Setup guide TELUS AD Sync June 2013
TELUS AD Sync User Guide. The AD Sync Tool must be downloaded onto your organization s Domain Controller. Please call TELUS at 1 877 846 4456 to have this feature provisioned onto your account. About TELUS AD Sync. AD Sync allows you to synchronize your localized Domain Controller to the TELUS-hosted Domain Controller. Your company s Domain in the hosted Domain Controller will be regularly updated with any user name and password changes that have been modified in your domain controller. All hosted services that are provisioned to the users will be configured directly to the user objects that are saved in the hosted domain controller. Note: The Customer Administrator accounts within UC Management Centre do not get synced. Once provisioned, your administrator will have access to download and configure the TELUS AD Sync Tool to your existing Domain Controller(s). The TELUS AD Sync tool must be installed on each Domain Controller in the customer Domain. TELUS AD Sync Function. AD Sync allows you to manage your users on your existing local domain controller and synchronize these users to the hosted domain controllers available on the TELUS UC Management Centre. This is achieved by setting up an interface between the customer s Domain Controller and the TELUS-hosted Domain Controller. The interface is a one way feed, where any user updates that are made on the Customer Domain Controller are synchronized to the TELUS-hosted environment. The specified user s Active Directory accounts are duplicated within in the hosted domain and the services are configured to these replica user accounts. When a user changes their passwords in their own Domain, the password change is updated in the TELUS-hosted domain. Synchronized users properties cannot be amended on the TELUS UC Management Centre; any user change must be completed on their existing domain controller. Activating the TELUS AD Sync service disables the ability to modify a user and a users password from the TELUS UC Management Centre. A TELUS AD Sync user s status can now be updated so that it can become a hosting user. 2
Managing Password Policies. The password complexity and expiry policy are essentially controlled by your on-premises Active Directory. In order for the solution to work, the TELUS hosted Active Directory must have either the same or a more lenient password policy than your password policy in order for passwords to be successfully synchronized. The password policies of the supplied credentials are dependent on the TELUS hosted Active Directory password policy. This means that if the credentials from the user do not meet the policy requirements of the TELUS hosted Active Directory, the password sync will fail. AD Sync Installation. TELUS recommends that a group called TELUS AD SYNC be present and used for syncing users on a local domain. After installation the Domain controller will require a restart. Once the TELUS AD Sync Service is provisioned and the TELUS AD SYNC user group is created, you will be able to access the TELUS AD Sync tool s installer from the TELUS AD Sync Download page on the TELUS UC Management Centre. To access this screen, select Services > Active Directory (AD Sync) > Download from the top menu. Before downloading the user sync tool, your account property Allow Passwords to never Expire must be set to True. If this is set to False, errors will appear in your Event Viewer and no users will appear on Cortex. 3
Downloading the TELUS AD Sync Tool. 1. Select the correct Windows version that is running on the Domain Controller (this is the Domain Controller on the customer s server) and click on Download. 2. Select Run > Next. 3. Accept the terms and conditions of installing the TELUS AD Sync tool. 4. Ensure that the Customer property is populated with your Customer Name. Enter the Password for the Administrator user. Select Next. 5. AD Sync now needs to be configured with what information should be passed from the Active Directory to the Control Panel. By default, password changes are always enabled. Enable Watch for changes to users if user properties changes are to be submitted to and synchronized with the TELUS UC Management Centre. The frequency of the Sync User actions can also be adjusted. The default value is 5 seconds. This value should not need to be changed. Select Next. 4
6. The Wizard allows you to define which User Groups will be excluded/included by the TELUS AD Sync Tool. To search for a Group, enter TELUS AD SYNC > Find Now. Results from the Search will be displayed in the Groups Found property. Click on the TELUS AD SYNC group and select Add to either exclude users or include users. Select Next. 7. The Wizard will confirm the connection details for the Cortex Tool to connect to the hosting environment. Do not change these settings as it may stop the User Sync tool from working successfully. Select Next, the Wizard test the connectivity to the hosting environment using the specified parameters. If no error message appears and the Wizard navigates to the Destination Folder step, the connectivity to the hosted environment is working. 5
8. Enter the destination folder where the TELUS AD Sync Tool will be installed. The default setting is C:\Program Files\TELUS Sync\ > Next. 9. Select Install to commence the installation. Once the installation is complete, select Finish to exit the Setup Wizard. To start the TELUS AD Sync Tool, the Domain Controller needs to be re-started. 10. Once the Domain Controller is restarted, all users that are already saved in the Active Directory will appear in the TELUS UC Management Centre. Users will not be able to log in or use the TELUS UC Management Centre until they have changed their password. TELUS recommends that the system administrator force a password change upon next login for users using the service. 6
Change User s Status From TELUS AD Sync to Hosting. A TELUS AD Sync user s status can be updated so that it can become a hosting user. This means the user account on the control panel is no longer sync d with the remote domain controller and the user s details and password will be managed in Cortex. 1. Select Edit User for the user for whom you want to disable AD Sync. 2. At the top of the User Details screen, the control panel confirms that the user is an AD Sync d user. Click on Disable AD Sync. 3. The control panel will verify that you want to remove AD Sync from the user s account. Select OK if you want to proceed with the change. The control panel s page will refresh and remove the AD Sync User wording at the top of the screen and the user s details are now editable. 4. Select Provision to update the user account. (This should be selected even if no changes were made to the user s properties). 7
TELUS AD Sync Uninstall. Uninstalling AD Sync is a multi step process that requires co-ordination with TELUS operational support staff in order to ensure that there are no password synchronization issues. Use the following steps to successfully uninstall TELUS AD Sync: 1. Change all AD Sync users to Hosted Users by following steps above. 2. Uninstall the AD Sync tool from your Domain Controller. 3. Call TELUS at 1 877 846 4456 and request removal of the AD Sync service. The TELUS Customer Service Administrator will open a ticket and facilitate the removal of the service. After TELUS removes the AD Sync service, your AD Sync Tool page should disappear. Limitations: There are some known limitations with the User Sync Tool: Cannot use the Copy User functionality for a synced user Enable & Disable User functions on the UC Management Centre will not have any affect on the user s status in the customer s active directory. There is no data being passed back to the customer s environment. Changes to Group management, ie. moving users into a group will not be passed to the UC Management Centre. An actual change needs to take place on the user s AD properties for the change to be passed through. 8