Import Active Directory containers to ePO - SaaS

Prev Next

Import systems from your Active Directory containers directly into the System Tree by mapping Active Directory source containers to System Tree groups.

Mapping Active Directory containers to groups allows you to:

  • Synchronize the System Tree structure to the Active Directory structure so that when containers are added or removed in Active Directory, the corresponding group in the System Tree is added or removed.

  • Delete systems from the System Tree when they are deleted from Active Directory.

  • Prevent duplicate entries of systems in the System Tree when they exist in other groups.

For details about product features, usage, and best practices, click ? or Help.

  1. Select MenuSystem Tree Deploy, then scroll to the bottom on the page and select Configure Directory Service.

    Note

    You cannot synchronize the Lost and Found group of the System Tree.

  2. Next to Synchronization type, click Directory Service.

  3. Next to Systems that exist elsewhere in the System Tree, select whether to create a duplicate entry for systems that exist in another group of the System Tree.

    Note

    If you are using Active Directory synchronization as a starting point for security management, and plan to use System Tree management functionality after mapping your systems, do not create duplicate entries of the systems.

  4. Select the type of Active Directory synchronization you want to occur between this group and the Active Directory container (and its subcontainers):

    Options

    Definitions

    Systems and container structure

    Select this option if you want this group to truly reflect the Active Directory structure. When synchronized, the System Tree structure under this group is modified to reflect that of the Active Directory container it's mapped to. When containers are added or removed in Active Directory, they are added or removed in the System Tree. When systems are added, moved, or removed from Active Directory, they are added, moved, or removed from the System Tree.

    Systems only

    Select this option if you only want the systems from the Active Directory container (and non-excluded subcontainers) to populate this group, and this group only. No subgroups are created when mirroring Active Directory.

  5. In the Active Directory domain section, select from a list of already registered Active Directory servers.

  6. Select whether leave systems in their current location in the System Tree, or to delete systems from the System Tree when they are deleted from the Active Directory domain. Optionally choose whether to remove agents from the deleted systems.

  7. Select whether to apply tags to new or updated computers.

  8. Next to Containers, do the following:

    Options

    Definitions

    Browse

    Select a source container in the Select Container dialog box.

    Add Root...

    Add the root container of your Active Directory.

    Add

    Enter the containers manually.

    Exclude empty containers (Also deletes empty groups)

    Select whether to exclude empty containers during synchronization.

  9. Next to Exclusions, do the following:

    Options

    Definitions

    Add Containers...

    Select a source container that you want to exclude during synchronization in the Select Container dialog box.

    Add Computers...

    Select a system that you want to exclude during synchronization in the Select Systems dialog box.

    Import

    Type a list of Distinguished Names (DN) that you want to exclude.

    Note

    Separate the DNs through semicolons or by typing it in a new line.

  10. To synchronize the group with Active Directory immediately, click Synchronize Now .

    Clicking Synchronize Now saves any changes to the synchronization settings before synchronizing the group. If you have an Active Directory synchronization notification rule enabled, an event is generated for each system that is added or removed. These events appear in the Audit Log, and are queryable.