McAfee EPOCDE-AA-BA Product Guide - Page 143

Select Active Directory Container, Active Directory domain

Page 143 highlights

Organizing the System Tree Creating and populating groups 12 3 Next to Synchronization type, select Active Directory. The Active Directory synchronization options appear. 4 Select the type of Active Directory synchronization you want to occur between this group and the desired Active Directory container (and its subcontainers): • Systems and container structure - Select this option if you want this group to truly reflect the Active Directory structure. When synchronized, the System Tree structure under this group is modified to reflect that of the Active Directory container it's mapped to. When containers are added or removed in Active Directory, they are added or removed in the System Tree. When systems are added, moved, or removed from Active Directory, they are added, moved, or removed from the System Tree. • Systems only - Select this option if you only want the systems from the Active Directory container (and non-excluded subcontainers) to populate this group, and this group only. No subgroups are created when mirroring Active Directory. 5 Select whether a duplicate entry for the system will be created for a system that already exists in another group of the System Tree. McAfee does not recommend selecting this option, especially if you are only using the Active Directory synchronization as a starting point for security management and use other System Tree management functionality (for example, tag sorting) for further organizational granularity below the mapping point. 6 In Active Directory domain you can: • Type the fully-qualified domain name of your Active Directory domain. • Select from a list of already registered LDAP servers. 7 Next to Container, click Add and select a source container in the Select Active Directory Container dialog box, then click OK. 8 To exclude specific subcontainers, click Add next to Exceptions and select a subcontainer to exclude, then click OK. 9 Select whether to deploy agents automatically to new systems. If you do, be sure to configure the deployment settings. McAfee recommends that you do not deploy the agent during the initial import if the container is large. Deploying the 3.62 MB agent package to many systems at once may cause network traffic issues. Instead, import the container, then deploy the agent to groups of systems at a time, rather than all at once. Consider revisiting this page and selecting this option after the initial agent deployment, so that the agent is installed automatically on new systems added to Active Directory. 10 Select whether to delete systems from the System Tree when they are deleted from the Active Directory domain. Optionally choose whether to remove agents from the deleted systems. McAfee® ePolicy Orchestrator® 4.6.0 Software Product Guide 143

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328

3
Next to
Synchronization type
, select
Active Directory
. The Active Directory synchronization options appear.
4
Select the type of Active Directory synchronization you want to occur between this group and the
desired Active Directory container (and its subcontainers):
Systems and container structure
— Select this option if you want this group to truly reflect the Active
Directory structure. When synchronized, the System Tree structure under this group is modified
to reflect that of the Active Directory container it's mapped to. When containers are added or
removed in Active Directory, they are added or removed in the System Tree. When systems are
added, moved, or removed from Active Directory, they are added, moved, or removed from the
System Tree.
Systems only
— Select this option if you only want the systems from the Active Directory container
(and non-excluded subcontainers) to populate this group, and this group only. No subgroups are
created when mirroring Active Directory.
5
Select whether a duplicate entry for the system will be created for a system that already exists in
another group of the System Tree.
McAfee does not recommend selecting this option, especially if you are
only using the Active Directory synchronization as a starting point for
security management and use other System Tree management
functionality (for example, tag sorting) for further organizational
granularity below the mapping point.
6
In
Active Directory domain
you can:
Type the fully-qualified domain name of your Active Directory domain.
Select from a list of already registered LDAP servers.
7
Next to
Container
, click
Add
and select a source container in the
Select Active Directory Container
dialog box,
then click
OK
.
8
To exclude specific subcontainers, click
Add
next to
Exceptions
and select a subcontainer to exclude,
then click
OK
.
9
Select whether to deploy agents automatically to new systems. If you do, be sure to configure the
deployment settings.
McAfee recommends that you do not deploy the agent during the initial
import if the container is large. Deploying the 3.62 MB agent package to
many systems at once may cause network traffic issues. Instead, import
the container, then deploy the agent to groups of systems at a time,
rather than all at once. Consider revisiting this page and selecting this
option after the initial agent deployment, so that the agent is installed
automatically on new systems added to Active Directory.
10
Select whether to delete systems from the System Tree when they are deleted from the Active
Directory domain. Optionally choose whether to remove agents from the deleted systems.
Organizing the System Tree
Creating and populating groups
12
McAfee
®
ePolicy Orchestrator
®
4.6.0 Software Product Guide
143