Chat now with support
Chat with Support

Active Roles 7.6.3 - Synchronization Service Administration Guide

Synchronization Service Overview Deploying Synchronization Service Getting started Connections to external data systems
External data systems supported with built-in connectors
Working with Active Directory Working with an AD LDS (ADAM) instance Working with Skype for Business Server Working with Oracle Working with Exchange Server Working with Active Roles Working with One Identity Manager Working with a delimited text file Working with Microsoft SQL Server Working with Micro Focus NetIQ Directory Working with Salesforce Working with ServiceNow Working with Oracle Unified Directory Working with an LDAP directory service Working with IBM DB2 Working with IBM AS/400 Working with an OpenLDAP directory service Working with IBM RACF connector Working with MySQL database Working with an OLE DB-compliant relational database Working with SharePoint Working with Microsoft 365 Working with Microsoft Azure Active Directory Configuring data synchronization with the SCIM Connector Configuring data synchronization with the Generic SCIM Connector
Using connectors installed remotely Creating a connection Renaming a connection Deleting a connection Modifying synchronization scope for a connection Using connection handlers Specifying password synchronization settings for a connection
Synchronizing identity data Mapping objects Automated password synchronization Synchronization history Scenarios of use
About scenarios Scenario 1: Create users from a .csv file to an Active Directory domain Scenario 2: Use a .csv file to update user accounts in an Active Directory domain Scenario 3: Synchronizing data between One Identity Manager Custom Target Systems and an Active Directory domain Scenario 4: Deprovisioning between One Identity Manager Custom Target Systems and an Active Directory domain Scenario 5: Provisioning of Groups between One Identity Manager Custom Target Systems and an Active Directory domain Scenario 6: Enabling Delta Sync mode between One Identity Manager Custom Target Systems and an Active Directory domain Example of using the Generic SCIM Connector for data synchronization
Appendix A: Developing PowerShell scripts for attribute synchronization rules Appendix B: Using a PowerShell script to transform passwords

Modifying an existing connection to Exchange Server

To modify connection settings

  1. In the Synchronization Service Administration Console, open the Connections tab.
  2. Click Connection settings below the existing Exchange Server connection you want to modify.
  3. Expand Specify connection settings option to modify the options it provides.
    • Select the Exchange Server version to which you want to connect. Select the Exchange Server version to which you want to connect.
    • Connect to. Choose how you want to connect to Exchange Server by selecting one of the following:
      • Any available Exchange Server in the forest. Allows you to connect to an Exchange Server computer residing in the Active Directory forest you specify. In the Domain in the forest text box, type the fully qualified domain name (FQDN) of any domain that belongs to the forest that includes the Exchange Server you want to connect to. If you select this option, make sure the account you specify under Access Exchange Server using has sufficient permissions to read the Root Directory Service Entry (rootDFS) and configuration naming context of the forest.
      • Specified Exchange Server. Allows you to connect to the Exchange Server computer whose fully qualified domain name (FQDN) you type in the provided text box.
    • Advanced. Opens a dialog box that allows you to specify advanced options for connecting to Exchange Server and reading and writing Exchange configuration data in Active Directory.
    •  Options related to reading and writing Exchange configuration data in Active Directory:
      • Use default domain controller. Causes Synchronization Service to read and write Exchange configuration data in Active Directory by using the default domain controller defined on the Exchange Server used for the connection.
      • Use specified domain controller. Causes Synchronization Service to read and write Exchange configuration data in Active Directory by using the domain controller whose FQDN is specified in the text box below this option.
      Options related to connecting to Exchange Server:
      • Connect using HTTPS. Select this check box to connect to Exchange Server by using HTTPS.
      • Validate server certificate. Select this check box to validate server certificate on the target Exchange Server.
      • Authentication method. Select an authentication method to access Exchange Server.
    • Access Exchange Server using. Select one of the following access options:
      • Synchronization Service account. Allows you to access Exchange Server in the security context of the account under which the Synchronization Service is running.
      • Windows account.Allows you to access Exchange Server in the security context of the account whose user name and password you type in the provided text box.
    • Test Connection. Click this button to verify the specified connection settings.
  4. When you are finished, click Save.

