If you have sync workflows configured and run by Quick Connect (the predecessor of ), or earlier versions of Active Roles , then you can transfer those sync workflows to the current version of Active Roles .
You can transfer sync workflows from the following Quick Connect or Active Roles versions:
-
Quick Connect for Active Directory 6.1
-
Quick Connect for AS400 1.4
-
Quick Connect for Base Systems 2.4
-
Quick Connect for Cloud Services 3.7
-
Quick Connect for RACF 1.3
-
Quick Connect Sync Engine 5.5 and 6.1
-
7.5 and later
For more information, see Transferring sync workflows from Quick Connect in the Active Roles Administration Guide.
To transfer sync workflows from Quick Connect to
-
Install .
You can install on the computer running Quick Connect or on a different computer. For installation instructions, see Installing Synchronization Service.
-
Configure to use a new database for storing configuration settings and synchronization data.
To perform this step, use the Configuration Wizard that appears when you start the the first time after you install . For more information, see Configuring Synchronization Service.
-
Import configuration settings from Quick Connect or .
Before you proceed with this step, it is highly recommended to disable the scheduled workflows and mapping operations in Quick Connect or earlier versions of . You can resume the scheduled workflows and mapping operations after you complete this step.
To import configuration settings:
-
On the computer where you have installed , start the .
-
In the upper right corner of the Active Roles window, click the gear icon, and then click Import Configuration.
-
In the wizard that appears, select the version of Quick Connect Sync Engine used by your Quick Connect version or Active Roles from which you want to import the configuration settings.
Optionally, you can select the Import sync history check box to import the sync history along with the configuration settings.
-
Follow the steps in the wizard to complete the import operation.
If the synchronization data you want to import is stored separately from the configuration settings, then, on the Specify source SQL Server databases step, select the Import sync data from the specified database check box, and specify the database.
-
Retype access passwords in the connections that were imported from Quick Connect.
NOTE: Re-entering passwords in the imported connections is required because due to security reasons, the configuration import process does not retrieve encrypted passwords from Quick Connect. To modify the imported connections later, use the . For more information, see External data systems supported with built-in connectors.
-
If your sync workflows involve synchronization of passwords, then you need to install the new version of Capture Agent on your domain controllers. For installation instructions, see Managing Capture Agent.
The new version of Capture Agent replaces the old version. However, as the new version supports both and Quick Connect, you do not lose the password synchronization functions of Quick Connect after you upgrade Capture Agent.
Active Roles uses the following default communication ports. To make sure that the specific traffic type works as intended, open the following ports on the machine running Active Roles .
For more information on opening ports, see the instructions of the Windows Defender Firewall with Advanced Security console of your operating system, or the documentation of your network device.
Port required for traffic
Port required for DNS traffic
Port required for Kerberos traffic
Ports required for SMB / CIFS traffic
-
Port 139, TCP, Inbound / Outbound.
-
Port 445, TCP, Inbound / Outbound.
Ports required for LDAP traffic
-
Port 389, TCP / UDP, Outbound.
-
Port 3268, TCP, Outbound.
Ports required for SSL traffic
-
636, TCP, Outbound.
-
3269, TCP, Outbound.
NOTE: This port is only required if is configured to use SSL to connect to an Active Directory domain.
Ports required for Active Roles Capture Agent traffic
If is configured to synchronize user passwords from an Active Directory domain to other connected data systems, open the following port on the DC where the Capture Agent is installed.
Port required for RPC endpoint mapper traffic
Deploying Synchronization Service for use with AWS Managed Microsoft AD
NOTE: This feature is officially supported starting from Active Roles Synchronization Service 8.1.3 SP1 (build 8.1.3.10). It is not supported on Active Roles Synchronization Service 8.1.3 (build 8.1.3.2) and earlier versions.
Active Roles supports deployment and configuration in the Amazon cloud to manage AWS Managed Microsoft AD object synchronization.
This allows you to:
-
Synchronize directory data from an on-premises AD environment to AWS Managed Microsoft AD.
-
Synchronize passwords from an on-premises Active Directory to AWS Managed Microsoft AD (with certain limitations).