Importing existing groups and computers from an Active Directory or an LDAP server

Article:HOWTO80777  |  Created: 2012-10-24  |  Updated: 2013-01-30  |  Article URL http://www.symantec.com/docs/HOWTO80777
Article Type
How To


Subject


Importing existing groups and computers from an Active Directory or an LDAP server

If your company uses either Active Directory or an LDAP server to manage groups, you can import the group structure into Symantec Endpoint Protection Manager. You can then manage the groups and computers from the management console.

Table: Importing existing groups and computers lists the tasks you should perform to import the group structure before you can manage them.

Table: Importing existing groups and computers

Step

Task

Description

Step 1

Connect Symantec Endpoint Protection Manager to your company's directory server

You can connect Symantec Endpoint Protection Manager to either Active Directory or an LDAP-compatible server. When you add the server, you should enable synchronization.

See About importing organizational units from the directory server.

See Connecting Symantec Endpoint Protection Manager to a directory server.

See Connecting to a directory server on a replicated site.

Step 2

Import either entire organizational units or specific computer accounts or user accounts

You can either import the existing group structure, or import individual computer accounts or user accounts into the Symantec Endpoint Protection Manager groups that you create.

See Importing organizational units from a directory server.

If you want to use the group structure of Symantec Endpoint Protection Manager and not the directory server, import individual accounts.

See Searching for and importing specific accounts from a directory server.

Step 3

Either keep imported computer or user accounts in their own group or copy imported accounts to existing groups

After you import organizational units, you can do either of the following actions:

  • Keep the imported organizational units or accounts in their own groups. After you import organizational units or individual accounts, you assign policies to the organizational unit or group.

  • Copy the imported accounts to existing Symantec Endpoint Protection Manager groups. The copied accounts follow the policy of the Symantec Endpoint Protection Manager group and not the imported organizational unit.

    See Adding a group.

See Assigning a policy to a group.

See The types of security policies.

Step 4

Change the authentication method for administrator accounts (optional)

For the administrator accounts that you added in Symantec Endpoint Protection Manager, change the authentication method to use directory server authentication instead of the default Symantec Endpoint Protection Manager authentication. You can use the administrator accounts to authenticate the accounts that you imported. When an administrator logs on to Symantec Endpoint Protection Manager, the management server retrieves the user name from the database and the password from the directory server.

See Changing the authentication method for administrator accounts.

See Best practices for testing whether a directory server authenticates an administrator account.


Legacy ID



v15828324_v81626096


Article URL http://www.symantec.com/docs/HOWTO80777


Terms of use for this information are found in Legal Notices