Import Active Directory containers

Prev Next

Import systems from Active Directory containers directly into your System Tree by mapping source containers to System Tree groups.

Mapping Active Directory containers to groups allows you to:

  • Synchronize the System Tree structure to the Active Directory structure so that when containers are added or removed in Active Directory, the corresponding group in the System Tree is added or removed.

  • Delete systems from the System Tree when they are deleted from Active Directory.

  • Prevent duplicate entries of systems in the System Tree when they exist in other groups.

For details about product features, usage, and best practices, click ? or Help.

  1. Select MenuSystemsSystem TreeGroup Details, then select a group in the System Tree for mapping an Active Directory container to.

    Note

    You cannot synchronize the Lost and Found group of the System Tree.

  2. Next to Synchronization type, click Edit. The Synchronization Settings page for the selected group appears.

  3. Next to Synchronization type, select Active Directory. The Active Directory synchronization options appear.

  4. Select the type of Active Directory synchronization you want to occur between this group and the Active Directory container (and its subcontainers):

    • Systems and container structure — Select this option if you want this group to truly reflect the Active Directory structure. When synchronized, the System Tree structure under this group is changed to reflect the Active Directory container that it's mapped to. When containers are added or removed in Active Directory, they are added or removed in the System Tree. When systems are added, moved, or removed from Active Directory, they are added, moved, or removed from the System Tree.

    • Systems only — Select this option if you only want the systems from the Active Directory container (and non-excluded subcontainers) to populate this group, and this group only. No subgroups are created when mirroring Active Directory.

  5. Select whether to create a duplicate entry for systems that exist in another group of the System Tree.

    If you are using Active Directory synchronization as a starting point for security management, and plan to use System Tree management functionality after mapping your systems, do not select this option.

  6. In the Active Directory domain section, you can:

    • Type the fully qualified domain name of your Active Directory domain.

    • Select from a list of already registered LDAP servers.

  7. Next to Container, click Add and select a source container in the Select Active Directory Container dialog box, then click OK.

  8. To exclude specific subcontainers, click Add next to Exceptions and select a subcontainer to exclude, then click OK.

  9. Select whether to deploy the Trellix Agent automatically to new systems. If you do, configure the deployment settings.

    Tip

    Best practice: Because of its size, do not deploy the Trellix Agent during the initial import if the container is large. Instead, import the container, then deploy the Trellix Agent to groups of systems at a time, rather than all at once.

  10. Select whether to delete systems from the System Tree when they are deleted from the Active Directory domain. Optionally choose whether to remove agents from the deleted systems.

  11. To synchronize the group with Active Directory immediately, click Synchronize Now.

    Clicking Synchronize Now saves any changes to the synchronization settings before synchronizing the group. If you have an Active Directory synchronization notification rule enabled, an event is generated for each system that is added or removed. These events appear in the Audit Log, and are queryable. If you deployed agents to added systems, the deployment is initiated to each added system. When the synchronization completes, the Last Synchronization time is updated, displaying the time and date when the synchronization finished, not when any agent deployments completed.

    Tip

    Best practice: Schedule an NT Domain/Active Directory synchronization server task for the first synchronization. This server task is useful if you are deploying agents to new systems on the first synchronization, when bandwidth is a larger concern.

  12. When the synchronization is complete, view the results with the System Tree.

When the systems are imported, distribute agents to them if you did not select to do so automatically.

Tip

Best practice: Set up a recurring NT Domain/Active Directory synchronization server task to keep your System Tree current with any changes to your Active Directory containers.