User management with Active Directory Definitions Primary Group A user s primary group is used by Technesis for reporting. The Workgroup reports refer to a user s primary group. Group Memberships A user belongs to a least one group (the Primary group) but is not limited to how many groups they are part of. Technesis uses group membership for rules based printing. Protected Users Users with status protected cannot have their Technesis User data changed. PINs Personal Identification Numbers (PIN) are used for tracking and costing of walkup copying, faxing, scanning activities at MFPs. How Technesis works with Active Directory Technesis Print Control System imports users, groups and Personal Identification Numbers (PINs) from Active Directory. Technesis calls this process Synchronization. Here is the logic behind Technesis Synchronization. All Active Directory users are imported into Technesis as users Technesis populates User fields with First name, last name, Active Directory login, employee#, email address. Synchronization rules are set to import groups and assign primary groups Synchronization rules are set to import PINs from Active Directory Synchronization rules are set to generate PINs Synchronization is manual Changes to user profiles in Active Directory govern the changes to the user profiles in Technesis Console when synchronizing. If there are changes to a user s data in Technesis, they are overridden by the next synchronization, UNLESS the user is PROTECTED. What s covered in this walkthrough This walkthrough guides the setup of Users in Technesis Print Control System. The source for user data is a Windows Active Directory user list. Topics covered are: Synchronization Adding group synchronization rules Adding individual synchronization rules (PIN codes) Managing Users and Groups Technesis, Inc. Sept 2008 Page 1 of 10 PCS v5.6 Walkthrough User Management with Active Directory
Background information on Active Directory and ADSI Technesis Synchronization is dependent on accurate and up to date user information in Windows Active Directory. This section reviews the Active Directory User Profile and importing into Technesis. Microsoft ADSI Editor is a tool for Administrators to perform more sophisticated user management tasks. Here is the Active Direct Users and Computers Control Panel. Technesis will import from Active Directory all users except the IUSR and IWAM users. Administrators set rules governing which OU s, Distribution Groups, Security Groups to include For OUs, child OUs are imported automatically Below is the User Properties for Oscar OMalley. An Active Directory user s first name, last name, email address and login are imported into Technesis. Any other fields from the user s properties are brought into groups and grouping. Again, depending on reporting and rules based printing requirements, any of the user properties are imported as primary or membership groups. Technesis, Inc. Sept 2008 Page 2 of 10 PCS v5.6 Walkthrough User Management with Active Directory
ADSIEdit ADSIEdit is an optional tool in MS Windows 2003. It shows the exact field names and values for the Active Directory user properties. Once installed, run ADSIEDIT.MSC. Here are the user properties from ADSIEdit. Technesis imports the employeenumber value into the User s employee number field in the Technesis database. The attribute is the actually field name in Active Directory. Some Active Directory attributes are listed in the table below as well ADSI Attribute Businesscategory company department description division employeeid employeenumber L physicaldeliveryofficename title Description Business category label Company name Department name Description Division name Employee ID value Employee number Location (City) Office Title Technesis, Inc. Sept 2008 Page 3 of 10 PCS v5.6 Walkthrough User Management with Active Directory
Background information on Active Directory and PIN codes Technesis Synchronization contains Individual Rules that govern PIN code importing or PIN code generation. The options for PIN code management are: Set an individual rule that instructions Technesis to import PIN codes from an Active Directory user attribute (example: pager, employeeid) Set an individual rule that instructs Technesis to automatically generate PIN codes (3/4/5/6 digits) Set an individual rule that instructs Technesis to send an email notifying individuals of their PIN codes. Special situations where Technesis and external systems are used to manage users, groups and Pin codes There will be various situations where the requirement is to use Active Directory for users, groups and a financial/accounting system for PIN codes. Although many organizations express the interest to deploy one system today to manage all their user information