サポートと今すぐチャット
サポートとのチャット

Identity Manager 8.1.5 - Administration Guide for Active Roles Integration

Active Roles integration

One Identity Manager supports the connection of Active Directory systems through an integrated Active Roles connector. Additional Active Directory relevant functionality, for example, Microsoft Exchange, Office Communication Services or Active Directory Lightweight Directory Service (AD LDS), is not supported through this connector.

One Identity Manager is assumed to be the master in the default configuration of processes and synchronization behavior and is allowed to bypass Active Roles workflows. Default behavior requires an administrative account. Active Roles workflows can still be controlled by the integrated Active Roles connector. You may need to define custom processes in One Identity Manager in order to use this functionality.

NOTE: For more detailed information about applying, managing, and configuring an Active Roles server, see your One Identity Active Roles documentation.

NOTE: This guide only goes into specific features of using the Active Roles Connector. For detailed documentation on managing an Active Directory environment with One Identity Manager, see One Identity Manager Administration Guide for Connecting to Active Directory.

Architecture overview

The following servers are used for managing an Active Directory environment with One Identity Manager and Active Roles:

  • Active Roles server

    Active Roles server that establishes the connection to the Active Directory domain controller. The synchronization server connects to this Active Roles server.

  • Synchronization server

    The synchronization server executes the communication between the One Identity Manager Service and Active Roles. The One Identity Manager Service with the Active Roles connector is installed on this server. Data entries required for synchronization and administration with the One Identity Manager database are processed by the synchronization server. The synchronization server connects to the Active Roles server.

The Active Roles One Identity Manager connector uses the Active Roles ADSI interface for communicating with an Active Roles instance. The Active Roles connector is used for synchronization and provisioning Active Directory. The Active Roles connector connects to an Active Roles instance, which then connects to the Active Directory domain controller.

Figure 1: The synchronization architecture

Migrating data between One Identity Manager and Active Roles

Scenario

You want to manage an Active Directory domain, currently managed by Active Roles, with One Identity Manager. Active Roles Self-Service Manager is not implemented.

Select one of the following editions modules when you install the One Identity Manager database:

  • One Identity Manager Active Directory Edition
  • One Identity Manager

Initial synchronization of Active Directory domains with One Identity Manager must be carried out by the Active Roles connector. All other synchronization is also carried out by the Active Roles connector.

  • Create a synchronization project with the Synchronization Editor by using the default project template for Active Roles.
Scenario

You want to manage an Active Directory domain, currently managed by Active Roles, with One Identity Manager. Active Roles Self-Service Manager is implemented. The functionality should be transferred to the One Identity Manager‘s IT Shop.

Select one of the following editions modules when you install the One Identity Manager database:

  • One Identity Manager Active Directory Edition
  • One Identity Manager

In the One Identity Manager Active Directory Edition, there is direct support for transferal of Active Roles Self-Service Manager functionality to the One Identity Manager's IT Shop. If you are using the One Identity Manager Edition, run the following steps before initial synchronization:

  1. In the Designer, set the "QER | Policy | GroupAutoPublish" configuration parameter.
  2. In the Designer, set the "QER | ITShop | GroupAutoPublish | ADSGroupExcludeList" configuration parameter and specify Active Directory groups which are not to be added automatically to the IT Shop.
  3. In the Designer, set the "TargetSystem | ADS | ARS_SSM" configuration parameter.
  4. Compile the database.

Active Directory domain synchronization with One Identity Manager must be carried out by the Active Roles connector. All other synchronization is also carried out by the Active Roles connector.

  • Create a synchronization project with the Synchronization Editor by using the default project template for Active Roles.
Scenario

You want to manage an Active Directory domain, currently managed by One Identity Manager, with Active Roles. Currently, Active Directory domain synchronization is carried out by the Active Directory connector.

To manage the Active Directory domains with One Identity Active Roles

  1. In the Synchronization Editor, delete the existing synchronization project.
  2. Create a synchronization project with the Synchronization Editor by using the default project template for Active Roles.
Detailed information about this topic

Configuring synchronization with Active Directory using One Identity Active Roles

One Identity Manager supports synchronization with Active Roles versions 6.9, 7.0, 7.2, 7.3.1, 7.3.3, 7.4.1, 7.4.3., and 7.4.4.

To load Active Directory objects into the One Identity Manager database for the first time

  1. Prepare a user account with sufficient permissions for synchronizing in Active Directory.
  2. One Identity Manager components for managing Active Directory environments are available if the TargetSystem | ADS configuration parameter is enabled.

    • In the Designer, check if the configuration parameter is set. Otherwise, set the configuration parameter and compile the database.

    • Other configuration parameters are installed when the module is installed. Check the configuration parameters and modify them as necessary to suit your requirements.
  3. Install and configure a synchronization server and declare the server as a Job server in One Identity Manager.
  4. Transfer of One Identity Manager Self-Service Manager functionality into the Active Directory Active Roles is directly supported in the IT Shop One Identity Manager Edition. If you are using the One Identity Manager Edition, run the following steps before initial synchronization:

    1. In the Designer, set the QER | ITShop | GroupAutoPublish configuration parameter.
    2. In the Designer, set the QER | ITShop | GroupAutoPublish | ADSGroupExcludeList configuration parameter and specify the Active Directory groups that are not to be added automatically to the IT Shop.
    3. In the Designer, set the TargetSystem | ADS | ARS_SSM configuration parameter
    4. Compile the database.
  5. Create a synchronization project with the Synchronization Editor.
Detailed information about this topic
セルフ・サービス・ツール
ナレッジベース
通知および警告
製品別サポート
ソフトウェアのダウンロード
技術文書
ユーザーフォーラム
ビデオチュートリアル
RSSフィード
お問い合わせ
ライセンスアシスタンス の取得
Technical Support
すべて表示
関連ドキュメント

The document was helpful.

評価を選択

I easily found the information I needed.

評価を選択