Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Configuring Global Settings > Setting user directory information
Setting user directory information
Security Manager Help | Web, Data, and Email Protection Solutions | v8.5.x
Use the page Global Settings > General > User Directory to configure directory communication for administrators using their network accounts. The same directory must be used to authenticate all administrative users.
*
*
 
Note 
The Security Manager can communicate with the following Lightweight Directory Access Protocol (LDAP) directories:
*
*
*
*
It can also communicate with other generic LDAP-based directories.
*
*
To enable administrators to log on to the Security Manager using a network account:
1.
Select a user directory type from the drop-down list User directory server; Active Directory, Generic Directory, Lotus Notes, Norvell eDirectory, or Oracle Directory Server.
Configuration options display for your selection.
2.
Enter the IP address or host name to identify the directory server.
3.
Enter the communication Port for the directory.
4.
Enter a User distinguished name and Password for the administrative account that the software should use to retrieve user name and path information from the directory.
*
*
In the field User distinguished name, enter the account details as a single string. You can use the format "CN=user, DC=domain" or, if your organization uses Active Directory, "domain\username".
5.
6.
Enter the Root naming context that the Security Manager should use to search for user information. This is required for generic LDAP directories, Lotus Notes/Domino, and Oracle Directory Service, and optional for Active Directory and Novell eDirectory. If you supply a value, it must be a valid context in the domain.
If the Root naming context field is left blank, the software begins searching at the top level of the directory service.
 
Note 
7.
8.
9.
10.
*
Email attribute: The attribute name used to locate a user's email address in LDAP entries. The default is mail.
*
User logon ID attribute: The attribute name used to locate a user's logon ID in LDAP entries.
*
User logon filter: The filter to apply when searching for user details at logon. This string must contain the %uid token, which is then replaced with the user name entered by the user when logging on.
*
User lookup filter: The filter used to find users for import on the Add Network Account page. You can enter %query in this field as a placeholder, and then click Refine search on the Add Network Account page to enter a new context for finding network users.
*
Group object class (optional): The LDAP object class that represents a group. The default is group.
*
Group Properties: Specify whether your directory schema uses the memberOf attribute. If it does, in the Group attribute field enter the attribute used to reference the groups that the user is a member of.
If it does not, in the User group filter field enter the query used to resolve groups containing the specific user. You can enter %dn, which will be replaced by the distinguished name of the user.
11.
The settings are saved.
 
Note 

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Configuring Global Settings > Setting user directory information
Copyright 2018 Forcepoint. All rights reserved.