including its history.

Select the end date for displaying the history (Min. date). Older changes and assignments that were removed before this date, are not shown in the report.

Show user accounts overview (incl. history)

Container

This report shows all the container's user accounts with their permissions including a history.

Select the end date for displaying the history (Min. date). Older changes and assignments that were removed before this date, are not shown in the report.

Show system entitlements overview (incl. history)

Container

This report shows the container's system entitlements with the assigned user accounts including a history.

Select the end date for displaying the history (Min. date). Older changes and assignments that were removed before this date, are not shown in the report.

Overview of all assignments

Container

This report finds all roles containing identities with at least one user account in the selected container.

Overview of all assignments

group

This report finds all roles containing identities who have the selected system entitlement.

Show overview

group

This report shows an overview of the system entitlement and its assignments.

Show overview including origin

group

This report shows an overview of the system entitlement and origin of the assigned user accounts.

Show overview including history

group

This report shows an overview of the system entitlement and including its history.

Select the end date for displaying the history (Min. date). Older changes and assignments that were removed before this date, are not shown in the report.

Show entitlement drifts

Domain

This report shows all system entitlements that are the result of manual operations in the target system rather than provisioned by One Identity Manager.

Show user accounts overview (incl. history)

Domain

This report returns all the user accounts with their permissions including a history.

Select the end date for displaying the history (Min. date). Older changes and assignments that were removed before this date, are not shown in the report.

Show user accounts with an above average number of system entitlements

Domain

This report contains all user accounts with an above average number of system entitlements.

Show identities with multiple user accounts

Domain

This report shows all the identities that have multiple user accounts. The report contains a risk assessment.

Show system entitlements overview (incl. history)

Domain

This report shows the system entitlements with the assigned user accounts including a history.

Select the end date for displaying the history (Min. date). Older changes and assignments that were removed before this date, are not shown in the report.

Overview of all assignments

Domain

This report finds all roles containing identities with at least one user account in the selected target system.

Show unused user accounts

Domain

This report contains all user accounts, which have not been used in the last few months.

Show orphaned user accounts

Domain

This report shows all user accounts to which no identity is assigned.

Table 58: Additional reports for the target system

Report

Description

Active Directory user account and group administration

This report contains a summary of user account and group distribution in all domains. You can find this report in My One Identity Manager.

Data quality summary for Active Directory user accounts

This report contains different evaluations of user account data quality in all domains. You can find this report in My One Identity Manager.

Related topics
Related Documents

The document was helpful.

Seleziona valutazione

I easily found the information I needed.

Seleziona valutazione