Overview
Importing users into inSync from separate domains does not require creating separate connections to each domain. AD mapping can be configured so that inSync can import users from separate parent and child domains using a single AD security group.
To configure this, you will need to complete the following phases:
Configure the inSync Connector and AD security group
Register the AD/LDAP account
Create the AD mapping
Phase 1: Configure the inSync Connector and AD Security Group
Log in to the Druva Cloud Console.
Go to Druva Cloud Settings > Provisioning Methods > AD/LDAP.
Click on Add a New Connector. (Note: Copy the registration key shown on the screen, as it is required to activate the connector post-installation).
4. Install the inSync AD connector software on a server joined with the parent domain and register it using the registration key.
5. Create a universal security group on the parent domain Active Directory.
6. Import users into this security group from both the parent and child domains.
💡 Tip: Ensure both domains have a 2-way trust established.
Phase 2: Register the AD/LDAP Account
Log in to the Druva Cloud Console.
Go to Druva Cloud Settings > Provisioning Methods > AD/LDAP > Accounts.
Click Register New Account and provide the following details:
Host: FQDN/IP address of any domain controller on the parent domain (where the security group exists).
Port: 3268 (the port for the global catalog).
4. Open the inSync Connector installed on the server and click Manage AD accounts.
5. Enter the domain account credentials that have access to both the parent and child domains.
Phase 3: Create AD Mapping
On the Users Provisioning page, click New Mapping.
Click the Switch to manual AD/LDAP filters link.
On the Create AD/LDAP Mapping window, enter the following field values and click Next:
AD/LDAP mapping name: Name for the AD Mapping.
AD/LDAP Server: Select the AD server from the drop-down list.
Base DN: The part of the base domain name that is common across the domain names of the users in the AD security group.
Name to be used for creation: Username based on the organizational nomenclature.
Organizational unit: Keep this field blank.
AD Security group: Distinguished name of the AD security group (e.g., CN=Druva_Users,OU=Test OU,DC=forest,DC=com).
Department: Optional.
Country: Optional.
4. Once the mapping is created, verify the configuration by performing a manual import. Navigate to Users > User Provisioning to test.
