You can configure the appliance to connect to a directory service, for example, Active Directory. When you connect to your directory service, you will create one or more Directory Junctions to access specific domains or OUs. The appliance does not modify the directory service you connect to. The software caches the attributes for each directory service entry, so that if the connection to the directory service is lost temporarily, the software can use the cached information for management tasks.
When creating a Directory Junction, you use the following industry standard acronyms:
In the Management Console, the Users > Directory Tree displays a hierarchical view of Users and Groups.
What happens when you add Directory Junctions
Each Directory Junction that you create specifies a starting node in the directory tree. A new directory junction cannot include users who are already members of another junction, and junctions cannot be nested.
If you add a Parent Directory Junction, all of its children are migrated to that junction. All imported Users and Groups will be moved to the Parent, along with all Elastic Assignments. After being moved, the Child Directory Junctions are deleted.
If you’re creating several Distinguished Names
The system compares the Domain Component first---the portions of the Distinguished Name that start with "DC=". Please be aware that in Distinguished Names, order matters. For example, DC=A,DC=B is different than DC=B,DC=A. The system adds separate Directory Junctions if their DC components differ, or if their DC components match and the remaining components do not overlap. Directory Junctions are merged if their DC components match and their other components are related.
User attributes are imported from the directory service
The App Layering software imports and caches user and group attributes from your directory service when:
The attributes that the software caches are read only. All changes to the attributes for directory service users come from the directory server.
Imported attributes are synchronized regularly
The software synchronizes the information it caches for directory service users with the directory service every 12 hours. If the software discovers that a user is no longer an object in the directory service, it classifies the user as abandoned (you can view this information in the Information view for the user).