Use this task to add new synchronization tasks for the Directory Services Connector. Each Active Directory Domain is limited to one synchronization task.
Before you begin
Complete the following in the Account Management tab of the Control Console before synchronizing users.
- Set Directory Integration to AD Domain.
- Create an email distribution list for exception notifications.
Complete the following in ePO.
- Under Configuration | Server Settings, set up the Email Server for email notifications.
- Under Configuration | Registered Servers, set up the Directory Services Connector server type.
For option definitions, click ? in the interface.
Task
-
From the toolbar, select Menu | Automation |
Directory Services Connector
to open the Directory Services Connector page.
-
Create a new AD domain synchronization using one of the following:
- Select Actions | New.
- Click New .
The Directory Settings page appears.
-
Complete the options to set up the Active Directory server.
-
Enter valid values for Email Attribute and Search Filter.
Required Field |
Recommended value |
Email Attribute
|
proxyAddresses
|
Search Filter
|
(&(proxyAddresses=smtp:*)(name=*))
|
-
Select DSC Server Authorization to register this task with the Control Console.
Note Directory Services Connector registration is required and you cannot continue or save without registering.
-
UnderAdditional Attributes, select the checkboxes for any additional attributes you want to include in the synchronization.
-
To verify that the server information you entered is correct, click Test .
-
Click Next.
The Exception Notifications and Automatic Synchronization page appears.
-
From the Exception Notification Distribution drop-down, select an email distribution list.
Note An active email distribution list is required to save the task. You can create the list in the Control Console.
-
Select the options for Exception Notification ContentException Notification Distribution.
-
Under Automatic Synchronization leave Enable deselected for now.
Note Run the task manually first. If it works as you expect, return here and select Enable.
-
If necessary, enter a value to specify the User Deactivation Limit.
-
Under Schedule, select the frequency of how often you would like the task to run.
-
Click Save.
The Directory Services Connector task is set up and ready to run. McAfee recommends that you run the task manually before enabling it to run automatically.