Chat now with support
Chat with Support

Active Roles 7.3.1 - Synchronization Service Administrator Guide

Synchronization Service Overview Deploying Synchronization Service Getting started Connections to external data systems
External data systems supported out of the box
Working with Active Directory Working with an AD LDS (ADAM) instance Working with Skype for Business Server Working with Exchange Server Working with Active Roles Working with One Identity Manager Working with a delimited text file Working with Microsoft SQL Server Sample queries to modify SQL Server data Working with an OLE DB-compliant relational database Working with SharePoint Working with Microsoft Office 365 Working with Microsoft Azure Active Directory
Using connectors installed remotely Creating a connection Renaming a connection Deleting a connection Modifying synchronization scope for a connection Using connection handlers Specifying password synchronization settings for a connection
Synchronizing identity data Mapping objects Automated password synchronization Synchronization history Scenarios of use Appendix A: Developing PowerShell scripts for attribute synchronization rules Appendix B: Using a PowerShell script to transform passwords

Rule-based generation of distinguished names

Synchronization Service lets you create flexible rules for generating the distinguished names (DNs) of objects being created. These rules allow you to ensure that created objects are named in full compliance with the naming conventions existing in your organization.

Scheduling capabilities

You can schedule the execution of data synchronization operations and automatically perform them on a regular basis to satisfy your company’s policy and save time and effort.


To access external data systems Synchronization Service employs special connectors. A connector enables Synchronization Service to read and synchronize the identity data contained in a particular data system. Out of the box, Synchronization Service includes connectors that allow you to connect to the following data systems:

  • Microsoft Active Directory Domain Services
  • Microsoft Active Directory Lightweight Directory Services
  • Microsoft Exchange Server
  • Microsoft Skype for Business Server
  • Microsoft Azure Active Directory
  • Microsoft Office 365
  • Microsoft SQL Server
  • Microsoft SharePoint
  • Active Roles version 7.3, 7.2, 7.1, 7.0, or 6.9
  • One Identity Manager version 7.0, or 8.0
  • Data sources accessible through an OLE DB provider
  • Delimited text files

Azure Backsync Configuration

In any hybrid environment, on-premises Active Directory objects are synchronized to Azure AD using some means such as Azure AD Connect. When Active Roles is deployed in such a hybrid environment, the existing users and groups' information, such as Azure objectID, must be synchronized back from Azure AD to on-premises AD to continue using the functionality. To synchronize existing AD users and groups from Azure AD to Active Roles we must use the back-synchronization operation.

Back Synchronization is performed by leveraging the existing functionality of Active Roles Synchronization Service. Synchronization workflows are configured to identify the Azure AD unique users or groups and map them to the on-premises AD users or groups. After the back-synchronization operation is completed, Active Roles displays the configured Azure attributes for the synchronized objects.

The Azure Backsync Configuration feature allows you to configure the backsync operation in Azure with on-premises Active Directory objects through the Synchronization Service Web interface. The required connections, mappings, and sync workflow steps are created automatically.

The Azure App registration is done automatically with the default app name ActiveRoles_AutocreatedAzureBackSyncApp.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating