McAfee EPOCDE-AA-BA Product Guide - Page 126

Active Directory and NT domain synchronization, Active Directory synchronization, Types of tags

Page 126 highlights

12 Organizing the System Tree Active Directory and NT domain synchronization Types of tags ePolicy Orchestrator uses two types of tags: • Tags without criteria. These tags can be applied only to selected systems in the System Tree (manually) and systems listed in the results of a query. • Criteria-based tags. These tags are applied to all non-excluded systems at each agent-server communication. Such tags use criteria based on any properties sent by the agent. They can also be applied to non-excluded systems on demand. Active Directory and NT domain synchronization ePolicy Orchestrator can integrate with Active Directory and NT domains as a source for systems, and even (in the case of Active Directory) as a source for the structure of the System Tree. Active Directory synchronization If your network runs Active Directory, you can use Active Directory synchronization to create, populate, and maintain part or all of the System Tree with Active Directory synchronization settings. Once defined, the System Tree is updated with any new systems (and subcontainers) in your Active Directory. Active Directory integration allows you to: • Synchronize with your Active Directory structure, by importing systems and the Active Directory subcontainers (as System Tree groups) and keeping them up-to-date with Active Directory. At each synchronization, both systems and the structure are updated in the System Tree to reflect the systems and structure of Active Directory. • Import systems as a flat list from the Active Directory container (and its subcontainers) into the synchronized group. • Control what to do with potential duplicate systems. • Use the system description, which is imported from Active Directory with the systems. In previous versions of ePolicy Orchestrator, there were the two tasks: Active Directory Import and Active Directory Discovery. Now, use this process to integrate the System Tree with your Active Directory systems structure: 1 Configure the synchronization settings on each group that is a mapping point in the System Tree. At the same location, you can configure whether to: • Deploy agents to discovered systems. • Delete systems from the System Tree when they are deleted from Active Directory. • Allow or disallow duplicate entries of systems that already exist elsewhere in the System Tree. 2 Use the Synchronize Now action to import Active Directory systems (and possibly structure) into the System Tree according to the synchronization settings. 3 Use an NT Domain/Active Directory Synchronization server task to regularly synchronize the systems (and possibly the Active Directory structure) with the System Tree according to the synchronization settings. 126 McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Types of tags
ePolicy Orchestrator uses two types of tags:
Tags without criteria
. These tags can be applied only to selected systems in the System Tree (manually)
and systems listed in the results of a query.
Criteria-based tags
. These tags are applied to all non-excluded systems at each agent-server
communication. Such tags use criteria based on any properties sent by the agent. They can also be
applied to non-excluded systems on demand.
Active Directory and NT domain synchronization
ePolicy Orchestrator can integrate with Active Directory and NT domains as a source for systems, and
even (in the case of Active Directory) as a source for the structure of the System Tree.
Active Directory synchronization
If your network runs Active Directory, you can use Active Directory synchronization to create,
populate, and maintain part or all of the System Tree with Active Directory synchronization settings.
Once defined, the System Tree is updated with any new systems (and subcontainers) in your Active
Directory.
Active Directory integration allows you to:
Synchronize with your Active Directory structure, by importing systems and the Active Directory
subcontainers (as System Tree groups) and keeping them up-to-date with Active Directory. At each
synchronization, both systems and the structure are updated in the System Tree to reflect the
systems and structure of Active Directory.
Import systems as a flat list from the Active Directory container (and its subcontainers) into the
synchronized group.
Control what to do with potential duplicate systems.
Use the system description, which is imported from Active Directory with the systems.
In previous versions of ePolicy Orchestrator, there were the two tasks: Active Directory Import and
Active Directory Discovery. Now, use this process to integrate the System Tree with your Active
Directory systems structure:
1
Configure the synchronization settings on each group that is a mapping point in the System Tree.
At the same location, you can configure whether to:
Deploy agents to discovered systems.
Delete systems from the System Tree when they are deleted from Active Directory.
Allow or disallow duplicate entries of systems that already exist elsewhere in the System Tree.
2
Use the Synchronize Now action to import Active Directory systems (and possibly structure) into
the System Tree according to the synchronization settings.
3
Use an NT Domain/Active Directory Synchronization server task to regularly synchronize the
systems (and possibly the Active Directory structure) with the System Tree according to the
synchronization settings.
12
Organizing the System Tree
Active Directory and NT domain synchronization
126
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide