Set up Active Directory connectors and register your Active Directory server with Trellix ePO - SaaS

Prev Next

(This topic applies to Trellix DLP - SaaS.) Trellix ePO - SaaS communicates with your Active Directory servers through the Active Directory Connectors. You must have a registered Active Directory server to use Policy Assignment rules, to enable dynamically assigned permission sets, and to enable Active Directory user logon.

Before you begin

  • You must have one or two systems as your Active Directory connectors for failover support. These systems must be managed by Trellix ePO - SaaS before you begin the setup process.
  • You need to know your Active Directory domain name in DNS-style.

Task

  1. Select MenuConfigurationDirectory Service and click New Server.
  2. In the Description page, select Directory Services in Server type, then specify a unique name and optional description and click Next.
  3. In the Details page, select Active Directory from the Directory Services list.

    Note

    OpenLDAP servers aren't supported in Trellix ePO - SaaS.

  4. Enter a domain name or a specific server name.
    Use DNS-style domain names (such as internaldomain.com), or fully qualified domain names or IP addresses for servers (such as server1.internaldomain.com or 192.168.75.101).
  5. Click Select Systems to add Active Directory Connectors (ADC). You can select a maximum of two systems as your connectors.

    Tip

    For best results, choose servers as your Active Directory Connectors.

    1. Click Deploy to deploy the Active Directory connector.
    2. After the status changes to Installed, click Test Connection to verify the connectivity between Trellix ePO - SaaS, your Active Directory connector, and the Active Directory server.
  6. Choose whether to Use SSL to communicate with this server.

    Note

    Enable this option if you set SSL in your Active Directory.

  7. Select Global Catalog ports instead of standard LDAP ports to retrieve user and group information when querying Active Directory.
  8. Select Chase Referrals if you don't use the Global Catalog.
    Chasing referrals can generate non-local network traffic.
  9. Enter a User name and Password for an administrator account on the server in the format domain\username.
  10. Enter a Site name for the server, or select it by clicking Browse and navigating to it. (Specifying the name of an Active Directory site physically near your ADC deployments. This can reduce LDAP query latency.)
  11. You can set up a schedule that updates the changes in the mapped domain or Active Directory container. You can schedule it hourly or daily based on your requirements.
  12. Click Test Connection to verify the connection to confirm the communication between your Active Directory and Trellix ePO - SaaS is successful, and click Save to complete the registration.