Software Secure Access
Activity Manage

Create AD Groups in a Selective Sync File

  1. Identify the AD Groups of interest. Users and computers belonging to these Groups synchronize to Secure Access. For each sub-tree, only the parent group needs to be specified. All AD groups, users, and computers that are part of this parent group are automatically included.

     
    If you enabled Selective Sync, AD Users and Computers that are not members of Groups specified in CiscoADGroups.dat or their subgroups are not synchronized to Secure Access and are completely exempt from Secure Access access rules and reports.
  2. Create a CiscoADGroups.dat file in the C:\ drive of each machine where the connector is installed. The connector only reads the C:\CiscoADGroups.dat file. If the file is incorrectly named or is not present in the C:\ drive, all groups are imported to Secure Access.
  3. List the AD groups that need to be synchronized in distinguished name (DN) format in this file.
  4. Ensure that there are no blank lines anywhere in the file.

     
    If you are running multiple AD Connectors, the file C:\CiscoADGroups.dat should be present on each system running the connector and should be identical on each system.