Netiq Multi-Domain Active Directory Driver Implementation Guide
Total Page:16
File Type:pdf, Size:1020Kb
NetIQ® Identity Manager Driver for Multi-Domain Active Directory Implementation Guide February 2018 Legal Notice For information about NetIQ trademarks, see https://www.netiq.com/company/legal/. Copyright (C) 2018 NetIQ Corporation. All rights reserved. Contents About this Book and the Library 7 About NetIQ Corporation 9 1 Understanding the Multi-Domain Active Directory Driver 11 Key Terms . 11 Identity Manager . 12 Connected System. 12 Identity Vault. 12 Identity Manager Engine . 12 Multi-Domain Active Directory Driver . 12 Driver Shim . 12 .NET Remote Loader . 13 Data Transfers Between Systems. 13 Support for Standard Driver Features. 13 Supported Operations . 14 Remote Platforms . 14 Multi-Domain Support . 14 PowerShell Command Support . 14 Entitlements and Permission Collection and Reconciliation Service . 15 Automatic Domain Controller Discovery and Failover . 17 Domain Controller Failover . 17 Password Synchronization Support . 17 Data Synchronization Support . 17 Nested Group Synchronization Support. .17 Scalability . 17 Multiple Active Directory User Account Support. 18 Default Driver Configuration . 18 User Object Name Mapping. 18 Data Flow . 18 Checklist for Enabling User Synchronization . 22 2 Preparing Multi-Domain Active Directory 23 Driver Prerequisites . 23 Deploying the Multi-Domain Active Directory Driver . 24 Remote Installation on Windows and Other Platforms. 24 Remote Installation on a Windows Member Server . 25 Securing Driver Communication . 26 Authentication Methods . 26 Encryption Using SSL . 26 Creating an Administrative Account . 29 Configuring System Permissions . 30 Windows Message Queuing Permissions. 31 Becoming Familiar with Driver Features . 31 Schema Changes. 31 Structuring eDirectory Container Hierarchy . 31 Moving Cross Domain Objects. 32 Automatic Failover . 32 Multivalue Attributes . 33 Using Custom Boolean Attributes to Manage Account Settings. 33 Contents 3 Provisioning Exchange Mailboxes . 34 Expiring Accounts in Active Directory. 34 Driver Response Behavior . 35 3 Installing the Driver Files 37 Preparing for Driver Installation . 37 Installing the Driver Files. 37 Configuring the Multi-Domain Active Directory Driver. 37 4 Creating a New Driver 39 Creating the Driver in Designer. 39 Importing the Current Driver Packages . 39 Installing the Driver Packages . 40 Configuring Domain Connections for Multi-Domain Active Directory Driver. 44 Configuring the Driver . 46 Deploying the Driver. 48 Starting the Driver . 48 Activating the Driver . 49 Adding Packages to an Existing Driver. 49 5 Upgrading an Existing Driver 51 Supported Upgrade Paths . 51 What’s New . ..