Prepare Active Directory

In order to configure a synchronization you first of all need some basic connection properties used to gain access to the Active Directory. You also need to prepare a group, or several groups, in the Active Directory. The groups will be used to organize users in the Active Directory into different roles. Discuss this together with your network- and Active Directory administrator. Also make sure that the process of administrating users in the Active Directory is taken into consideration.

Actions

Consult your network administrator to get the necessary information needed to configure synchronization between Active Directory and IFS Applications User Registry.

  1. Create an Active Directory service account.

    An account with read access to the Active Directory is needed by the sync job to access the Active Directory and place queries.

    Note: Create a service account on the Active Directory server for this purpose only. For security reasons it should be limited to read access only. Make sure to set the password to never expire.

  2. Get names of Active Directory Domain Controllers.

    At least one, but preferably two, domain controller server names (and ports). The second one will be used as fallback if the first one is unavailable during synchronization. Make sure to use domain controllers close to (network wise) the server running IFS Applications.

  3. Name of group(s) in Active Directory.

    When setting up the configuration you will browse and select the groups in the Active Directory but you need to know their name and location. Each group correspond to a role in IFS Applications.