Exchange Server data supported out of the box

The next table lists the Exchange Server object types supported by the Exchange Server Connector out of the box and the operations you can perform on these objects by using the connector.

 

Table 28: Supported objects and operations 

Object

Read

Create

Delete

Update

ActiveSyncMailboxPolicy

Allows you to read the Mobile Device mailbox policy settings for a specified Mobile Device mailbox policy.

Yes

No

No

No

AddressBookPolicy

Allows you to read data related to address book policies.

Yes

No

No

No

AddressList

Allows you to read data related to a specified address list.

Yes

No

No

No

DistributionGroup

Allows you to read or write data related to a specified distribution group.

Yes

Yes

Yes

Yes

DynamicDistributionGroup

Allows you to read or write data related to a specified dynamic distribution group.

Yes

Yes

Yes

Yes

ExchangeServer

Allows you to read attribute values of a specified Exchange Server.

Yes

No

No

No

GlobalAddressList

Allows you to read data related to a specified global address list (GAL).

Yes

No

No

No

Mailbox

Allows you to read or write data related to a specified mailbox.

Yes

Yes

Yes

Yes

MailboxDatabase

Allows you to read a specified mailbox database object.

Yes

No

No

No

MailContact

Allows you to read or write data related to a specified mail-enabled contact.

NOTE: The Exchange Server Connector cannot create new users in Active Directory. You can create new AD users with the Active Directory Connector.

Yes

Yes

Yes

Yes

MailUser

Allows you to read or write data related to a specified mail-enabled user.

NOTE: The Exchange Server Connector cannot create new users in Active Directory. You can create new AD users with the Active Directory Connector.

Yes

Yes

Yes

Yes

OfflineAddressBook

Allows you to read data related to an offline address book (OAB).

Yes

No

No

No

OrganizationConfig

Allows you to read configuration data of an Exchange organization.

Yes

No

No

No

OwaMailboxPolicy

Allows you to read data related to Microsoft Office Outlook Web App mailbox policies in the Exchange organization.

Yes

No

No

No

PublicFolder

Allows you to read data related to a public folder.

Yes

No

No

No

RoleAssignmentPolicy

Allows you to read data related to a management role assignment policy.

Yes

No

No

No

UmDialPlan

Allows you to read data related to a Unified Messaging (UM) dial plan.

Yes

No

No

No

UmMailboxPolicy

Allows you to read data related to a Unified Messaging (UM) mailbox policy.

Yes

No

No

No

For each of the above-listed Exchange Server object types Synchronization Service provides a number of special attributes that allow you to read and/or write the data related to that object type in Exchange Server. You can access and use these attributes from the Synchronization Service Administration Console (for example, when selecting the source and target attributes you want to participate in the synchronization operation).

The next sections describe the attributes provided by Synchronization Service and explain what data you can read and/or write in Exchange Server by using a particular attribute.

In the next sections:

ActiveSyncMailboxPolicy object attributes

 

Table 29: ActiveSyncMailboxPolicy attributes 

Attribute

Type

Description

Supported operations

ObjectID

Single-valued, string

Gets the unique identifier for a specified object in Exchange Server.

Read

Other attributes provided for the ActiveSyncMailboxPolicy object have the same names and descriptions as parameters of the following Exchange Management Shell cmdlet:

  • Get-ActiveSyncMailboxPolicy

For more information, see the Exchange Management Shell Help topic for this cmdlet.

AddressBookPolicy object attributes

 

Table 30: AddressBookPolicy attributes

Attribute

Type

Description

Supported operations

ObjectID

Single-valued, string

Gets the unique identifier for a specified object in Exchange Server.

Read

Other attributes provided for the AddressBookPolicy object have the same names and descriptions as parameters of the following Exchange Management Shell cmdlet:

  • Get-AddressBookPolicy

For more information, see the Exchange Management Shell Help topic for this cmdlet.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating