The 黑料海角91入口 Active Directory Integration (ADI) enables the syncing of users, groups, and passwords between 黑料海角91入口 and on-premise or off-premise AD. As covered in Get Started with the Active Directory Integration, the ADI uses two agents: an import agent and a sync agent that can be installed in three (3) configurations. The configurations are determined by where you want to manage users, groups, and passwords.
- Manage users, groups, and passwords in AD
- Manage users and passwords in either system, or both
- Manage users, groups, and passwords in 黑料海角91入口
This article covers how to leverage the ADI depending on your configuration and use case.
Prerequisites
- You鈥檝e read and are familiar with the concepts in step 1 of this series, Get Started with the Active Directory Integration (ADI).
- The ADI agent(s) are installed and running on your AD servers. See Configure the Active Directory Integration.
Sync interval
The ADI agents check for updates from 黑料海角91入口 and the Domain Controller(s) every 90 seconds. Any changes made will be updated and reflected in the counterpart within that cadence.
Use cases and workflows
The table shows a summary of the most common use cases and the ADI configurations that support them. Reference Configure the Active Directory Integration for more information.
ADI Configuration | Use case | User and Group Authority | Password authority | Data sync direction | Server type(s) on which agent(s) can be installed | Install Import Agent | Install Sync Agent |
---|---|---|---|---|---|---|---|
Manage users, groups and passwords in AD | Extend AD | Domain Controllers | |||||
Manage users and passwords in either system, or both | Extend AD | Domain Controllers, Member Servers | |||||
Minimize AD footprint | Domain Controllers | ||||||
Migrate away from AD | Domain Controllers, Member Servers (Sync agent only) | ||||||
Manage users, groups, and passwords in 黑料海角91入口 | Minimize AD footprint | Domain Controllers, Member Servers | |||||
Migrate away from AD | Domain Controllers, Member Servers |
Workflow for Managing Users, Groups, and Passwords in AD
When the 黑料海角91入口 ADI is configured for AD Import only, the illustrations below show the user identity workflows for any user data changes or password updates in this configuration. This method allows Admins to extend their AD Users and Passwords to 黑料海角91入口. 黑料海角91入口 can then extend these identities out to resources, such as RADIUS WiFi or VPN networks, SSO Applications, LDAP resources, and more.
If you鈥檙e only using AD Import, continue to the Using AD Import section of this article and disregard the Using AD Sync section.
AD Import Agent Only 鈥 Single Domain Workflow
AD Import Agent Only 鈥 Multiple Domain Workflow
Workflow for Managing Users, Groups, and Passwords in AD, 黑料海角91入口, or Both
When the 黑料海角91入口 ADI is configured for AD Import and AD Sync, the illustrations below show the user identity workflow for any changes or password updates in this configuration. This scenario allows Admins to not only extend their AD users and Passwords to 黑料海角91入口 but to also allow 黑料海角91入口 to manage identities and passwords within AD for synced users.
Two-way Sync 鈥 Single Domain Workflow
Two-way Sync 鈥 Multiple Domain Workflow
Workflow for Managing Users, Groups, and Passwords in 黑料海角91入口
When the 黑料海角91入口 ADI is configured for AD Sync only, the illustrations below show the user identity workflow for any changes or password updates in this configuration. This scenario allows Admins to manage identities and passwords within AD solely from 黑料海角91入口 for synced users.
AD Sync Agent Only 鈥 Single Domain Workflow
AD Sync Agent Only 鈥 Multiple Domain Workflow
Using the AD Import Agent
When the import agent is installed on a member server, the password is not synced from AD to 黑料海角91入口.
The AD import agent allows you to do the following in 黑料海角91入口 from AD:
- Import users
- Update, and Deactivate users accounts
If the AD import agent is installed on a DC, it also allows you to:
- Activate the user鈥檚 password
To import users from AD into 黑料海角91入口
The AD Import Agent will only import users that you directly add as a memberOf the 黑料海角91入口 ADI Security Group within AD (i.e., the Security Group you created during the AD Import Agent installation).
