LDAP/AD Group synchronization

Prev Next

This document provides information about the AD/LDAP group synchronization report screen that displays information about the synchronization of LDAP/AD groups.

Path to access

  1. On Segura®, in the navigation bar, hover over the Products menu and select Settings.
  2. In the side menu, select Provisioning > Active directory > Group synchronization.

Actions menu

Item Type Description
Actions Dropdown menu Displays the options for Print Report, Export CSV, and Schedule Report.

Search fields

Info

To view all search fields, click More.

Item Type Description
Name Text field Filters by the name of the LDAP/AD group.
Server Text field Filters by the LDAP/AD server name.
DN Text field In this context, DN refers to Distinguished Name. A DN is a string that uniquely identifies an object in the Active Directory file structure by specifying the object's full path, including the object's name and location in the directory's hierarchical structure. Enter the string required to identify the group you are looking for.
Active synchronization Dropdown menu Filters by the synchronization status. Choose All to not apply any filter; Yes to filter the records with synchronization active and No to filter the records that do not have synchronization active.
Enabled Dropdown menu Filters the registers by their activation state. The options are Yes and No. Clear the field to enable the All option.

Report fields

  • ID.
  • Name.
  • Server.
  • DN.
  • Department.
  • Last synchronization: indicates when the last successful synchronization occurred.
  • Synchronization error: indicates when the last synchronization error occurred.
  • Active synchronization
  • Enabled.
  • Actions:
  • Edit group: opens the LDAP/AD Groups window in edit mode.
  • Users: opens the Synchronized users form.
  • Synchronization log: opens the AD/LDAP group synchronization logs form.
  • Synchronization test: opens the LDAP/AD group synchronization simulation form to test the group synchronization.
Info

By default, the report displays 30 records per screen. To go to the next screen, click the forward buttons at the end of the report.

LDAP/AD Group

When selecting the New Group option, accessed through Actions > New group, or the Edit group option, accessed through Actions > Edit group, the LDAP/AD group window will appear. This window contains the following fields.

Settings section

Item Type Required Description
Name Text field Yes Fill in the group name.
Server Dropdown menu Yes Choose the server where the search will be performed.
User Group Dropdown menu Yes Choose the user group that the current group will belong to. Note: this field is responsible for defining the groups defined for the synchronized users.
Enabled Toggle button No Choose the status of the group at the time of creation.
Synchronization Toggle button No Choose the possibility of the group having automatic synchronization.
Overwrite user accesses Toggle button No Choose whether synchronization replaces the roles a user already has with the roles listed in the current group's Roles section. When disabled, an existing user keeps the roles they already have. This toggle applies only to roles: it does not change the user group or the user's access policies.
DN Text field Yes Fill in the base DN.
AD username attribute Text field Yes Fill in the attributes associated with the username.
AD name attribute Dropdown menu No Binds the user's real name to the user's field in Active Directory.
Department Dropdown menu No Choose the user's department.
AD query Text field No Fill in the group search parameters.

The Overwrite user accesses toggle determines when the roles listed in the Roles section reach a user:

  • First synchronization: Segura® applies the roles listed in the Roles section the first time the current group synchronizes a user, regardless of the Overwrite user accesses toggle.
  • Later synchronizations: Segura® replaces the user's roles with the roles listed in the Roles section only when Overwrite user accesses is enabled. Otherwise, the user keeps the roles they already have.
Info

Segura® always applies the user group defined in this section, and the user inherits that user group's access policies. Neither depends on the Overwrite user accesses toggle.

Roles section

Item Type Description
Add Button Opens the Roles modal.
ROLE Text field Name of the chosen role.
BUILT-IN Text field Indicates whether the role is one of the defaults provided by the Segura or if it is a custom role, created by a user.
DESCRIPTION Text field Description of the chosen role.

Domum section

Item Type Description
Enable synchronization Toggle button Choose whether to enable synchronization with Segura® Domum.
Type Toggle button Choose which type of Segura® Domum user will be allowed in the group.
Vendor/Internal Group Dropdown menu Choosing the group in Segura® Domum to which the LDAP/AD group will belong.

Review section

The review session allows the user to check the LDAP/AD group information before finalizing the action. To save, click Save.

LDAP/AD group synchronization simulation

Item Type Required Description
DN Text field Yes Enter the base DN parameter that will be tested for synchronization.
Raw View Toggle button No Define if the response will be sent in plain text (raw).
User filter Text field Yes Enter the user filter parameter