The product enables import from one or more AD servers. Importing from multiple servers is useful when there are frequent cross-links between them. Currently, the product can export to only a single AD server.
Follow these steps:
The Active Directory Wizard - Step 1 dialog appears.
The following option is available:
Specifies that the Windows login is used to access target servers.
Note: Passwords are not saved in the registry, so when returning to an AD import page, most values are kept, but not the password. Reset passwords each time you run the connector.
The Active Directory Wizard - Step 2 dialog appears.
Specifies how Active Directory entities are mapped to CA GovernanceMinder roles. You can select more than one option. Valid values include:
Native CA GovernanceMinder roles are marked as such during a preceding export.
Primitive groups (meaninig that they are not the parent of other groups), are imported as resources, and parent groups are imported as CA GovernanceMinder roles.
Specified types of Active Directory groups are imported as roles.
The Active Directory Wizard - Step 3 dialog appears.
To activate the mapping, select the line that is associated with the CA GovernanceMinder attribute in the mapping table on the right.
When you map AD attributes to CA GovernanceMinder entities, take special care to import unique values into CA GovernanceMinder keys, including users' PersonID, roles' Role Name, and resources' combination of ResName1, 2, and 3.
To enable proper mapping of imported attributes back into AD in an export process, import the CN and DN. Use the Object Name attributes.
Note: CA GovernanceMinder imports up to 127 characters for each field, and logs alerts for objects that exceed such limitation.
The following fields are not self-explanatory:
Chooses specific predesignated schema attributes ad/or combinations thereof.
CN and DN map to the respective schema attributes.
CNi maps to the i-th part of the object's DN, from right to left (meaniing that it is based on the hierarchy), and beginning from the first container after the DC values.
DNi maps to the i-th part of the object's DCs.
You can map a constant field into a CA GovernanceMinder field. For example, it is often preferred to map the string "Active Directory" to Res Name 3.
This field enables you to leave a CA GovernanceMinder field blank.
Specifies a name for a CA GovernanceMinder attribute field
A similar window displays to enable you to map roles.
When completed, the product starts the import, and displays the import process progress. The following are steps to the import process:
When the import process is completed, a message appears that provides statistics on the imported data.
During the import process, the product creates a log file in the CA GovernanceMinder Logs folder. This log file is separate from the product main log file, and is named according to CA GovernanceMinder's naming convention eurekifyADConverter_<username>_<date>_<time>.log. This log file contains all the errors and mis-configurations that the product has encountered. The product prompts you to view this log file when the import is finished.
Important! Review the log file to ensure that it does not contain material warnings.
Copyright © 2014 CA.
All rights reserved.
|
|