You can convert a directory of type Other, which stores users and groups synced from Workspace ONE UEM, to a directory of type Active Directory over LDAP or Active Directory over Integrated Windows Authentication, which are associated with the VMware Identity Manager connector. After you convert the directory, the VMware Identity Manager connector is used instead of ACC to sync users and groups from your enterprise directory to the VMware Identity Manager service.
Необходимые условия
- Install and activate the VMware Identity Manager connector.
To use some features, you must join the Windows server to the domain, you must install the VMware Identity Manager connector as a domain user that is part of the administrator group on the Windows server, and you must choose to run the IDM Connector service as a Windows domain user.
This requirement applies to the following cases.
- If you plan to convert the Other directory to Active Directory over Integrated Windows Authentication
- If you plan to use Kerberos authentication
- The following Active Directory information is required:
- If you are converting to Active Directory over LDAP, the Base DN, and Bind user DN and password are required.
The Bind user must have the following permissions in Active Directory to grant access to users and groups objects:
- Read
- Read All Properties
- Read Permissions
Using a Bind user account with a non-expiring password is recommended.
- If you are converting to Active Directory over Integrated Windows Authentication, the user name and password of the Bind user who has permission to query users and groups for the required domains is required.
The Bind user must have the following permissions in Active Directory to grant access to users and groups objects:
- Read
- Read All Properties
- Read Permissions
Using a Bind user account with a non-expiring password is recommended.
- If your Active Directory requires access over SSL/TLS, the Intermediate (if used) and Root CA certificates of the domain controllers for all relevant Active Directory domains are required. If the domain controllers have certificates from multiple Intermediate and Root Certificate Authorities, all the Intermediate and Root CA certificates are required.
- For Active Directory over Integrated Windows Authentication, when you have multi-forest Active Directory configured and the Domain Local group contains members from domains in different forests, make sure that the Bind user is added to the Administrators group of the domain in which the Domain Local group resides. If this is not done, these members are missing from the Domain Local group.
- For Active Directory over Integrated Windows Authentication:
- For all domain controllers listed in SRV records and hidden RODCs, nslookup of hostname and IP address should work.
- All the domain controllers must be reachable in terms of network connectivity.
- If you are converting to Active Directory over LDAP, the Base DN, and Bind user DN and password are required.
Процедура
Дальнейшие действия
Stop directory sync from Workspace ONE UEM to the converted directory.