Connect to a Microsoft Active Directory instance
- Create a Microsoft Active Directory account that UEM can use. The account must meet the following requirements:
- It must be located in a Windows domain that is part of the Microsoft Exchange forest.
- It must have permission to access the user container and read the user objects stored in the global catalog servers in the Microsoft Exchange forest.
- The password must be configured not to expire and does not need to be changed at the next login.
- If you enable single sign-on, constrained delegation must be configured for the account.
- The UEM server must also be joined to the Active Directory domain.
- Review the port requirements for connections from UEM to Active Directory.
- If your organization uses a Microsoft Exchange resource forest, you must create a mailbox in the resource forest for each user account and associate them with the user accounts in the account forests. UEM uses the mailboxes to look up the user accounts in the individual domains. To authenticate users who log in to UEM, UEM must read the user information that is stored in the global catalog servers that are part of the resource forest. You must create an Active Directory account for UEM that is located in a Windows domain that is part of the resource forest. When you create the directory connection, you provide the Windows credentials for the Active Directory account, and, if required, the names of the global catalog servers that UEM can use.
- Do any of the following optional tasks:
- If you want to remove a directory connection, you must first remove all of the associated directory users and directory-linked groups from UEM.