Chat now with support
Chat with Support

Identity Manager 8.1.4 - Administration Guide for Connecting to Active Directory

Managing Active Directory environments Setting up Active Directory synchronization Basic data for managing an Active Directory environment
Account definitions for Active Directory user accounts Password policies for Active Directory user accounts Initial password for new Active Directory user accounts Email notifications about login data User account names Target system managers Editing a server
Active Directory domains Active Directory user accounts
Linking user accounts to employees Supported user account types Entering master data for Active Directory user accounts Additional tasks for managing Active Directory user accounts Automatic assignment of employees to Active Directory user accounts Updating employees when Active Directory user account are modified Automatic creation of departments and locations based on user account information Disabling Active Directory user accounts Deleting and restoring Active Directory user accounts
Active Directory contacts Active Directory groups
Entering master data for Active Directory groups Validity of group memberships Assigning Active Directory groups to Active Directory user accounts, Active Directory contacts, and Active Directory computers Additional tasks for managing Active Directory groups Deleting Active Directory groups Default solutions for requesting Active Directory groups and group memberships
Active Directory security IDs Active Directory container structures Active Directory computers Active Directory printers Active Directory locations Reports about Active Directory objects Configuration parameters for managing an Active Directory environment Default project template for Active Directory

Performing computer diagnostics

You can use the following tasks to run a diagnosis if the computer can be found on the network and if you have sufficient access permissions.

Table 72: Diagnostics tasks
Task Description
Diagnostics - Browse This opens a Window Explorer window. All shares for the selected computer are shown.
Diagnostics - Windows Diagnostics This opens the system information (winmsd.exe or msinfo32.exe) for the computer.
Windows Computer Administration This opens the Microsoft Management console for computer administration for the selected computer. For example, here you can see the result log or the local user administration.

To run diagnostics for a computer

  1. Select the Active Directory | Computers category.
  2. Select the computer and run the required diagnosis task from the task view.

Active Directory printers

All shared printers of a domain are read into One Identity Manager during synchronization.

To display a printer

  1. Select the Active Directory | Printers category.
  2. In the result list, select a printer then select the Change master data task.

Following information is displayed for a printer.

Table 73: Printer master data
Property Description
Printer name Name of the printer.
Driver Printer driver identifier.
Active Directory computers Computer or server to which the printer is connected.
Full server name Full name of the server to which the printer is connected.
Server Server's short name.
Port Printer connection.
UNC name Universal Naming Convention (UNC) address of the printer.
Location description Text field for additional explanation.
Description Text field for additional explanation.
Duplex Specifies whether double sided printing is supported.
Color Specifies whether color is supported.
Supports sorter Defines whether the printer supports a sorter.
Pages per minute Printer speed in page per minute.
Max. resolution [dpi] Maximum printer resolution in dpi.
Max. horizontal resolution Maximum printer resolution along the X-axis (width).
Max. vertical resolution

Maximum printer resolution along the Y-axis (height).

Spare field no. 01 ... Spare field no. 10

Additional company-specific information. Use the Designer to customize display names, formats, and templates for the input fields.

Active Directory locations

Locations are a group of computers based on networking information. In Active Directory, location data is used to control replication between domain controllers.

The information about Active Directory locations is loading into One Identity Manager during synchronization and cannot be edited.

To display location information

  1. Select the Active Directory | Locations category.
  2. Select the location in the result list.
  3. To display a location's server, select the Location overview task.
  4. To display a location's master data, select the Change master data task.

Following information about locations is displayed.

Table 74: Location master data
Property Description
Name Location name.
Canonical name The location's canonical name
Description Text field for additional explanation.
Location description Text field for additional explanation.
Forest The name of the Forest to which this location belongs.
Subnets IP address range at this location.
Related topics

Reports about Active Directory objects

One Identity Manager makes various reports available containing information about the selected base object and its relations to other One Identity Manager database objects. The following reports are available for Active Directory.

NOTE: Other sections may be available depending on the which modules are installed.
Table 75: Reports for the target system

Report

Description

Overview of all assignments (domain)

This report find all roles containing employees with at least one user account in the selected domain.

Overview of all assignments (container)

This report finds all roles containing employees with at least one user account in the selected container.

Overview of all assignments (group)

This report finds all roles containing employees with the selected group.

Show orphaned user accounts

This report shows all user accounts in the domain that are not assigned to an employee. The report contains group memberships and risk assessment.

Show employees with multiple user accounts

This report shows all employees with more than one user account in the domain. The report contains a risk assessment.

Show unused user accounts

This report shows all user accounts in the domain that have not been used in the last few months. The report contains group memberships and risk assessment.

Show entitlement drifts

This report shows all groups in the domain that are the result of manual operations in the target system rather than provisioned by One Identity Manager.

Show user accounts with an above average number of system entitlements

This report contains all user accounts in the domain with an above average number of group memberships.

Active Directory user account and group administration

This report contains a summary of user account and group distribution in all domains. You can find this report in My One Identity Manager.

Data quality summary for Active Directory user accounts

This report contains different evaluations of user account data quality in all domains. You can find this report in My One Identity Manager.

Related topics
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating