1 2 Previous Next 11 Replies Latest reply on Jun 20, 2013 11:23 AM by wingnut144

    Configuring AD sync for client installs?

      I am taking over this EPO management from someone else, and would like to make sure all our workstations have the agent installed.  I looked at the AD sync, but when I run it manually, I get:

       

      6/19/13 9:54:35 AM Started: Synchronizing 1 groups
      6/19/13 9:54:35 AM Synchronizing 1 synchronized groups
      6/19/13 9:54:35 AM Synchronization point My Organization failed to connect to active directory server ICSSCODCp02, user: ICS\comadmin
      6/19/13 9:54:35 AM AD Synchronization (Synchronized 1 groups)

       

       








      Name

       

       

      Start Date

       

       

      End Date

       

       

      User Name

       

       

      Status

       

       

      Source

       

       

      Duration

       








       

       

      Am I missing something that would allow this to run?  What do I need to check to make sure its configured correctly??  Is it just a matter that the account comadmin may have a bad password??

        • 1. Re: Configuring AD sync for client installs?
          Laszlo G

          Hi wingnut144, did you registered the AD server under registered servers or did you just wrote down data under the sync group option?

           

          If you go under Menu->Configuration->Registered Servers you can set a new AD server and test its connection when configuring it so you'll be able to see if it can connecto or not to AD

          • 2. Re: Configuring AD sync for client installs?

            If I go to  Menu -> Configuration -> Registered Servers and select the option to add a new server, the only options I have are:

             

            ePO

            LDAP

            SNMP

             

            Am I missing a option?  It doesn't seem like LDAP would be the correct option to pick in this situation......

             

            Message was edited by: wingnut144 on 6/20/13 8:36:03 AM CDT
            • 3. Re: Configuring AD sync for client installs?
              Laszlo G

              That's right, there you have to choose LDAP and under the nex screen you'll be able to select the "Active Directory" option

              • 4. Re: Configuring AD sync for client installs?

                Ok, I created the LDAP/AD server, and tested the connection.  It says it was sucessful. 

                 

                But when I try the AD sync, I'm still getting:

                 

                6/20/13 8:05:35 AM Started: Synchronizing 1 groups
                6/20/13 8:05:35 AM Synchronizing 1 synchronized groups
                6/20/13 8:05:35 AM Synchronization point My Organization failed to connect to active directory server ICSSCODCp02, user: ICS\comadmin
                6/20/13 8:05:35 AM AD Synchronization (Synchronized 1 groups)

                 

                 








                Name

                 

                 

                Start Date

                 

                 

                End Date

                 

                 

                User Name

                 

                 

                Status

                 

                 

                Source

                 

                 

                Duration

                1 thing I'm confused about, our organization has its its own OU in the structure, we share the AD system with a bunch of different agencies.  Will this sync ALL those users with my ePO system?  I don't see a way to just select our own OU

                 

                Message was edited by: wingnut144 on 6/20/13 9:11:32 AM CDT
                • 5. Re: Configuring AD sync for client installs?
                  Laszlo G

                  Under the AD synced group details you should use the "Use registered LDAP server" option instead of "Use domain" so you won't need to write down user and password again.

                  • 6. Re: Configuring AD sync for client installs?

                    I guess I'm not seeing what you're referring to........

                     

                    If I edit the AD sync server task, which is what I think you're talking about, there is nothing that says 'use registered LDAP server'..........

                    • 7. Re: Configuring AD sync for client installs?
                      Laszlo G

                      This is because you are setting the automated task for Ad sync but you haven't defined how it will synced yet.

                       

                      First of all go under system tree and select the base group you want to be synced with AD and, on the right, go to the "Group Details" tab:

                       

                      AD_1.JPG

                      Once you click on teh "edit" link you will be able to set the AD sync user and password:

                       

                      AD_2.JPG

                       

                      After this just go down and select the root container you want to sync computers from and next to the bottom you'll find the "

                       

                      Finally you just need to click on "Save" at the bottom and the automated task will execute the AD sync task whenever you want

                      • 8. Re: Configuring AD sync for client installs?

                        That worked perfectly!  Thanks for all your help 

                        • 9. Re: Configuring AD sync for client installs?

                          Ok, so it imported the missing computer names, they still show as 'unmanaged' even though the option to install the client was selected.

                           

                          Might this be because the machines are not turned on?  If so, will the client be installed automatically when those computers come on?  Or will I need to push the client out to those unmanaged machines manually at a later time?

                          1 2 Previous Next