Overview
With the new AD management feature, the integration with AD/LDAP Connectors and AD Accounts is centralized to manage Druva administrators efficiently by the DCP administrators. The article provides information for the Administrators on upgrading the existing AD/LDAP connectors and their associated configuration through DCP (Druva Cloud Platform).
As an Endpoints & SaaS Apps administrator, ensure that all the connectors are upgraded by DCP administrators since you won't be able to modify the associated mappings with old connectors until the upgrade.
📝Note
With the Administrator management functionality, the AD/LDAP connector management setting for users is moved to the Druva Cloud Platform. For more information, see Administrator Provisioning using AD/LDAP.
Administrator Rights
The AD Management feature changes the administrator’s management capabilities by centralizing the privileges for AD integration to Druva Cloud Administrators. Below are the privileges with respect to AD/LDAP integration and associated functionality.
Privileges
Action | Druva Cloud Administrator | Workload (inSync) Administrators |
✅ | ❌ | |
✅ | ❌ | |
✅ | ❌ | |
✅ | ❌ | |
✅ | ❌ | |
✅ | ✅ | |
✅ | ✅ | |
✅ | ✅ | |
✅ | ✅ |
Upgrade old AD/LDAP connectors:
The DCP Administrators must upgrade all the old AD/LDAP Connectors to allow the inSync & DCP Administrators to modify the mapping and related configuration.
For more information on the detailed steps for the DCP Administrator to upgrade old connectors, see Upgrade Connector.
Modify AD/LDAP Mappings
Once all the connectors are upgraded by the DCP administrator, you can access and modify the existing mappings linked to your new connector.
Create AD/LDAP Mappings
Once the DCP Admin upgrades all the connectors, you can create a new mapping for users
Before you begin
Ensure that you have completed the following configurations:
The AD/LDAP Connector is installed by DCP Administrators. For more information, Download & Install AD/LDAP Connector.
The AD/LDAP Connector is configured by DCP Administrators. For more information, see Configure AD/LDAP Connector.
The AD/LDAP Account is registered by DCP Administrators. For more information, see Register your AD/LDAP Account.
A Profile is created by inSync Administrators. For more information, see Create a Profile.
To create a mapping
Follow the steps mentioned in the Create a Mapping.
