Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

OpenManage Enterprise 4.1.x User's Guide

Import Active Directory and LDAP groups

This topic describes how to import users in active directory or LDAP for authentication into the appliance.

Prerequisites

  • Ensure you are logged into OpenManage Enterprise as an Administrator, as described in User roles.
  • Users other than Administrator cannot enable or disable the Active Directory (AD) and Lightweight Directory Access Protocol (LDAP) users.
  • Ensure Active Directory groups have a Universal group scope.
  • AD and LDAP directory users can be imported and assigned one of the OpenManage Enterprise roles (Administrator, DeviceManager, or Viewer). The Single-Sign-On (SSO) feature stops at login to the console. Actions run on the devices require a privileged account on the device.
  • If RSA SecurID authentication is required on users from the Active Directory or LDAP groups, ensure the active directory or LDAP groups are integrated with the RSA server.

Steps

  1. Click Import Directory Group.
  2. In the Import Active Directory dialog box:
    1. From the Directory Source drop-down menu, select an Active Directory or LDAP source that must be imported for adding groups.
      For more information on support services, see Add or edit the Active Directory connection.
    2. Click Input Credentials.
    3. In the dialog box, type the username and password of the domain where the directory is saved. Use tool tips to enter the correct syntax.
    4. Click Finish.
  3. In the Available Groups section:
    1. In the Find a Group box, enter the initial few letters of the group name available in the tested directory. All the groups names that begin with the entered text are listed under GROUP NAME.
    2. Select the check boxes corresponding to the groups be imported, and then click the >> or << buttons to add or remove the groups.
  4. In the Groups to be Imported section:
    1. Select the check boxes of the groups, and then select a role from the Assign Group Role drop-down menu. For more information about the role-based access, see Role and scope-based access.
    2. Click Assign Role.
      NOTE:For a logged-in Active Directory user belonging to an imported child Active Directory group, multiple roles such as Device Manager and Viewer are displayed upon a mouse-over on the username on the appliance masthead. This happens if the parent directory group and child directory group are imported with different privileges. For such Active Directory users, the role with the maximum privilege will be applied.
      The users in the group under the selected directory service are assigned the selected user roles.
    3. For the Device Manager role, the scope is defaulted to All Devices, however, the administrator can restrict the scope by choosing the Assign Scope option followed by selecting the device group(s).
  5. Repeat steps 3 and 4, if necessary.
  6. Click Import.
    The directory groups are imported and displayed in the Users list. However, all users in those groups will log in to OpenManage Enterprise by using their domain username and credentials.

Example

It is possible for a domain user, for example john_smith, to be a member of multiple directory groups, and also for those groups to be assigned different roles. In this case, multiple roles such as Device Manager and Viewer are displayed upon a mouseover on the username on the appliance masthead right-hand corner. Such users will receive the highest level role for all the directory groups they are assigned to.

  • Example 1: The user is a member of three groups with admin, DM, and viewer roles. In this case, user becomes an administrator.
  • Example 2: The user is a member of three DM groups and a viewer group. In this case, the user will become a DM with access to the union of device groups across the three DM roles.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\