黑料海角91入口 is an open directory platform that allows you to manage and secure user identities across devices, applications, and resources using multiple protocols. 黑料海角91入口 can integrate with Active Directory (AD) using the 黑料海角91入口 Active Directory Integration (ADI). ADI enables the syncing of user information and groups between 黑料海角91入口 and on-premise or off-premise AD and using the same user login for all AD and 黑料海角91入口 managed resources. ADI can be deployed in flexible configurations to support your specific use case, goals, and AD environment.
This article series presents the different configurations, workflows, and frameworks that can be leveraged for an integration between 黑料海角91入口 and AD.
ADI Deployment Configurations and Use Cases
ADI can be configured to support a variety of use cases. The three (3) most common use cases for ADI are:
- Extending your AD environment to support additional capabilities in the cloud and greater flexibility.
- Minimizing the number of resources managed by AD without replacing your AD environment.
- Migrating away from AD completely.
There are three (3) possible ADI deployment configurations for syncing data between AD and 黑料海角91入口.
There is also an Active Directory Migration Utility (ADMU) for migrating device management from AD to 黑料海角91入口.
黑料海角91入口 Terminology & Glossary
The full integration that enables the syncing of users and groups between 黑料海角91入口 and AD, as well as a single login for all AD and 黑料海角91入口 managed resources. The integration consists of two agents; the Import Agent and Sync Agent. The integration can be configured to use one or both of the agents. Your use case determines which agents are required, the direction of the sync, and which system is the authority.
The 黑料海角91入口 Active Directory Migration Utility (ADMU) is a tool that automates the migration of AD domain users to 黑料海角91入口 managed users and AD bound Windows devices to 黑料海角91入口 managed devices. The utility automates the tedious steps required to convert AD user profiles to local user profiles that can be managed by 黑料海角91入口, simultaneously removing the device from the AD domain and installing the 黑料海角91入口 agent. The utility can be used to a migrate a single device or many devices at once.
黑料海角91入口鈥檚 lightweight agent imports user identities and certain security groups from AD to 黑料海角91入口.聽 It can also be configured to import passwords if installed on DCs.聽 It can be installed on all the DCs or one or more member servers. This agent pushes or sends all user, group, and, if applicable, password changes that have occurred in AD since the last sync to 黑料海角91入口. Syncs occur every 90 seconds by default.
黑料海角91入口鈥檚 lightweight agent that聽pulls user identities, user groups, and passwords from 黑料海角91入口 and syncs that information to AD. It can be installed on one or more Domain Controllers (DCs) or member servers within an AD environment. This agent communicates to 黑料海角91入口 from the server(s) every 5 seconds to get all changes that have occurred in 黑料海角91入口 since the last sync, for any users and user groups connected to the ADI in 黑料海角91入口.
The directory considered to be the聽source-of-truth聽or the聽辫谤颈尘补谤测听辞谤听补耻迟丑辞谤颈迟补迟颈惫别听directory for user identities and groups.
A stand鈥揳lone instance of AD that contains a collection of one or more domains and acts as the security boundary within an AD environment.
A single AD domain within a forest that contains a collection of users, security groups, and other AD objects that share a domain name.
Two or more AD domains within a single forest.
Containers of objects within AD's logical structure in which security groups and users reside and can be nested. OUs are important within the ADI configuration as they are the search base used by the 黑料海角91入口 Import and Sync Agents.
The Security Group created by you during the ADI Import installation process and used by the 黑料海角91入口 Import Agent to determine which users and groups to sync from AD to 黑料海角91入口. This Security Group will be created in the Configuration article鈥檚 instructions. Only members of this group are synced between AD and 黑料海角91入口.
The main container or path containing the users and groups you'd like to sync between 黑料海角91入口 and AD. This can be a top-level OU, a sub-level OU, or the default 鈥淯sers鈥 container within AD. 黑料海角91入口鈥檚 ADI is configured to reference this as the Root User Container for which all users integrated with 黑料海角91入口 should reside. The AD Import and Sync agents use this Root User Container as a search base by default. If users are outside of the root User container, or its sub-level OUs, but are bound to the 黑料海角91入口 ADI Security Group, then user identity or credential issues may arise between 黑料海角91入口 and AD.
Ready to Configure?
Check out the next article in this document series, Configure the Active Directory Integration (ADI), to determine which ADI deployment configuration is best for your use case. You'll get an overview of the benefits, example use cases, workflows, and implementation steps and a link to the step-by-step configuration article for each available ADI deployment configuration.
Want additional assistance from 黑料海角91入口?
黑料海角91入口 now offers a myriad of professional services to assist you with implementing and configuring 黑料海角91入口. If you鈥檙e looking for assistance with Migrating from AD or integrating AD with 黑料海角91入口, we recommend you reach out to 黑料海角91入口鈥檚 Professional Services team on the following page: Professional Services - 黑料海角91入口.
Learn More
Need help troubleshooting?
If you鈥檙e having issues getting 黑料海角91入口鈥檚 ADI working, try Troubleshoot: ADI.
Want more information?
- [web page] Modernize Active Directory
- [eBook] Breaking Up with Active Directory
- [eBook] Modernize Active Directory: Break Free from the Limitations of AD
- [eBook] How to Modernize Your AD Instance: The IT Professional鈥檚 Roadmap to Augmenting or Replacing AD
- [blog] Modernizing AD is Possible
- [webinar] How To Modernize AD: An Admin鈥檚 Journey to IT Flexibility