There are two ways to specify which users to import from AD to 黑料海角91入口:
- through a direct membership to the 黑料海角91入口 ADI Security Group
- through a Security Group that is a member of the 黑料海角91入口 ADI Security Group
How passwords are handled for users added in AD who already exist in 黑料海角91入口 is controlled by the setting for the UserTakeoverAction in the AD import configuration file. The default value is deactivate, which will cause the user鈥檚 黑料海角91入口 password to be removed and set to a password pending status. The user will temporarily lose access to their 黑料海角91入口 provisioned resources (such as RADIUS, LDAP, SSO apps, etc.) until the password is updated within AD. See the Advanced Configurations for AD Import article for more information around UserTakeoverAction.
To import a single user from AD to 黑料海角91入口
- Open the Active Directory Users and Computers (ADUC) Menu by clicking the start button, typing 鈥渄sa鈥 and clicking the Active Directory Users and Computers icon.
- Once ADUC is open, navigate to a user that you would like to import into 黑料海角91入口.
- Right-click on the target user and click Properties.
- Navigate to the Member Of tab in the Properties menu.
- Click Add. Then add this user as a member of the 黑料海角91入口 ADI Security Group.
- Click Apply. Wait up to 90 seconds and then check to see if the user has been fully imported into 黑料海角91入口. This validates that your AD Import Agent is working appropriately.
The user is created with a Password Status of Password Pending and will have an AD Integration badge below their email address. The user state is controlled by setting for Users>Settings>Default User State for User Creation> Manual/Single User API. See Manage User States for more information about this setting.
Users who existed in AD before the AD import agent was installed must update their password in AD or an AD-managed resource for the Password Status to become active in 黑料海角91入口.
If the import agent is installed on your DCs, users created in AD after the AD import agent was installed will have their passwords automatically imported/updated in 黑料海角91入口 and their Password Status will be active.
To import multiple users from AD into 黑料海角91入口:
This method allows you to import all users that are members of a specific Security Group. For example, if you want to export all AD users that are members of the Accounting Security Group, you would make the Accounting Security Group a memberOf the 黑料海角91入口 ADI Security Group. This will then import the Accounting Security Group and all users that are associated members.
- Open the Active Directory Users and Computers (ADUC) Menu by clicking the start button, typing 鈥渄sa鈥 and clicking the Active Directory Users and Computers icon.
- Once ADUC is open, navigate to a user that you would like to import into 黑料海角91入口.
- Right-click on the target Security Group and click Properties.
- In the Security Group Properties Menu, click the Member Of tab and click Add.
- Add this Security Group to the 黑料海角91入口-named Security Group and click Apply.
- Wait 90 seconds for both the Security Group and the Users within that Security Group to be created in 黑料海角91入口. You will see both the user accounts and user groups within 黑料海角91入口鈥檚 Admin Portal marked by an AD Integration badge.
Users who existed in AD before the AD import agent was installed must update their password in AD or an AD-managed resource for the Password Status to become active in 黑料海角91入口.
If the import agent is installed on your DCs, users created in AD after the AD import agent was installed will have their passwords automatically imported/updated in 黑料海角91入口 and their Password Status will be active.
To sync users passwords from AD to 黑料海角91入口
Syncing passwords from AD to 黑料海角91入口 is only applicable when the import agent is installed on DCs. When the import agent is installed on member servers, the password is not synced from AD to 黑料海角91入口.
When existing AD users are imported from AD into 黑料海角91入口, there is no password associated with their account in 黑料海角91入口 until the user resets their password in AD. You鈥檒l see the newly imported users in 黑料海角91入口 marked with an AD badge and in an orange Password Pending password status within the user menu.
