Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Importing AD Security Groups

Created: 31 Aug 2011 | 6 comments
Jamy69's picture
0 0 Votes
Login to vote

Hi all,

Is it possible to import all Security groups from AD ?

I've seen the option in the AD Import Connector, but it needs to select one by one...

Is it possible with a connector and how ? I have created my connector but my rule doesn't work (lookup key problem... What settings ?)

Thanks a lot

 

GREG

Comments

cnpalmer75's picture
05
Sep
2011
0 Votes 0
Login to vote

Yes...

In order to import your groups as security roles you need to use the AD connector rule. In this rule you need to specify which groups to import. If you have a naming convention it is easier to import however you can select them individually. Once your groups are added ensure you are select the correct Type to import, perhaps that is why you are receving an error.

If you need some screenshots please let me know.

Benjamin Palmer
Specialist | Client Design
Director | Symantec CT User Group

If you find this post helpful please give it a thumbs up!
If you find that this solves your problem please mark it as the solu

cnpalmer75's picture
07
Sep
2011
0 Votes 0
Login to vote

Here's the process doc for you...

Follow these steps.

AttachmentSize
AD Security Role Import.docx 84.22 KB

Benjamin Palmer
Specialist | Client Design
Director | Symantec CT User Group

If you find this post helpful please give it a thumbs up!
If you find that this solves your problem please mark it as the solu

Jamy69's picture
08
Sep
2011
0 Votes 0
Login to vote

Thanks for your answers The

Thanks for your answers

The problem with the AD connector, is that I need to add each group manually in the rule, in order to import these.

I want to know if there is a possibility to import each new group (in a special OU for example) automatically.

Thanks a lot.

 

GREG

cnpalmer75's picture
08
Sep
2011
0 Votes 0
Login to vote

Enhancement Request

I understand what you are trying to do now. I do not think this is possible once you select the "Role and Account" resources to import. Anything other than this selection allows for the "starting from" to be selected which is where you would select the starting OU.

Sounds like an enhancement request to have this added as an option for this type of import rule.

Benjamin Palmer
Specialist | Client Design
Director | Symantec CT User Group

If you find this post helpful please give it a thumbs up!
If you find that this solves your problem please mark it as the solu

powellbc's picture
28
Sep
2011
1 Vote +1
Login to vote

Workaround

I stumbled across a workaround for your issue. We have a similar environment with around 20 specific roles/AD Groups (each supporting a different group of resources). They all belong to a parent AD group which assigns base privileges in SMP. If you import the parent AD group, it will pull in all the individual member groups as well.

So basically, do this:

  1. Create an AD security group and add all the other security groups you want to import into SMP.
  2. Create a schedule to import the parent group created in step 1 in the AD connector page.
  3. All of the AD security groups should now show up in the roles page of SMP.

Hope this helps.

powellbc's picture
29
Sep
2011
0 Votes 0
Login to vote

Also, unless I am missing

Also, unless I am missing something, why not just add all of the groups you need to the one rule? That will work too.