When you configure the connection to your enterprise Active Directory or LDAP directory in the Workspace ONE Access console, you specify the users and groups to sync to Workspace ONE Access. You initially specify users and groups when you create a directory in Workspace ONE Access. Later, you can view and modify the users and groups from the Users and Groups tabs on the directory's Sync Settings page.

Keep the following considerations in mind while adding groups.

  • As a best practice, add and sync only a few groups while creating the directory. After the initial setup, you can add more groups.
  • When you add groups and sync them, only group names are synced to the directory. Users that are members of the group are not synced to the directory until the group is entitled to an application or the group name is added to an access policy rule.
    Note: You can override this restriction by selecting the Sync Group Members to the Directory When Adding Group option in the Settings > Login Preferences page.
  • (Active Directory) When you sync a group, any users that do not have Domain Users as their primary group in Active Directory are not synced.
  • (LDAP Directory) If you have multiple groups with the same name in your LDAP directory, you must specify unique names for them in the groups page.

Keep the following considerations in mind while adding users:

  • Because members in groups do not sync to the directory until the group is entitled to applications or added to an access policy rule, add all users who need to authenticate before group entitlements are configured.
  • The Bind user that you specified in the Bind Details section is not synced to the Workspace ONE Access service by default. If you want to sync the Bind user, enter the Bind user DN on the users page. After the directory is synced, you can set the role for the Bind user if required.

Procedure

  1. To navigate to the users and groups pages, choose from the following options.
    • If you are adding users and groups while creating the Workspace ONE Access directory, in the Add Directory wizard proceed to the Select the groups you want to sync page.
    • If you are adding or modifying users and groups after creating the Workspace ONE Access directory:
      1. Select Integrations > Directories.
      2. Click the directory you want to update.
      3. Click Sync Settings, then select the Groups tab.

        The page displays the group DNs that you added previously and the number of groups in each group DN that are selected for sync. You can click Select to see the list of groups under a group DN.

  2. Select the groups to sync from your enterprise directory to the Workspace ONE Access directory.
    To select groups, specify one or more group DNs and select the groups under them.
    1. In the Specify the top-level group row, click + and specify the top-level group DN. For example, CN=users,DC=example,DC=company,DC=com.
      Tip: Entering a high-level DN such as the Base DN to search under is not recommended, as search will take a long time. Try to enter a more specific DN to search under.
      Important: Specify group DNs that are under the Base DN that you entered in the Base DN text box in the Add Directory page. If a group DN is outside the Base DN, users from that DN will be synced but will not be able to log in.
    2. If you want to select all the groups under the group DN you added, select the Select All check box.
      If groups are added to or deleted from the group DN in the enterprise directory after the Workspace ONE Access directory is created, the changes are reflected in subsequent syncs.
    3. If you want to select specific groups under the group DN instead of selecting all of them, click Select Groups, make your selections, and click Save.
      When you click Select Groups, all the groups found in the DN are listed. You can narrow the results or search for specific groups by entering a search term in the search box.
    4. Select or deselect the Sync nested group members option, as needed.
      The Sync nested group members option is selected by default. When this option is selected, all the users that belong directly to the group you select as well as all the users that belong to nested groups under it are synced when the group is entitled. Note that the nested groups are not synced; only the users that belong to the nested groups are synced. In the Workspace ONE Access directory, these users will be members of the parent group that you selected for sync.

      If the Sync nested group members option is not selected, when you specify a group to sync, all the users that belong directly to that group are synced but users that belong to nested groups under it are not synced. Deselecting this option is useful for large directory configurations where traversing a group tree is resource and time intensive. If you deselect this option, ensure that you select all the groups whose users you want to sync.

  3. Navigate to the users page.
    • If you are adding users and groups from the Add Directory wizard, click Next to proceed to the Select the users you would like to sync page.
    • If you are adding or modifying users and groups from the directory's Sync Settings pages, click Save in the Groups tab, then select the Users tab.
  4. Select the users to sync from your enterprise directory to the Workspace ONE Access directory.
    1. In the Specify the user DNs row, click + and enter the user DNs. For example:

      CN=username,CN=Users,OU=Sales,DC=example,DC=com

      Important: Specify user DNs that are under the Base DN that you entered in the Base DN text box in the Add Directory page. If a user DN is outside the Base DN, users from that DN will be synced but will not be able to log in.

      To check if the user DN is valid and to see the number of users that will be synced, click the Test button for that row.

    2. Specify filters to include or exclude users from the DNs, if needed.
  5. Save your changes.