Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Configuring Global Settings > Setting user directory information
Setting user directory information
Security Manager Help | Web, Data, and Email Protection Solutions | v8.4.x
Use the Global Settings > General > User Directory page to configure directory communication for administrators using their network accounts. The same directory must be used to authenticate all administrative users.
*
*
 
Note 
The Security Manager can communicate with the following LDAP (Lightweight Directory Access Protocol) directories:
*
*
*
*
It can also communicate with other generic LDAP-based directories.
Note that:
*
*
To enable administrators to log on to the Security Manager using a network account:
1.
Select a user directory type from the User directory server list.
2.
Enter the IP address or host name to identify the directory server.
3.
Enter the communication Port for the directory.
4.
Specify a User distinguished name and Password for the administrative account the software should use to retrieve user name and path information from the directory.
*
*
Enter the account details as a single string in the User distinguished name field. You can use the format "CN=user, DC=domain" or, if your organization uses Active Directory, "domain\username".
5.
Click Test Connection to confirm that the directory exists at the specified IP address or name and port number, and that the specified account can connect to it.
6.
Enter the Root naming context that the Security Manager should use to search for user information. This is required for generic LDAP directories, Lotus Notes/Domino, and Oracle Directory Service, and optional for Active Directory and Novell eDirectory. If you supply a value, it must be a valid context in the domain.
If the Root naming context field is left blank, the software begins searching at the top level of the directory service.
 
Note 
7.
If the LDAP schema includes nested groups, mark Perform additional nested group search.
8.
9.
10.
*
Email attribute: The attribute name used to locate a user's email address in LDAP entries. The default is mail.
*
User logon ID attribute: The attribute name used to locate a user's logon ID in LDAP entries.
*
User logon filter: The filter to apply when searching for user details at logon. This string must contain the %uid token, which is then replaced with the user name entered by the user when logging on.
*
User lookup filter: The filter used to find users for import on the Add Network Account page. You can enter %query in this field as a placeholder, and then click Refine search on the Add Network Account page to enter a new context for finding network users.
*
Group object class (optional): The LDAP object class that represents a group. The default is group.
*
Group Properties: Specify whether your directory schema uses the memberOf attribute. If it does, in the Group attribute field enter the attribute used to reference the groups that the user is a member of.
If it does not, in the User group filter field enter the query used to resolve groups containing the specific user. You can enter %dn, which will be replaced by the distinguished name of the user.
11.
 
Note 

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Configuring Global Settings > Setting user directory information
Copyright 2017 Forcepoint. All rights reserved.