Users MUST change their AD user password within AD or a domain-managed resource to set a password 黑料海角91入口 account. This is a required step. If the user never resets their password in AD, then 黑料海角91入口 will never receive a password and the 黑料海角91入口 user will never be able to access their 黑料海角91入口 managed resources.
Users created in AD post install of the 黑料海角91入口 AD Import Agent will arrive in your 黑料海角91入口 tenant with a green Active state and do not require a password reset from with in AD.
To sync a password from AD to 黑料海角91入口
- Users will need to change their password in AD or on an AD-managed resource.
- In 90 seconds, in the 黑料海角91入口 Admin Portal Users page, you should now see the user鈥檚 Password Status change orange Password Pending state to a green check-marked active status with the expiry date from AD.
The password expiry date for AD-managed users is the expiry date from AD as the expiry is managed by AD, not 黑料海角91入口.
- All Password changes moving forward will need to be done within AD or on AD-bound resources.
If you鈥檙e planning on using AD Sync alongside AD Import, Passwords can be updated in 黑料海角91入口 after this required initial password change has taken place within the steps outlined above. This is a requirement for both AD Import only and AD Import & Sync use cases.
To create, update, and disable user accounts
These changes on a user or user group will be reflected within 黑料海角91入口 in approximately 90 seconds.
Now that AD Import has been successfully installed and configured, AD Admins will be able to manage 黑料海角91入口 user accounts and the following attributes within AD for any CrUD updated (Create, Update, and Deactivate/Disable):
- firstname
- lastname
- username
- password, and
- user state (active or disabled)
Creating new users in AD
Follow the same process outlined above for importing users from AD into 黑料海角91入口.
- Create a new user account in AD
- Add the user to the 黑料海角91入口 ADI security group
- Wait 90 seconds
- Verify the user was created in 黑料海角91入口.
Updating user attributes in AD
When you change any attributes of an AD user which is currently synced via the AD Import Agent, this will reflect within your 黑料海角91入口 tenant in approximately 90 seconds. For example, if you change the First or Last Name of a user, this will reflect on the 黑料海角91入口 user鈥檚 First or Last Name attribute in 90 seconds.
Disabling users in AD
When deleting, suspending, or deactivating users within AD, this will in turn delete the users from 黑料海角91入口 thus removing access to any of the 黑料海角91入口-managed resources he or she had access to such as RADIUS, LDAP, or SSO Applications.
Using AD Sync
If you鈥檙e choosing to also leverage the functionality of AD Sync Agent with your AD Integration, this allows 黑料海角91入口 to push CrUD changes of synced users down to AD. With the AD Sync Agent in place, you will be able to do the following:
- Create users in 黑料海角91入口 which will then push down to AD.
- When users change passwords in 黑料海角91入口, this new password will be pushed down to their AD user account.
- When you suspend or delete a user in 黑料海角91入口, this will disable the user Account in AD.
To sync an existing user from 黑料海角91入口 to AD
This functionality allows 黑料海角91入口 users to be created in AD if they don鈥檛 exist or allows 黑料海角91入口 to either take over management of the user if you have configured a one-way sync from 黑料海角91入口 to AD (only the AD sync agent is running) or co-manage the user with AD in a 2-way sync configuration (both the AD import and AD sync agents are running).
Follow the steps below to sync users from 黑料海角91入口 to AD.
If you are managing users in both 黑料海角91入口 and AD (two-way sync), and you left the default setting for UserTakeoverAction, which is deactivate, when you sync user with passwords from 黑料海角91入口 to AD, the AD import agent will change the 黑料海角91入口 user passwords status from Active to Password Pending. This results in these users losing access to any resources assigned to them in 黑料海角91入口. To prevent this, we recommend to see Advanced Configurations for AD Import and change the UserTakeoverAction attribute to retain.
- Navigate to your user in 黑料海角91入口 and open up their Details.
- Click on the user groups tab on the user aside.
- Assign user to a 黑料海角91入口 group and click Save.
- Wait for Active Directory badge to appear.