for print and copy tracking, the reality is that many organizations maintain separate systems, but require comprehensive reporting, rules based printing, and cost accounting for walkup activities. The following table is a reference guide to setting up Technesis Synchronization based on user, groups and PIN code management requirements. Active Directory Users, Groups, and PIN code requirements External systems Users, Groups, and PIN code requirements Action(s) to take to import Users, Groups and PIN codes into Technesis You want Active Directory to manage groups, users and PIN codes. You don t have any requirements for another system in managing users and PIN codes. Synchronize in Active Directory. Set Group synchronization rules. Set Individual synchronization rules. You want Active Directory to manage groups and users. You have another system that manages PIN codes. Synchronize in Active Directory. Set Group synchronization rules. Create CSV file called employees.csv. Each employee must have a unique PIN code. Each employee number from CSV file must match employee number in Active Directory. Save file to the transact folder. You don t have any requirements of Active Directory You have another system that manages PIN codes Create CSV file called employees.csv. Each employee must have a unique PIN code. Save file to the transact folder. Technesis, Inc. Sept 2008 Page 4 of 10 PCS v5.6 Walkthrough User Management with Active Directory
Important considerations when using Active Directory for users and groups, CSV Import for PIN codes Due to the nature of managing data from different sources, it is necessary to provide general rules for data management and importing Users, Groups and PIN codes into Technesis Print Control System for use. Please follow these rules carefully when preparing for data synchronization. 1. The most important rule in the combination of Active Directory, CSV Import and Technesis is for all users they have a PIN code, their employee numbers in Active Directory and CSV Import file(s) must match. 2. The first import must be an Active Directory synchronization. There is a systems logic that is applied for CSV Imports. 3. Any subsequent synchronizations with Active Directory will update the user profile in Technesis. The PIN code will not be changed through Active Directory synchronization 4. Any subsequent CSV Imports will overwrite user details. This is by design. The latest updates can come from either Active Directory or CSV Imports. Active Directory User Technesis Active Directory User Employee number = CSV Import Employee number 5. If login names match between Active Directory synchronization and CSV import, the Active Directory details are saved over the CSV import details. 6. Any employee numbers from CSV import that are not in Active Directory result in new users being added into Technesis, but these users will not be updated with any future Active Directory synchronizations. This user will need to be deleted, then re-created via Active Directory synchronization. 7. If the CSV Import contains blanks for PIN Code, Technesis automatically generates a PIN code. 8. If the plan is to have Technesis automatically generate PIN codes, and then change over to CSV Import for PIN codes, then: a. Delete all users in Technesis Console b. Change the synchronization rules c. Synchronize with Active Directory d. Import CSV file with new PIN codes Setting up Technesis Console for emailing Technesis Print Control System sends email notifications. In order to send emails, a valid email server, a valid credential, and a reply to address must be provided in Technesis Console. In Technesis Console, go to System Settings>Company Info. 1. Select Edit. 2. Enter in the SMTP Server address. 3. Enter in valid user and password. 4. Enter in a Reply to address. 5. Test and Save. Technesis, Inc. Sept 2008 Page 5 of 10 PCS v5.6 Walkthrough User Management with Active Directory
The focus of the walkthroughs will be in the Users Section of Technesis Console. Click on the Users Bar and the section expands. To get started, click on Synchronize Synchronization This is the main synchronization page. Synchronization is performed at the root level or at subdomains. Type in the domain(s) to perform synchronization. Separate multiple domains by a semicolon (;). Certain domains require credentialing before synchronization. You will type in credentials after you completed defining the Importing Rules. The third section is Importing Rules. There are two types of Importing Rules: Group rules These are the rules governing which Active Directory attributes to import as groups in Technesis. Also, a user s Primary Groups are set via Group rules. Individual rules These are the rules governing how Technesis generates PIN codes or which Active Directory attribute to import as a PIN code. The up and down arrows allow for prioritizing of rules affecting the order in which primary groups are determined. To add a rule, click on Add. To start synchronizing, click on Synchronize. Technesis, Inc. Sept 2008 Page 6 of 10 PCS v5.6 Walkthrough User Management with Active Directory
