By default, a synchronization is created for each Active Directory domain when you set up the Directory Services Connector server as a registered server. However, you must configure and schedule AD domain synchronizations and ensure that user information is automatically updated in the Control Console.
Before you begin
Complete the following in the Account Management tab of the Control Console before synchronizing users.
- Set Directory Integration to AD Domain.
- Create an email distribution list for exception notifications.
Complete the following in ePO.
- Under Configuration | Server Settings, set up the Email Server for email notifications.
- Under Configuration | Registered Servers, set up the Directory Services Connector server type.
For option definitions, click ? in the interface.
Task
-
From the toolbar, select Menu | Automation |
Directory Services Connector
to open the Active Directory Domain Synchronization page.
-
Set up a synchronization using one of the following:
- Select the checkbox for a Domain and then click Actions | Edit.
- Mouse over the row for a domain to highlight it. Under the Actions column, click Edit.
The Directory Settings page appears.
-
Complete the options to set up the Active Directory server.
-
Enter valid values for Email Attribute and Search Filter.
If you are using Exchange Servers with Active Directory, enter search values as follows.
Required Field |
Recommended value |
Email Attribute
|
proxyAddresses
|
Search Filter
|
(&(proxyAddresses=smtp:*)(name=*))
|
If you are not using Exchange Servers with Active Directory, enter other search values, commonly using the "mail" attribute as follows.
Required Field |
Recommended value |
Email Attribute
|
mail
|
Search Filter
|
(&(mail=*)(name=*))
|
-
If necessary, select DSC Server Authorization to authorize this Directory Services Connector within the Control Console to synchronize this AD domain .
Note Directory Services Connector authorization is required and you cannot continue or save without it.
-
Under Additional Attributes, select any or all of the following checkboxes if you want to collect the additional data from the Active Directory:
-
First Name
-
Last Name
-
Display Name
-
Mobile Phone
-
Title
-
Department
Note This data can be useful if you use the Cloud SSO application and you automatically provision apps that user can access under the Cloud SSO umbrella.
-
To verify that the server information you entered is correct, click Test.
-
Click Next.
The Group Synchronization page appears.
-
Select Enable to add group names for synchronization or to select existing groups for synchronization.
-
In the Group Name field, type the initial letters of a group you want to add.
Directory Services Connector searches your Active Directory for matching group names and a list based on the characters you enter.
Note Directory Services Connector synchronizes only Active Directory security groups, not distribution groups.
-
Select the group name you want, and click Add
The group is added to the list.
-
Add other groups as needed.
-
Select the checkbox next to each group name you want to synchronize.
Note If you add a group to an AD domain in Directory Services Connector, the group is automatically included in the synchronization of any other AD domains you add in Directory Services Connector.
-
Click Next.
The Exception Notifications and Automatic Synchronization page appears.
-
From the Exception Notification Distribution drop-down, select an email distribution list.
Note An active email distribution list is required to save the synchronization settings. You can create the list in the Control Console.
-
Select the options for Exception Notification Content.
-
If necessary, enter a value to specify the User Deactivation Limit.
-
Under Automatic Synchronization leave Enable deselected for now.
Note Run the synchronization manually first. If it works as you expect, return here, select
Enable, and select:
- Enable automatic synchronization of Users — Synchronizes users in the AD domain, without assigning them to groups in the Control Console.
- Enable automatic synchronization of Users and Groups — Synchronizes users in the AD domain and assigns them to groups in the Control Console.
-
Under Schedule, select the frequency of how often you would like the task to run.
-
Click Save.
The Directory Services Connector synchronization is set up and ready to run. McAfee recommends that you run the synchronization manually before enabling it to run automatically. Repeat this process for each of your Active Directory domains.