AD Lightweight Directory Service (AD LDS) is a lighter version of Active Directory Domain Services that provides the means to maintain extranet directories separate from your Active Directory, create information consolidation stores, and authenticate web users with LDAP-based authentication. EmpowerID manages AD LDS in the same way that it manages an Active Directory account store.
This topic describes how to add AD LDS to the EmpowerID Identity Warehouse as a managed Account Store.
In the ADAM Server window that appears, do the following:
The image below shows what the screen looks like with the above selections made. Your values will differ accordingly.
This pane is used to set general configuration information for the Account Store.
Allow Business Role and Location Recalculation - Allows or disallows the Account Store to be used by the Role and Location Compiler and Role and Location Processor to determine the Business Roles and Locations that should be associated with a person.
To enable this function, click the Allow Business Role and Location Recalculation button to the left of the line and toggle it so that the green check is visible. You must also enable the Role and Location Compiler and Role and Location Processor jobs within the EmpowerID Servers and Roles interface of Configuration Manager.
This pane is used to enable or disable inventory of the Account Store as well as to set the run schedule for the EmpowerID Inventory Job.
Inventory Provision Request Workflow - This is the request workflow that is initiated when new accounts are discovered via the inventory feature. If you set this workflow, the Allow Automatic Person Provision and Allow Automatic Join Provision flags described below are ignored.
To set the workflow, click the Edit button to the right of the line, select a workflow from the Change Request Workflow window that opens, and then click OK. You can clear the selection by clicking on the red sphere to the right of the Edit button.
Location for New Inventory Provision - This allows you to a select the location that is to be the primary location for the people discovered during the inventory process. The default setting uses the Active Directory OU of the user object as the primary location. It is recommended that you leave this set to the default setting.
To pick a location other than the default, click the Edit button to the right of the line, select a location from the Business Role and Location Selector window that opens, and then click OK. You can clear the selection by clicking on the red sphere to the right of the Edit button.
Allow Automatic Person Join on Inventory - This allows EmpowerID to join newly discovered accounts to people during the inventory process if they meet the Join Rule as specified by the Custom_Account_InventoryInboxJoinBulk SQL stored procedure.
To enable automatic joining, click the button to the left of the line and toggle it so that the green check is visible.
RBAC-Assign Initial Group Membership On First Inventory - This converts each user account in an Active Directory group to a Resource Role Assignment for the person who owns the user account.
Use this pane to enable or disable and schedule group membership reconciliation for the domain. When this function is enabled, EmpowerID dynamically manages the membership of Active Directory groups, adding and removing users to and from groups based upon policy-based assignment rules.
To set the Group Membership Reconciliation Schedule, do the following: