Active Directory Scanner; Configuring A Directory Scanner Instance - Check Point HARMONY R81 Administration Manual

Endpoint server
Table of Contents

Advertisement

Active Directory Scanner

If your organization uses Microsoft Active Directory (AD), you can import users, groups,
Organizational units (OUs) and computers from multiple AD domains into the Endpoint
Security Management Server. After the objects have been imported, you can assign policies.
When you first log in to SmartEndpoint, the Users and Computers tree is empty. To populate
the tree with users from the Active Directory, you must configure the Directory Scanner.
The Directory Scanner scans the defined Active Directory and fills the Directories node in the
Users and Computers tab, copying the existing Active Directory structure to the server
database.
Required Permissions to Active Directory
For the scan to succeed, the user account related to each Directory Scanner instance requires
full read permissions to:
n
The Active Directory root.
n
All child containers and objects.
n
The deleted objects container.
An object deleted from the Active Directory is not immediately erased but moved to the
Deleted Objects container. Comparing objects in the AD with those in the Deleted
objects container gives a clear picture of network resources (computers, servers, users,
groups) that have changed since the last scan.
The Active Directory Scanner does not scan Groups of type "Distribution".
Required Configuration for Domains
On the Active Directory server, set the Groups Scope to Domain Local only.

Configuring a Directory Scanner Instance

A scanner instance defines which path of the Active Directory will be scanned and the scan
frequency. One scanner instance can include the full Active Directory domain, or a part of the
domain, for example an OU.
If you want to scan more than one domain or different parts of the same domain, configure in
SmartEndpoint more than one scanner. For example, if you want to scan the "HOME" domain
and the "OFFICE" domain, configure one scanner instance for each.
Do not create a scanner instance for an OU that is included in a different scan. If you try to
create a scan that conflicts with a different scan, an error message shows.
R81 Harmony Endpoint Server Administration Guide      |      93
Active Directory Scanner

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the HARMONY R81 and is the answer not in the manual?

Table of Contents

Save PDF