- Bind this user to the user group which they need to be a memberOf in AD (that is also synced using the ADI). In our example, we can see the Accounting User Group is tied to AD via the Directories in the drop-down menu.
- Click Save User. The user will then be created in the Root User Container within your AD domain. This can take up to 90 seconds.
Users who are created in AD from 黑料海角91入口 are automatically put into the Root User Container you configured during the installation of the AD Import & Sync Agents. If you need to move the user to the appropriate OU or sub OU, you鈥檒l have to do this within AD on the DC.
To create, update and deactivate user accounts
The following section covers how to manage AD user accounts from 黑料海角91入口. With the AD Sync in place, 黑料海角91入口 Admins are able to manage AD users from the 黑料海角91入口 Admin Portal. This makes user onboarding, off-boarding, and management much easier. Additionally, this may help with removing the need to remotely access the DC for simple tasks within the Identity Lifecycle for user accounts.
Creating Users in 黑料海角91入口
黑料海角91入口 Admins can create users in AD by binding any 黑料海角91入口 user to an AD Integrated User Group within 黑料海角91入口. For example, if you鈥檝e synced the Accounting group from AD to 黑料海角91入口 via the Import Agent, then any 黑料海角91入口 user bound to this synced user group will be created within AD under the Root User Container.
The user is created within AD, is a memberOf the associated user group (Security Group in AD), and their AD user account will use their 黑料海角91入口 Password.
Suspending or deleting users in 黑料海角91入口
Suspending or deleting users within 黑料海角91入口 will Disable the user account within AD. 黑料海角91入口 in any form will never remove or delete user accounts in any of the 3rd party integrations. (This also includes SAML, LDAP, AD, GWS, and M365). These changes will reflect in 90 seconds.
Managing ADI
Update agents
We recommend keeping your agents current to ensure you have the latest security updates, bug fixes, and functionality and to retain support.
To update the agents:
- Log in to the .
- Go to Directory Integrations > Active Directory.
- Select your AD domain
- From your selected use case (the section marked 鈥淭his is my use case鈥), click the download button for the agent.
- Select a download location
- Upload the agent installation file to the server where the agent is already installed
- Run the installation wizard
- Only minimal installation screens are shown.
- Directory for where the installation should occur
- Finish screen
- Restart the service.
Rotate ADI service account passwords in AD
The ADI import and sync service account passwords should be rotated on a regular basis for security purposes.
To rotate the ADI import service account (jcimport) password:
- Log in to a Domain Controller with an AD domain admin account
- Open the registry
- Navigate to HKLM\SOFTWARE\黑料海角91入口\AD Integration Import Agent\ldap
- Edit bind_password
- Enter the new password in the Value data field
- Click OK
- Open services.msc
- Restart the 黑料海角91入口 AD Integration Import Agent service.
To rotate the AD sync service account (jcsync) password:
- Log in to a Domain Controller with an AD domain admin account
- Open the registry
- Navigate to HKLM\SOFTWARE\黑料海角91入口\AD Integration Sync Agent\ldap
- Edit bind_password
- Enter the new password in the Value data field
- Click OK
- Open services.msc
- Restart the 黑料海角91入口 AD Integration Import Agent service.
Change use case
- Log in to the .
- Go to Directory Integrations > Active Directory.
- Select your AD domain
- Expand the desired use case
- Check 鈥淭his is my use case鈥
- Use the table below to determine the changes you need to make
Use case | New Use Case | Changes | ||
---|---|---|---|---|
Manage users, groups, and passwords in AD | Manage users and passwords in either system, or both | Manage users, groups, and passwords in 黑料海角91入口 | ||
Manage users, groups, and passwords in 黑料海角91入口 | x | 1. Delete the sync agent from the Admin Portal 2. Uninstall sync agents on all servers 3. Follow the instructions in to download and install the import agent(s)聽 | ||
x | Follow the instructions in to download and install the import agent(s)聽 | |||
Manage users, groups, and passwords in AD | x | Follow the instructions in Download and install sync agent(s) on server(s) | ||
x | 1. Delete the sync agent from the Admin Portal 2. Uninstall sync agents on all servers 3. Follow the instructions in to download and install the import agent(s)聽 | |||
Manage users and passwords in either system, or both | x | Follow the instructions in to download and install the import agent(s)聽 | ||
x | 1. Delete the import agent(s) from the Admin Portal 2. Uninstall import agents from all servers |
Manage agents in 黑料海角91入口
- Log in to the .
