Active Directory Synchronization Schedules
While importing users or resources from Active Directory, PAM360 provides the option to configure auto-synchronization for a specific group or OU of an AD domain, so as to ensure that the user database is always updated. To set up synchronization, you have to initially enter the time interval at which PAM360 has to query the Active Directory to keep the user/resource database in sync, while providing the domain details to initiate import. The time interval could be as low as a minute or it can be in the range of hours/days. Refer to the images shown below for the same.
Details about all synchronization schedules that you have configured for different AD domains can be accessed by navigating to Admin >> Active Directory >> View Synchronization Schedules. In the page that loads, all AD domains for which synchronization has been configured will be listed in the sidebar navigation tab. Additionally, synchronization schedules configured for users and resources will be individually displayed under different sections respectively, as shown in the image below.
1. Modify/Delete Domain Details
To view or modify the details of an AD domain,
- First locate the desired domain in the sidebar navigation tab and then click on the 'Edit' icon shown beside the domain.
- In the dialog box that opens, you can make changes to domain details like domain name, primary/secondary domain controllers, connection mode etc.
- Click Save to apply the changes.
Note: Once you have modified the details of a domain, PAM360 will use the modified details the next time when it tried to communicate with the domain for data synchronization.
Note: Once a domain is deleted here, all synchronization schedules configured for both user and resource import from that domain will be completely removed. To set up user/resource sync again, go to Admin >> Active Directory >> Import Now (or) Resources >> Discover Resources.
2. Modify/Delete Schedules
If you have configured a sync schedule for a specific AD domain while carrying out user/resource import operations, you can later modify the schedules and set different sync intervals for individual groups/OUs in that domain, for both user and resource import respectively.
To modify the sync schedule of a specific group/OU,
- Locate the desired AD domain from the list of domains displayed in the sidebar navigation tab and click on it. PAM360 will load the list of all groups/OUs of that domain for which user sync has been scheduled (If you want to modify the schedule of resource sync, switch to the resources section.)
- Next, locate the required group/OU from the list and click on its name. In the dialog box that opens, modify the sync interval as required.
- Additionally, you can also set a custom display name for the group/OU which will then be shown as the 'Group Name' across all other tabs like 'Users' and 'Resources' where the group/OU is listed. The new display name can be added in the 'Group Name' field in the 'Schedule Details' dialog box, as shown in the image below.
- Click 'Save' to apply the changes.
Note: Setting a custom display name will not overwrite the name of the group/OU in AD. The original AD name will also be retained.
To modify/delete schedules in bulk,
- Navigate to the Users or Resources section as required, where the schedules have to be deleted.
- Next, select the desired schedules.
- To change the sync interval for the selected schedules in bulk, click on Edit Schedules shown above the schedules list.
- In the dialog box that opens, set a new time interval and click 'Save'. Now you have successfully changed the sync interval for the selected schedules.
- To delete the selected schedules in bulk, click on 'Delete Schedules' shown above the schedules list and click 'Ok' to confirm deletion. The schedules will be deleted.