ePO - SaaS communicates with your Active Directory servers through the Active Directory Connectors. You must have a registered Active Directory server to use Policy Assignment rules, to enable dynamically assigned permission sets, and to enable Active Directory user logon.
You must have one or two systems as your Active Directory connectors for failover support. These systems must be managed by ePO - SaaS before you begin the setup process.
You need to know your Active Directory domain name in DNS-style.
Select Menu → Configuration → Directory Service and click New Server.
In the Description page, select Directory Services in Server type, then specify a unique name and optional description and click Next.
In the Details page, select Active Directory from the Directory Services list.
Note
OpenLDAP servers aren't supported in ePO - SaaS.
Enter a domain name or a specific server name.
Use DNS-style domain names (such as
internaldomain.com), or fully qualified domain names or IP addresses for servers (such asserver1.internaldomain.comor192.168.75.101).Click Select Systems to add Active Directory Connectors (ADC). You can select a maximum of two systems as your connectors.
Tip
For best results, choose servers as your Active Directory Connectors.
Click Deploy to deploy the Active Directory connector.
After the status changes to Installed, click Test Connection to verify the connectivity between ePO - SaaS, your Active Directory connector, and the Active Directory server.
Choose whether to Use SSL to communicate with this server.
Note
Enable this option if you set SSL in your Active Directory.
Select Global Catalog ports instead of standard LDAP ports to retrieve user and group information when querying Active Directory.
Select Chase Referrals if you don't use the Global Catalog.
Chasing referrals can generate non-local network traffic.
Enter a User name and Password for an administrator account on the server in the format
domain\username.Enter a Site name for the server, or select it by clicking Browse and navigating to it. (Specifying the name of an Active Directory site physically near your ADC deployments. This can reduce LDAP query latency.)
Note
Don't update the Synchronization Schedule details as these aren't applicable to Trellix DLP – SaaS appliances. You can use the policy in Users and Groups in Policy Catalog → DLP Appliance Management to retrieve and synchronize information from the registered Active Directory servers.
You can set up a schedule that updates the changes in the mapped domain or Active Directory container. You can schedule it hourly or daily based on your requirements.
Click Test Connection to verify the connection to confirm the communication between your Active Directory and ePO - SaaS is successful, and click Save to complete the registration.
Add the Active Directory server to the User and Groups policy, and push the policy to the appliance using the Wake Up Agent option. Before you push the Users and Groups policy changes to the appliance, make sure that the policy is assigned to the appliance.
In ePO - SaaS, go to Policy Catalog → DLP Appliance Management <version>, and click Users and Groups.
Click the Edit link of the policy, to update the policy.
In LDAP Servers, select the checkbox to add the registered Active Directory server, and click Save. You can also change the daily synchronization schedule.
To push the changes to the appliance immediately, in System Tree → Systems, select the appliance and click Wake Up Agents.
In the Wake Up Trellix Agent page, select the Force complete policy and task update checkbox and continue to use the other default settings. Click OK.