aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
LDAP User Synchronization
Synchronization Profiles can also be configured to
Update Existing
User Accounts (i.e. User Accounts which do not
have the corresponding Synchronization Profile ID).
14.4
Creating and Updating User Accounts
Synchronization involves searching in the LDAP Server for User Accounts which match the filter definitions and are
located at the Search Base defined in the Synchronization Profile. User Accounts and the Attributes listed for
mapping in the profile are retrieved from the LDAP Server. For retrieved User Accounts, the synchronization
process may identify one of the following possibilities on the aXsGUARD Identifier (also shown in the image below):
1.
The User Account exists on the aXsGUARD Identifier in the destination domain and organizational unit:
with the same Synchronization Profile ID
. In this case the User Account is updated.
without the same Synchronization Profile ID
. In this case, synchronization behavior depends on the
Synchronization Profile
Update Existing
setting:
if enabled, properties are updated and the Synchronization Profile ID added.
if disabled, there is no action, but an informational message is logged.
2.
The User Account exists on the aXsGUARD Identifier in the destination domain but in a different
organizational unit:
with the same Synchronization Profile ID
. In this case the User Account is moved and the properties are
updated.
without the same Synchronization Profile ID
. In this case, no account is created and an error is logged
(User Accounts must be unique within a domain in the aXsGUARD Identifier: see section
3.
The User Account does not exist on the aXsGUARD Identifier. In this case the User Account is created and the
Synchronization Profile ID added.
©
2009 VASCO Data Security
83
Image 29: Administration Web Interface > Users > User 'annelies'> User Attributes