IDR SSO - Step 5: Connect LDAP Directory
Add a Connection to LDAP Directory
Perform these steps to connect to an LDAP directory quickly using only required settings. If you want to use advanced options, see Add an Identity Source.
Procedure
- In the Cloud Administration Console, click Users > Identity Sources.
- Click Add an Identity Source > Select next to Active Directory.
- Click Add an Identity Source > Select next to the directory to add.
- Enter the identity source name and root (the base DN for users from the planning worksheet).
- In the SSL/TLS Certificate section, unselect Use SSL/TLS encryption to connect to the directory servers.
- In the SSL/TLS Certificates section:
- Select Use SSL/TLS encryption to connect to the directory servers.
- Click Add and select the SSL/TLS certificate.
- In the Directory Servers section, add each directory server in the identity source, and test the connection.
- Click Next Step.
- On the User Attributes page, click Refresh Attributes, and verify that a valid list of attributes appears.
Select Use selected policy attributes with the Cloud Authentication Service.
In the Policies column, select sAMAccountName, virtualGroups, and memberOf or other attributes that you might use to identify users.
- Click Next Step.
In the User Search Filter field, specify your test group using a filter. The following is an Active Directory example:
(&(objectCategory=Person)(sAMAccountName=*)(objectClass=user)(mail=*)(memberOf=<yourgroup_distinguishedName>))
Where <yourgroup_distinguishedName> is the name of your test administrator group.
For example, (&(objectCategory=Person)(sAMAccountName=*)(objectClass=user)(mail=*)(memberOf=CN=SecurIDAccessUsers,OU=Groups,DC=Corp,DC=local))
- Click Save and Finish.
- Click Publish Changes.
Synchronize LDAP Directory for Cloud Access Service
Synchronize data between Cloud Access Service (CAS) and your LDAP directory to ensure that CAS reflects any updates made to the LDAP directory.
During synchronization, users are added and attribute values that you selected in the previous step are copied to CAS. User passwords are not synchronized.
Procedure
- In the Cloud Administration Console, click Users > Identity Sources.
- Next to your identity source, select Synchronization from the drop-down menu.
In the Identity Source Details section, click Synchronize Now.
Depending on the number of users you are synching, this process can take a number of minutes.
IDR SSO - Step 6: Configure the Standard Web Application Portal
Related Articles
Cloud Access Service Quick Setup Guide for My Page SSO - Step 5: Connect LDAP Directory 49Number of Views Cloud Access Service - Authentication Manager Integration 45Number of Views Cloud Access Service Overview 184Number of Views Connect Your Cloud Access Service Deployment to Authentication Manager 141Number of Views Connect Authentication Manager to the Cloud Access Service 671Number of Views
Trending Articles
How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager Upgrade Process