Active Directory Synchronization

In the Tools menu, choose Active Directory Synchronization to start the wizard of the same name.

The WinNT provider has been replaced by a more powerful LDAP provider since version 14. Furthermore, extended functionality for Active Directory synchronization has been implemented.

When opening the wizard, please enter the following information in a first step:

Regarding Active Directory synchronization, you will also be able to choose from further different options here, that is Recursively scan all containers and Check deleted objects. If the option Recursively scan all containers is checked the wizard will read the entire directory. In some cases, this may take some time. We recommend to only use this option the first time after porting data from an older version of Password Depot Server in order to replace all WinNT paths with LDAP paths. However, if this option is not selected, the wizard works like a usual Active Directory explorer, i.e. it only opens the specified object or container and scans the container when you expand the node afterwards.

Then, click Sign In to continue.

If login was successful, the Active Directory tree will be listed next.

Check users and/or groups here that should be imported or updated in Password Depot Enterprise Server.

If you have a large number of entries, you can filter them by using the Filter option at the bottom on the left.

If you right-click on the Active Directory tree, different features will be available in order to speed up selection.

Select desired users and/or groups by checking the boxes. In addition to that, you can also see in this dialog window further attributes of users in the Active Directory as well as their value.

Afterwards, click  Synchronize and results of synchronization will be displayed in a new dialog window.

NOTE: All imported users from Active Directory can log in with their accounts and passwords from Windows NT by default. You can change this in the user's properties.

 

HINT: With version 15, users and groups can also be synchronized individually with the Active Directory.