One Identity Manager supports the connection of Active Directory systems through an integrated connector. Additional Active Directory relevant functionality, for example, Microsoft Exchange, Office Communication Services or Active Directory Lightweight Directory Service (AD LDS), is not supported through this connector.
One Identity Manager is assumed to be the primary system in the default configuration of processes and synchronization behavior and is allowed to bypass workflows. Default behavior requires an administrative account. workflows can still be controlled by the integrated connector. You may need to define custom processes in One Identity Manager in order to use this functionality.
NOTE: The Active Directory Module and the Active Roles Module must be installed as a prerequisite for managing Active Directory in One Identity Manager. For more information about installing, see the One Identity Manager Installation Guide.
NOTE: This guide only goes into specific features of using the Connector. For more information about managing Active Directory with One Identity Manager, see the One Identity Manager Administration Guide for Connecting to Active Directory.
For more information about applying, managing, and configuring an server, see your One Identity Active Roles documentation.
The following servers are used for managing an Active Directory environment with One Identity Manager and :
-
server
server that establishes the connection to the Active Directory domain controller. The synchronization server connects to this server.
-
Synchronization server
Communication of the One Identity Manager Service with is run from the synchronization server. The One Identity Manager Service with the connector is installed on this server. Data entries required for synchronization and administration with the One Identity Manager database are processed by the synchronization server. The synchronization server connects to the server.
The One Identity Manager's connector uses the ADSI interface for communicating with an instance. The connector is used for synchronization and provisioning Active Directory. The connector connects to an instance, which then connects to the Active Directory domain controller.
Figure 1: The synchronization architecture
Scenario
You want to manage an Active Directory domain, currently managed by , with One Identity Manager. Self-Service Manager is not implemented.
Select the One Identity Manager edition when you install the One Identity Manager database.
Initial synchronization of Active Directory domains with One Identity Manager must be carried out by the connector. All other synchronization is also carried out by the connector.
Scenario
You want to manage an Active Directory domain, currently managed by , with One Identity Manager. Self-Service Manager is implemented. The functionality should be transferred to the One Identity Manager‘s IT Shop.
Select the One Identity Manager edition when you install the One Identity Manager database.
Before the initial synchronization, perform the following additional steps:
-
In the Designer, set the QER | ITShop | AutoPublish | ADSGroup configuration parameter.
-
In the Designer, set the QER | ITShop | AutoPublish | ADSGroup | ExcludeList configuration parameter and specify the Active Directory groups that are not to be added automatically to the IT Shop.
-
In the Designer, set the TargetSystem | ADS | ARS_SSM configuration parameter
-
Compile the database.
Active Directory domain synchronization with One Identity Manager must be carried out by the connector. All other synchronization is also carried out by the connector.
Scenario
You want to manage an Active Directory domain, currently managed by One Identity Manager, with . Currently, Active Directory domain synchronization is carried out by the Active Directory connector.
To manage the Active Directory domains with One Identity Active Roles
-
In the Synchronization Editor, delete the existing synchronization project.
-
Create a synchronization project with the Synchronization Editor by using the default project template for .
Detailed information about this topic
The One Identity Manager supports synchronization with versions 7.4.1, 7.4.3, 7.4.4, 7.4.5, 7.5, 7.5.2, 7.5.3, 7.6, 8.0, 8.1.1, 8.1.3, and 8.1.5.
To load Active Directory objects into the One Identity Manager database for the first time
-
Prepare a user account with sufficient permissions for synchronization.
-
One Identity Manager components for managing Active Directory environments are available if the TargetSystem | ADS configuration parameter is enabled. The components for managing are available if the TargetSystem | ADS | ARS configuration parameter is set.
-
Check whether the configuration parameters are set in the Designer. Otherwise, set the configuration parameters and compile the database.
NOTE: If you disable the configuration parameter at a later date, model components and scripts that are no longer required, are disabled. SQL procedures and triggers are still carried out. For more information about the behavior of preprocessor relevant configuration parameters and conditional compiling, see the One Identity Manager Configuration Guide.
-
Other configuration parameters are installed when the modules are installed. Check the configuration parameters and modify them as necessary to suit your requirements.
- Install and configure a synchronization server and declare the server as a Job server in One Identity Manager.
-
Before the initial synchronization, perform the following additional steps:
-
In the Designer, set the QER | ITShop | AutoPublish | ADSGroup configuration parameter.
NOTE: If you disable the configuration parameter at a later date, model components and scripts that are no longer required, are disabled. SQL procedures and triggers are still carried out. For more information about the behavior of preprocessor relevant configuration parameters and conditional compiling, see the One Identity Manager Configuration Guide.
-
In the Designer, set the QER | ITShop | AutoPublish | ADSGroup | ExcludeList configuration parameter and specify the Active Directory groups that are not to be added automatically to the IT Shop.
Example:
.*Administrator.*|Exchange.*|.*Admins|.*Operators|IIS_IUSRS
-
In the Designer, set the TargetSystem | ADS | ARS_SSM configuration parameter
-
Compile the database.
- Create a synchronization project with the Synchronization Editor.
TIP: Before you set up synchronization with an Active Directory domain, familiarize yourself with the Synchronization Editor. For more information about this tool, see the One Identity Manager Target System Synchronization Reference Guide.
Detailed information about this topic