Configure an on-premise Active Directory

You can create an on-premise directory to sync users and groups from your Active Directory to Identity as a Service.

Note: If you currently use an on-premise directory to sync users and groups from Microsoft Entra ID, Entrust recommends that you configure an Configure an Azure Directory (Preview).

The Directory Sync agent is an on-premise application that is of part of an Identity as a Service Gateway to automatically import user and group information from your Active Directory server. The directory sync agent periodically queries your AD server to ensure that new user and group information is automatically added to Identity as a Service.

When you configure an on-premise directory, you can add multiple directory servers for failover in case a directory cannot be reached.

Attention: Depending on the configuration of the domain controller, when you change your password due to it being in a Change Required or Expired state, the old password can remain active for a period of time (default 1 hour). See the following for more details: https://support.microsoft.com/en-us/help/906305/new-setting-modifies-ntlm-network-authentication-behavior.

For Enterprise Service Gateways prior to 5.3, only the first directory server in the list is used.

Attention: Once you configure a directory and associate it to a gateway through the directory sync agent, the synchronization begins immediately. If you configure a directory without Group Filter values, every user identified in your corporate directory is imported into Identity as a Service immediately after the directory setup is complete. All user groups are also imported if no Group Filters are set.

 

Supported Microsoft Entra ID user roles and operations

The following table shows the Active Directory user roles and supported permissions.

SI No.

Role

User Sync

Group Sync

Password Change

Password Reset

1

Global Administrator

Yes

Yes

Yes

Yes

2

User Administrator

Yes

Yes

Yes

Yes

3

Global Reader

Yes

Yes

No

No

4

Directory Reader

Yes

Yes

No

No

Domain user roles

The following are Active Directory Domain user roles:

       Domain Administrator—Users with this role can connect with IDaaS with write permissions and can perform User synchronization, Group synchronization, Password Reset, and Password change.

       Domain User—Users with this role can connect with IDaaS with read only permissions and can perform User synchronization and Group synchronization but not Password Reset and Password change.

Group synchronization

       When synchronizing users from AD, if synchronization is configured to synchronize all groups, then all users will have a group in common.

       If an administration role is configured with OWN group access then an administrator that was synchronized will have that same group in common and will be able to administer all users that were synchronized.

       If you want administrators to not have access to all synchronized users, you can do one of the following:

  Configure synchronization to synchronize only groups that match the group filter and do not include a group that is common to all users in AD in your group filter. This allows you to have an administrator role with access to OWN groups.

  Configure an administrator role that has access to DEFINED groups and do not include groups that are common to all users.

 

Add an on-premise directory

1.      Click > Resources > Directories. The Directories List page appears.

2.      Click and select On-premise Active Directory from the drop-down list. The Add Directory page appears.

3.      Set the connection settings.

4.      Add Directory Servers.

5.      Set searchbases and group filters.

6.      Set the attribute mappings.

7.      Set the synchronization settings.

8.      Click Add.

When synchronization completes, the new directory appears on the Directories List page.