McAfee EPOCDE-AA-BA Product Guide - Page 127

Types of Active Directory synchronization, Systems and structure, Systems only

Page 127 highlights

Organizing the System Tree Active Directory and NT domain synchronization 12 Types of Active Directory synchronization There are two types of Active Directory synchronization (systems only and systems and structure). Which one you use depends on the level of integration you want with Active Directory. With each type, you control the synchronization by selecting whether to: • Deploy agents automatically to systems new to ePolicy Orchestrator. You may not want to set this on the initial synchronization if you are importing a large number of systems and have limited bandwidth. The agent MSI is about 6 MB in size. However, you might want to deploy agents automatically to any new systems that are discovered in Active Directory during subsequent synchronization. • Delete systems from ePolicy Orchestrator (and remove their agents) when they are deleted from Active Directory. • Prevent adding systems to the group if they exist elsewhere in the System Tree. This ensures that you don't have duplicate systems if you manually move or sort the system to another location. • Exclude certain Active Directory containers from the synchronization. These containers and their systems are ignored during synchronization. Systems and structure When using this synchronization type, changes in the Active Directory structure are carried over into your System Tree structure at the next synchronization. When systems or containers are added, moved, or removed in Active Directory, they are added, moved, or removed in the corresponding locations of the System Tree. When to use this synchronization type Use this to ensure that the System Tree (or parts of it) look exactly like your Active Directory structure. If the organization of Active Directory meets your security management needs and you want the System Tree to continue to look like the mapped Active Directory structure, use this synchronization type with subsequent synchronization. Systems only Use this synchronization type to import systems from an Active Directory container, including those in non-excluded subcontainers, as a flat list to a mapped System Tree group. You can then move these to appropriate locations in the System Tree by assigning sorting criteria to groups. If you choose this synchronization type, be sure to select not to add systems again if they exist elsewhere in the System Tree. This prevents duplicate entries for systems in the System Tree. When to use this synchronization type Use this synchronization type when you use Active Directory as a regular source of systems for ePolicy Orchestrator, but the organizational needs for security management do not coincide with the organization of containers and systems in Active Directory. NT domain synchronization Use your NT domains as a source for populating your System Tree. When you synchronize a group to an NT domain, all systems from the domain are put in the group as a flat list. You can manage these systems in the single group, or you can create subgroups for more granular organizational needs. Use a method, like automatic sorting, to populate these subgroups automatically. If you move systems to other groups or subgroups of the System Tree, be sure to select to not add the systems when they already exist elsewhere in the System Tree. This prevents duplicate entries for systems in the System Tree. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 127

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

Types of Active Directory synchronization
There are two types of Active Directory synchronization (
systems only
and
systems and structure
).
Which one you use depends on the level of integration you want with Active Directory.
With each type, you control the synchronization by selecting whether to:
Deploy agents automatically to systems new to ePolicy Orchestrator. You may not want to set this
on the initial synchronization if you are importing a large number of systems and have limited
bandwidth. The agent MSI is about 6 MB in size. However, you might want to deploy agents
automatically to any new systems that are discovered in Active Directory during subsequent
synchronization.
Delete systems from ePolicy Orchestrator (and remove their agents) when they are deleted from
Active Directory.
Prevent adding systems to the group if they exist elsewhere in the System Tree. This ensures that
you don't have duplicate systems if you manually move or sort the system to another location.
Exclude certain Active Directory containers from the synchronization. These containers and their
systems are ignored during synchronization.
Systems and structure
When using this synchronization type, changes in the Active Directory structure are carried over into
your System Tree structure at the next synchronization. When systems or containers are added,
moved, or removed in Active Directory, they are added, moved, or removed in the corresponding
locations of the System Tree.
When to use this synchronization type
Use this to ensure that the System Tree (or parts of it) look exactly like your Active Directory structure.
If the organization of Active Directory meets your security management needs and you want the
System Tree to continue to look like the mapped Active Directory structure, use this synchronization
type with subsequent synchronization.
Systems only
Use this synchronization type to import systems from an Active Directory container, including those in
non-excluded subcontainers, as a flat list to a mapped System Tree group. You can then move these to
appropriate locations in the System Tree by assigning sorting criteria to groups.
If you choose this synchronization type, be sure to select not to add systems again if they exist
elsewhere in the System Tree. This prevents duplicate entries for systems in the System Tree.
When to use this synchronization type
Use this synchronization type when you use Active Directory as a regular source of systems for ePolicy
Orchestrator, but the organizational needs for security management do not coincide with the
organization of containers and systems in Active Directory.
NT domain synchronization
Use your NT domains as a source for populating your System Tree. When you synchronize a group to
an NT domain, all systems from the domain are put in the group as a flat list. You can manage these
systems in the single group, or you can create subgroups for more granular organizational needs. Use
a method, like automatic sorting, to populate these subgroups automatically.
If you move systems to other groups or subgroups of the System Tree, be sure to select to not add
the systems when they already exist elsewhere in the System Tree. This prevents duplicate entries for
systems in the System Tree.
Organizing the System Tree
Active Directory and NT domain synchronization
12
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
127