Previous Topic: WinNT Domain Connection Requirements

Next Topic: LanMan User Directories

Configure a Windows Directory Connection

After meeting the prerequisites described in the previous section, you can configure the connection.

Note: When you create or modify a Policy Server object in the Policy Server User Interface, use ASCII characters. Object creation or modification with non-ASCII characters is not supported.

To configure a Windows directory connection

  1. Open the User Directory Dialog.
  2. In the Directory Setup tab, select WinNT from the Namespace drop-down list.
  3. In the Directory Setup tab, enter connection information for your Windows domain.

    In the NT Domain Name field, enter the name of the WinNT domain, computer within the WinNT domain, or stand-alone WinNT computer:

    WinNT domains

    To define a namespace that represents global users and groups in a WinNT domain, specify the name of the domain in the NT Domain Name field. For user accounts in domains, SiteMinder supports both domain authentication as well as trusted domain authentication. In order for domain authentication to work, the system on which the Policy Server is installed must have a computer account in the appropriate domain. If this system does not have a computer account in all domains in which users need to be authenticated, the appropriate trust relationships must be established between domains.

    You can change the NT account under which the Policy Server is running. To do so, open the Settings, Control Panel, Services dialog, and change the account under which the Policy Server is running to an account that has the necessary privileges to access the specified domain. This account must have the Act As Part of Operating System system privilege.

    Individual WinNT computer in a domain

    To define a Namespace that represents local users and groups in a computer that is a member of a domain, specify the name of the domain, followed by the name of the computer in the NT Domain Name field. The domain same and computer name must be separated by a forward slash (/). If you do not specify the name of the computer, performance during searches may suffer.

    For example, if a domain called SampleDomain contains a computer called Comp1 which contains user information, you can enter the following in the NT Domain Name field:

    SampleDomain/Comp1

    Stand-alone WinNT computer

    To define a namespace that represents local users and groups in a stand-alone computer, specify the name of the computer in the NT Domain Name field. The stand-alone computer must have a Policy Server installed on it in order for this namespace to be accessible. There may be an initial delay when the Policy Server accesses this namespace for the first time.

  4. (Optional) In the Credentials and Connection tab, specify administrator credentials that the Policy Server will use to connect to the Windows domain.

    Note the following:

  5. (Optional) In the User Attributes tab, specify directory attributes that will be reserved for use by SiteMinder features.

More information:

Navigate to the User Directory Dialog

User Directory Dialog—WinNT Namespace—Directory Setup Tab

User Directory Dialog—WinNT Namespace—Directory Credentials and Connection Tab

Specify Directory Attributes

How SiteMinder Is Configured to Provide a Windows User Security Context