- Go to Directory Integrations > Active Directory.
- Select your AD domain
- Click the Domain Agents tab
- Click the pause to temporarily stop the agent
- This prevents information from flowing between 黑料海角91入口 and AD. For the AD sync agent, changes are still queued.
- Click delete to remove the agent from 黑料海角91入口.
Deleting an agent in 黑料海角91入口 does not stop the service in AD nor uninstall it.
Manage ADI services in AD
- Open services.msc
- Select the AD service (黑料海角91入口 AD integration Sync Agent or 黑料海角91入口 AD integration Impor Agent)
- Select the desired action: start, stop, restart
Modify agent configuration
Modify the AD Import Agent Configuration
The default configuration settings for the the AD import agent are:
- UserDissociateAction = remove
- UserTakeoverAction = deactivate
- UserDisableAction = suspend
- UserExpireAction = expire
- Review Advanced Configurations for the Active Directory Import Agent to understand the configuration settings available for the import agent.
- In AD, go to the 黑料海角91入口 folder where the AD Import agent is installed on a domain controller.
- Open the adint.config.json file using a text editor
- Edit the configurations in the 鈥淢ainLoop鈥 section of the file.
- Repeat this process for the configuration file on every AD server (DC controller on which AD Import is installed.
Modify the Root User container
If you decide to use a different Root user container for managing AD resources then you will want to modify or validate the configured Root User container location.
Verify the full LDAP path for the chosen Root user container you have selected in ADUC
- From the ADUC panel鈥檚 View menu, enable Advanced Features.
- Right-click the container and select Properties.
- Select the Attribute Editor tab.
- Select the 鈥渄istinguishedName鈥 attribute, then click View.
Modify the Root User container in AD sync configuration settings
Stop the 黑料海角91入口 AD Integration Sync service and make the required Sync Agent config changes:
- Open Registry Editor by clicking the Start button and typing in regedit. Click on the Registry Editor icon.
- Navigate to the following Registry Folder: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\黑料海角91入口\AD Sync.
- There should be a Key (looks like a folder) named ldap. If there is not, please create this Key in the registry and name it ldap.
- Open the ldap Key.
- You should see a Key labeled user_root_dn. You should also see the value with the targeted Root User Container you specified during install of the AD Sync Agent. If the user_root_dn value does not look correct, you can update it by double-clicking the key and updating the value to match your Root User Container.
- Once updated, you need to start the 黑料海角91入口 AD integration Sync Agent service within services.msc.
These changes should coincide with relocating the 黑料海角91入口 ADI security group in AD, as well as using the Delegation Wizard to set the associated agent service accounts.
Uninstall agents from AD servers
- Open Program Files.
- Find the program associated with the agent you want to uninstall (黑料海角91入口 AD Import or 黑料海角91入口 AD Sync)
- Uninstall
Want additional assistance from 黑料海角91入口?
If you鈥檙e having issues with getting 黑料海角91入口鈥檚 AD Integration working, see the Troubleshooting Guide.黑料海角91入口 now offers a myriad professional services offerings to assist customers with implementing and configuring 黑料海角91入口. If you鈥檙e looking for assistance with Migrating from AD, or to integrate AD with 黑料海角91入口, we recommend you reach out to 黑料海角91入口鈥檚 Professional Services team on the following page: Professional Services - 黑料海角91入口.