Nt Domain Synchronization; Criteria-Based Sorting - McAfee EPOLICY ORCHESTRATOR 4.0.2 Product Manual

Table of Contents

Advertisement

Organizing Systems for Management

Criteria-based sorting

When to use this synchronization type
Use this synchronization type when you use Active Directory as a regular source of systems for
ePolicy Orchestrator, but the organizational needs for security management do not coincide
with the organization of containers and systems in Active Directory.

NT domain synchronization

Use your NT domains as a source for populating your System Tree. When you synchronize a
group to an NT domain, all systems from the domain are put in the group as a flat list. You can
manage those systems in the single group, or you can create subgroups for more granular
organizational needs. Use a method, like automatic sorting to populate these subgroups
automatically.
If you move systems to other groups or subgroups of the System Tree, be sure to select to not
add the systems when they already exist elsewhere in the System Tree.
Unlike Active Directory synchronization, only the system names are synchronized with NT domain
synchronization — the system description is not synchronized.
Criteria-based sorting
As in past releases of ePolicy Orchestrator, you can use IP address information to automatically
sort managed systems into specific groups. You can also create sorting criteria based on tags,
which are like labels assigned to systems. You can use either type of criteria or both to ensure
systems are where you want them in the System Tree.
Systems only need to match one criterion of a group's sorting criteria to be placed in the group.
After creating groups and setting your sorting criteria, take a Test Sort action to confirm the
criteria and sorting order achieve the desired results.
Once you have added sorting criteria to your groups, you can run the Sort Now action. The
action moves selected systems to the appropriate group automatically. Systems that do not
match the sorting criteria of any group are moved to Lost&Found.
New systems that call into the server for the first time are added automatically to the correct
group. However, if you define sorting criteria after the initial agent-server communication, you
must run the Sort Now action on those systems to move them immediately to the appropriate
group, or wait until the next agent-server communication.
Sorting status of systems
On any system or collection of systems, you can enable or disable System Tree sorting. If you
disable System Tree sorting on a system, it is excluded from sorting actions.
System Tree sorting settings on the ePO server
For sorting to take place, sorting must be enabled on the server and on the systems. By default,
sorting at each agent-server communication is enabled.
Test sorting systems
Use this feature to view where systems would be placed during a sort action. The Test Sort
page displays the systems and the paths to the location where they would be sorted. Although
this page does not display the sorting status of systems, if you select systems on the page
McAfee ePolicy Orchestrator 4.0.2 Product Guide
45

Advertisement

Table of Contents
loading

Table of Contents