Create AD Groups in a Selective Sync File
Before you begin
- Full Admin user role. For more information, see Manage Accounts.
- Set up the AD Connector server, user account, and environment for deploying the AD Connector. For more information, see Prerequisites for AD Connectors.
- Add the AD components in Secure Access. For more information, see Add AD Components in Secure Access.
- (Optional) Configure Authentication for AD Connectors. For more information, see Configure Authentication for AD Connectors and VAs.
- (Optional) Configure software updates on the AD Connector. For more information, see Configure Updates on AD Connectors.
Procedure
1 |
Identify the AD Groups of interest. Users and computers belonging to these Groups synchronize to Secure Access. For each sub-tree, only the parent group needs to be specified. All AD groups, users, and computers that are part of this parent group are automatically included.
|
||
2 |
Create a CiscoADGroups.dat file in the C:\ drive of each machine where the connector is installed. The connector only reads the C:\CiscoADGroups.dat file. If the file is incorrectly named or is not present in the C:\ drive, all groups are imported to Secure Access. |
||
3 |
List the AD groups that need to be synchronized in |
||
4 |
Ensure that there are no blank lines anywhere in the file.
|