Adding group synchronization rules Importing Organizational Units (OU s). 1. Select Group Rules. 2. Select organizational unit. 3. If there is a specific OU structure to import, enter the value. 4. Technesis automatically imports child OUs. 5. Primary Group designation note If you want workgroup reports to be organized by OU, make sure to enable OU for the user s primary group. 6. Click on Save Importing Active Directory Attributes. 1. Select Group Rules. 2. Select Domain Object Property. 3. Select an attribute. 4. Primary Group designation note If you want workgroup reports to be organized by this attribute (ie by City), make sure to enable OU for the user s primary group. 5. Click on Save. Importing Distribution and Security Groups 1. Select Group Rules. 2. User defined groups. 3. Click on Save To exclude certain distribution and security groups, choose the option Excluded User-Defined Group. Importing Built in groups. 1. Select Group Rules. 2. Select Built in Group. 3. Select Built in Group. 4. Primary Group designation note If you want workgroup reports to be organized by groups, make sure to enable Built in Groups for the user s primary group. 5. Click on Save Technesis, Inc. Sept 2008 Page 7 of 10 PCS v5.6 Walkthrough User Management with Active Directory
The list of importing rules is displayed in the main Synchronization page. You can prioritize them by selecting and using the up and down arrows. Prioritizing is very important particular if you have multiple rules enabled for primary group designation. Prioritization effects the order Technesis searches the Active Directory for determining a user s primary group. Click on Synchronize to being synchronization. The rules are automatically saved for the next time you navigate to this page. Adding individual synchronization rules (PIN codes) Importing employee number 1. Select User Rules. 2. Select Employee Number 3. Enter in Active Directory Attribute. 4. Click on Save. Employee Number importing is extremely important if the requirement is to use Active Directory and an external system to manage PIN codes. Technesis, Inc. Sept 2008 Page 8 of 10 PCS v5.6 Walkthrough User Management with Active Directory
Importing PIN codes from Active Directory Attribute: 1. Select User Rules. 2. Select Pin Importing. 3. Type in the Active Directory attributes. 4. Click on Save Technesis will automatically generate a PIN for those Active Directory Users without a value in the specified attribute field. Generating PIN codes 1. Select User Rules. 2. Select PIN Generation. 3. Select 3/4/5/6 Digit Pin 4. Select Save. Technesis recommends using PIN Generation and PIN Notification rules together. Generating PIN Notification email 1. Select User Rules. 2. Select Pin Notification. 3. Click on Save to Activate. With PIN Notification activated, Technesis sends an email alerting the user after every PIN change to that user s details in Technesis Console. Technesis, Inc. Sept 2008 Page 9 of 10 PCS v5.6 Walkthrough User Management with Active Directory
Managing users and groups Users are managed in Technesis Console in the Users section. Important User management considerations Users must have employee numbers in Technesis if the requirement is to use CSV Imports for PIN Codes Users must have valid email addresses in Technesis if the requirement is to have Technesis generate PINs and notify users of PIN codes. Email Use this feature if you need to send emails to end users of their PIN Codes, Select users, then click on Email, Reset PINs Use this feature if you need to reset user PIN codes. Select users, then click on Reset PINs Protected Users Users with status protected cannot have their Technesis User data changed. To protect users, select users, then click on Protect Groups dropdown Filters the users by their primary group Primary Group A user s primary group is used by Technesis for reporting. The Workgroup reports refer to a user s primary group. To change a user s primary group, select the users, then choose the group in the dropdown, then click on Primary. Group Memberships A user belongs to a least one group (the Primary group) but is not limited to how many groups they are part of. Technesis uses group membership for rules based printing. To add users to groups, select the users, then choose the group in the dropdown, then click on Add members. Technesis, Inc. Sept 2008 Page 10 of 10 PCS v5.6 Walkthrough User Management with Active Directory