 |
This section shows how to configure PCM/IDM for use with Active Directory.
5.1 Synchronize IDM with Active Directory To synchronize ProCurve Manager with IDM with Active Directory:
- Open PCM, and navigate to the Preferences > Identity Management > User Directory Settings window:
- In the User Directory Settings window, ensure the Enable Active Directory synchronization box is checked.
- Enter your credentials. IAS validates your credentials, and IDM is synchronized to Active Directory. IAS authentication occurs every time synchronization is performed.
 » Return to top
5.2 Show behavior of adding or deleting a user in a subgroup
Follow this example of adding and deleting a user to see how PCM/IDM is synchronized with AD.
- In IDM, in Tools | Preferences | User Directory settings, you can see groups to synchronize with Active Directory. This example shows that the two groups, Marketing and Finance, have been synchronized.
- In IDM User Directory Settings, click the Add or Remove Groups button to show how groups from Active Directory are added or removed from the synchronization. For example:

- Now, go to Active Directory Users and Computers and create a new user:

- Give this new user a login name (sophie) and password:


- For this example, assign the new user sophie to the Marcom Group, which is a subgroup of the Marketing Group.


- In IDM, you can confirm that this new user appears in the Marketing Group:
- Now, for this example go to Active Directory and delete the user sophie:

- Return to IDM. Now you see the user sophie has disappeared from the Marketing group, indicating that IDM and Active Directory are synchronized:

» Return to top
5.3 Show behavior of a user in multiple synchronized groups
In Active Directory, a user can be member of multiple groups. In IDM, a user can only belong to a single Access Policy Group. This raises a question: How does IDM handle a user that is a member of multiple synchronized groups? The following example illustrates a user in multiple subgroups.
- In Active Directory Users and Computers, the Member Of tab of user Adrian Properties shows that user Adrian belongs to two groups:
- Marcom, which is a subgroup of Marketing
- Administration, which is a subgroup of Finance

- IDM’s User Directory Settings shows the order in which the two groups have been synchronized. Marketing was first, followed by Finance:
- Looking at the Users shows that Adrian appears in Marketing, the first group on the list:
- Now use the Move up and Move down buttons to change the order of the two groups, so that Finance appears before Marketing:
- Look at the Marketing and Finance groups again. You can see that Adrian has disappeared from the group he was in, and now appears in the group that has been moved at the top of the list:

This demonstration illustrates that when a user belongs to multiple synchronized groups, IDM always places the user
in the first group on the synchronization list. Remember to take this behavior into account when planning
synchronization of IDM with Active Directory.
 » Return to top
|