Configuring Active Directory domains in ADManager Plus
Easily set up and manage your Active Directory (AD) environment to enable a smooth integration with ManageEngine ADManager Plus. This help document helps you configure domains, permissions, and policies to streamline user and group management, reporting, and automation. Get started to simplify AD administration and boost efficiency.
During startup, ADManager Plus adds all the domains that can be discovered. If you wish to add more domains or modify the added domains, you can do so from here.
Note: The procedure to add child domains and domains from the same and different forests is the same.
To add more domains in ADManager Plus, follow these steps:
- Go to Directory/Application Settings in the top-right corner of the dashboard.
- Go to the Active Directory tab and click Click here to add a new domain to open the Add Domain Details dialog.
- Enter the Domain Name.
- Under Add Domain Controllers, click Discover Now to automatically locate domain controllers from the DNS. Alternatively, manually add all the domain controllers. The first domain controller in the list is treated as the primary domain controller. Use the up and down arrows to rearrange the domain controllers by their priority.
- Check the Implement DC Sort Intelligence box to fetch data from the fastest domain controller based on the response time. ADManager Plus will dynamically adjust the priority order based on performance.
- Check the Authentication box and enter the username and password of the privileged user account that will be used to connect to the domain controller.
- Click Add to save the domain settings.
You can perform the following actions from here:
- Choosing the default domain: The domain that is first discovered is considered the default domain and is shown in bold letters. Delegating security roles can only be done to the security principals of the default domain. If you wish to change the default, click the Make this the default domain icon in the Actions column next to the desired domain.
- Modifying a domain: To modify the domain details, click the Edit Domain Details icon, change the required values, and click Update.
- Deleting a domain: To delete a domain, click the Delete Domain icon.
- Refreshing the domain details: To synchronize the object details with AD, click the Update Domain Objects icon.
Note:
- The specified account should have sufficient privileges to perform management and reporting actions. For example, read-only privilege is sufficient to view reports.
- Domain controllers are contacted in succession based on their availability.
- The Replicating Directory Changes permission is recommended for reliable data synchronization between AD and ADManager Plus if the service account does not have domain-level administrator privileges.
- To view the permissions required for the AD and Microsoft 365 accounts configured in ADManager Plus, click here.