Connect to a Microsoft Active
Directory instance
Microsoft Active
Directory
instanceThe task below applies to a
UEM
on-premises environment. In a UEM Cloud
environment, install and configure the BlackBerry Connectivity Node to connect to your company directory.- Create aMicrosoft Active Directoryaccount thatUEMcan use. The account must meet the following requirements:
- It must be located in aWindowsdomain that is part of theMicrosoft Exchangeforest.
- It must have permission to access the user container and read the user objects stored in the global catalog servers in theMicrosoft Exchangeforest.
- The password must be configured not to expire and does not need to be changed at the next login.
- If you enable single sign-on, constrained delegation must be configured for the account.
- TheUEMserver must also be joined to theActive Directorydomain.
- If your organization uses aMicrosoft Exchangeresource forest, you must create a mailbox in the resource forest for each user account and associate them with the user accounts in the account forests.UEMuses the mailboxes to look up the user accounts in the individual domains. To authenticate users who log in toUEM,UEMmust read the user information that is stored in the global catalog servers that are part of the resource forest. You must create aMicrosoft Active Directoryaccount forUEMthat is located in aWindowsdomain that is part of the resource forest. When you create the directory connection, you provide theWindowscredentials for theMicrosoft Active Directoryaccount, and, if required, the names of the global catalog servers thatUEMcan use.
- In theUEMmanagement console, on the menu bar, clickSettings > External integration > Company directory.
- Click> Microsoft Active Directory connection.
- In theDirectory connection namefield, type a name for the directory connection.
- In theUsernamefield, type the username of theMicrosoft Active Directoryaccount.
- In theDomainfield, type the name of theWindowsdomain that is part of theMicrosoft Exchangeforest, in DNS format (for example, example.com).
- In thePasswordfield, type the account password.
- In theKerberos Key Distribution Center selectiondrop-down list, do one of the following:
- To permitUEMto automatically discover the key distribution centers (KDCs), clickAutomatic.
- To specify the list of KDCs forUEMto use for authentication, clickManual. In theServer namesfield, type the name of the KDC domain controller in DNS format (for example, kdc01.example.com). Optionally, include the port number that the domain controller uses (for example, kdc01.example.com:88). Click to specify additional KDC domain controllers that you wantUEMto use.
- In theGlobal catalog selectiondrop-down list, do one of the following:
- If you wantUEMto automatically discover the global catalog servers, clickAutomatic.
- To specify the list of global catalog servers forUEMto use, clickManual. In theServer namesfield, type the DNS name of the global catalog server that you wantUEMto access (for example, globalcatalog01.example.com). Optionally, include the port number that the global catalog server uses (for example, globalcatalog01.com:3268). Click to specify additional servers.
- ClickContinue.
- In theGlobal catalog search basefield, do one of the following:
- To permitUEMto search the entire global catalog, leave the field blank.
- To control which user accountsUEMcan authenticate, type the distinguished name of the user container (for example, OU=sales,DC=example,DC=com).
- If you want to enable support for global groups, in theSupport for global groupsdrop-down list, clickYes.If you want to use global groups for onboarding, you must selectYes. To configure a global group domain, in theList of global group domainssection, click . In theDomainfield, click the domain that you want to add. The default selection for theSpecify username and password?field is No. If you keep this default selection, the username and password for the forest connection is used. If you select Yes, you must provide valid credentials for anActive Directoryaccount in the domain that you selected. In theKDC selectionfield, you can select Automatic to permitUEMto automatically discover the key distribution centers, or Manual to specify the list of KDCs forUEMto use for authentication. ClickAdd.
- If your environment contains aMicrosoft Exchangeresource forest, to enable support for linkedMicrosoft Exchangemailboxes, in theSupport for linked Microsoft Exchange mailboxesdrop-down list, clickYes.To configure theMicrosoft Active Directoryaccount for each forest that you wantUEMto access, in theList of account forestssection, click . Specify the user domain name (the user may belong to any domain in the account forest), and the username and password. If necessary, specify the KDCs that you wantUEMto search. If necessary, specify the global catalog servers that you wantUEMto access. ClickAdd.
- To enable single sign-on, select theEnable Windows single sign-oncheck box. For more information about single sign-on, see Configure single sign-on for BlackBerry UEM in the Administration content.
- To synchronize more user details from your company directory, select theSynchronize additional user detailscheck box. The additional details include company name and office phone.
- ClickSave.
- ClickClose.
- Do any of the following optional tasks:
- If you remove a directory connection, all users that were added toUEMfrom that directory will be converted to local users. Once users are converted to local users they can't be converted back to directory linked users, even if you later re-add the company directory connection. Users will continue to function as local users butUEMwill not be able to synchronize updates from the company directory.