Dell EqualLogic PS6210XS EqualLogic Group Manager Administrator s Guide PS Ser - Page 65

Modify Active Directory Accounts and Groups, Test the Active Directory Server

Page 65 highlights

9. Select whether to use the default port for the selected protocol, or specify a different port. 10. Type the Base DN for the Active Directory server, or select Get Default to use the default value. The Base DN can be up to 254 ASCII characters. 11. Select whether to use anonymous connections to the server or type a Bind DN. 12. If a Bind DN is specified, type the Bind password. Passwords can be up to 63 ASCII characters. 13. To test the new Active Directory settings, click the Test AD settings button. Group Manager tests the Active Directory settings for all servers. If authentication fails, a dialog box opens, listing the Active Directory servers with which connections could not be established. If no connections can be established, you can accept the configuration as is or click Cancel and check the Active Directory settings again. 14. Click OK. Modify Active Directory Accounts and Groups When you modify Active Directory accounts and groups, the following restrictions apply: • You cannot change the account name. Instead, you must delete the account and then add it back with the updated name in Active Directory. • You cannot modify cached accounts. You can only view their configuration details. • You cannot change the account type. Instead, you must delete the account and recreate it with the desired account type. When you modify Active Directory groups, the following considerations apply: • An Active Directory security/distribution group is added to the PS Series group with the attribute that all members of the AD group now have access. If changes are made to any members of the group, the changes are automatically integrated the next time the members log in to the group. - When a new user is added to the Active Directory group, the user automatically has access to the group. - When an Active Directory user is removed from the AD group, the user no longer has access to the group. - When the user name of a current member of the AD group is modified in Active Directory, no changes need to be made for that user on the PS Series group. • When you change the name of the Active Directory group, the group must be deleted from the PS Series group and then re- added with the new name. To change an Active Directory account or group: 1. Click Group → Group Configuration. 2. Click the Administration tab. 3. In the Accounts and Groups panel, select either: • All accounts and groups to view both local and remote accounts. • Active Directory users to view only Active Directory user accounts. • Active Directory groups to view only Active Directory group accounts. 4. Select the account and click Modify. The Modify Administration Account dialog box opens. In the dialog box, use the Account type section to change attributes of the account type: • If the account type is Pool administrator or Volume administrator, you can use the Pool access section to specify the pools to which the account has access and the storage quota for the account. • If the account type is Pool administrator, you can use the Additional access section to give the account read-only access to the entire group. You can also grant read-only accounts permission to save diagnostics and save config from this dialog box. 5. To change replication partners for a volume administrator, click the Replication Partners tab and change the selections. NOTE: Only users with group administrator privileges can modify the NAS container replication configuration. 6. Click OK. Test the Active Directory Server After you have added the Active Directory server, test your connection by clicking Test AD settings. The firmware tests all of the Active Directory servers in the list and reports the results of each connection attempt. About Group-Level Security 65

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355

9.
Select whether to use the default port for the selected protocol, or specify a
different
port.
10.
Type the Base DN for the Active Directory server, or select
Get Default
to use the default value. The Base DN can be up to
254 ASCII characters.
11.
Select whether to use anonymous connections to the server or type a Bind DN.
12.
If a Bind DN is
specified,
type the Bind password. Passwords can be up to 63 ASCII characters.
13.
To test the new Active Directory settings, click the
Test AD settings
button. Group Manager tests the Active Directory settings
for all servers. If authentication fails, a dialog box opens, listing the Active Directory servers with which connections could not
be established. If no connections can be established, you can accept the
configuration
as is or click
Cancel
and check the
Active Directory settings again.
14.
Click
OK
.
Modify Active Directory Accounts and Groups
When you modify Active Directory accounts and groups, the following restrictions apply:
You cannot change the account name. Instead, you must delete the account and then add it back with the updated name in
Active Directory.
You cannot modify cached accounts. You can only view their
configuration
details.
You cannot change the account type. Instead, you must delete the account and recreate it with the desired account type.
When you modify Active Directory groups, the following considerations apply:
An Active Directory security/distribution group is added to the PS Series group with the attribute that all members of the AD
group now have access. If changes are made to any members of the group, the changes are automatically integrated the next
time the members log in to the group.
When a new user is added to the Active Directory group, the user automatically has access to the group.
When an Active Directory user is removed from the AD group, the user no longer has access to the group.
When the user name of a current member of the AD group is
modified
in Active Directory, no changes need to be made for
that user on the PS Series group.
When you change the name of the Active Directory group, the group must be deleted from the PS Series group and then re-
added with the new name.
To change an Active Directory account or group:
1.
Click
Group
Group
Configuration
.
2.
Click the
Administration
tab.
3.
In the Accounts and Groups panel, select either:
All accounts and groups
to view both local and remote accounts.
Active Directory users
to view only Active Directory user accounts.
Active Directory groups
to view only Active Directory group accounts.
4.
Select the account and click
Modify
. The Modify Administration Account dialog box opens.
In the dialog box, use the Account type section to change attributes of the account type:
If the account type is Pool administrator or Volume administrator, you can use the Pool access section to specify the pools
to which the account has access and the storage quota for the account.
If the account type is Pool administrator, you can use the Additional access section to give the account read-only access to
the entire group.
You can also grant read-only accounts permission to save diagnostics and save
config
from this dialog box.
5.
To change replication partners for a volume administrator, click the
Replication Partners
tab and change the selections.
NOTE: Only users with group administrator privileges can modify the NAS container replication
configuration.
6.
Click
OK
.
Test the Active Directory Server
After you have added the Active Directory server, test your connection by clicking
Test AD settings
. The
firmware
tests all of the
Active Directory servers in the list and reports the results of each connection attempt.
About Group-Level Security
65