Chat now with support
Chat with Support

Active Roles 8.1.1 - Synchronization Service Administration Guide

Synchronization Service overview Deploying Synchronization Service Getting started Connections to external data systems
External data systems supported with built-in connectors
Working with Active Directory Working with an AD LDS (ADAM) instance Working with Skype for Business Server Working with Oracle Database Working with Oracle Database user accounts Working with Exchange Server Working with Active Roles Working with One Identity Manager Working with a delimited text file Working with Microsoft SQL Server Working with Micro Focus NetIQ Directory Working with Salesforce Working with ServiceNow Working with Oracle Unified Directory Working with an LDAP directory service Working with an OpenLDAP directory service Working with IBM DB2 Working with IBM AS/400 Working with IBM RACF Working with MySQL database Working with an OLE DB-compliant relational database Working with SharePoint Working with Microsoft 365 Working with Microsoft Azure Active Directory Configuring data synchronization with the SCIM Connector Configuring data synchronization with the Generic SCIM Connector Objects and operations supported by the SCIM Connector Example of using the Generic SCIM Connector for data synchronization
Using connectors installed remotely Creating a connection Renaming a connection Deleting a connection Modifying synchronization scope for a connection Using connection handlers Specifying password synchronization settings for a connection
Synchronizing identity data Mapping objects Automated password synchronization Synchronization history Scenarios of use Developing PowerShell scripts for attribute synchronization rules Using PowerShell script to transform passwords

Scheduling capabilities

You can schedule running synchronization operations and automatically perform them on a regular basis to satisfy your company’s policy and save time and effort.

Extensibility

To access external data systems, Synchronization Service employs special connectors. A connector allows Synchronization Service to read and synchronize the identity data contained in a particular data system. Out of the box, Synchronization Service includes connectors that allow you to connect to the following data systems:

  • Microsoft Active Directory Domain Services

  • Microsoft Active Directory Lightweight Directory Services

  • Microsoft Exchange Server

  • Microsoft Skype for Business Server

  • Microsoft Azure Active Directory

  • Microsoft 365

  • Microsoft SQL Server

  • Microsoft SharePoint

  • Active Roles version 7.4.x, 7.3, 7.2, 7.1, 7.0, or 6.9

  • One Identity Manager version 8.1, 8.0, or 7.0

  • Data sources accessible through an OLE DB provider

  • Delimited text files

  • Generic LDAP Directory service

  • MYSQL Database

  • OpenLDAP Directory service

  • Salesforce

  • ServiceNow

  • IBM DB2 Database

  • IBM RACF Connector

  • IBM AS/400 Connector

  • Oracle Database connector

  • Oracle Database User Accounts connector

  • Micro Focus NetIQ Directory connector

  • Oracle Unified Directory connector

Azure BackSync configuration

In any hybrid environment, on-premises Active Directory objects are synchronized to Azure AD using some means such as Azure AD Connect. When Active Roles is deployed in such a hybrid environment, the existing users and groups' information, such as Azure objectID, must be synchronized back from Azure AD to on-premises AD to continue using the functionality. To synchronize existing AD users and groups from Azure AD to Active Roles, we must use the back synchronization operation.

Back synchronization is performed by leveraging the existing functionality of Active Roles Synchronization Service. Sync workflows are configured to identify the Azure AD unique users or groups and map them to the on-premises AD users or groups. After the back synchronization operation is completed, Active Roles displays the configured Azure attributes for the synchronized objects.

The Azure BackSync Configuration feature allows you to configure the back synchronization operation in Azure with on-premises Active Directory objects through the Synchronization Service Web Interface. The required connections, mappings, and sync workflow steps are created automatically.

When you configure the back synchronization, the Azure App registration is done automatically with the default app ActiveRoles_AutocreatedAzureBackSyncApp_V2.

NOTE: Consider the following when configuring Azure BackSync:

  • In case of an Application not found error, please try the configure back synchronization operation again after some time, since the Azure App synchronization may take some time.

  • If you use the existing back synchronization configuration settings, then the existing default app ActiveRoles_AutocreatedAzureBackSyncApp is used to run the back synchronization workflow. However, it is recommended to use the default app ActiveRoles_AutocreatedAzureBackSyncApp_V2 since it requires reduced administrator privileges. To use the latest Azure App, configure the back synchronization again. For information on how configure the back synchronization, see Configuring Azure BackSync.

  • For the back synchronization to work as expected, the user must have write permissions for edsvaAzureOffice365Enabled, edsaAzureContactObjectId, edsvaAzureObjectID, and edsvaAzureAssociatedTenantId. The user must also have a local administrator privileges where the Active Roles Synchronization Service is running.

Technical overview

The following illustration shows how Synchronization Service synchronizes data between connected data systems.

Figure 1: Synchronization of data between connected systems

Synchronization Service uses Capture Agents, connected data systems, connectors, connections, and sync workflows to synchronize identity data.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating