
synchronize: your users may complain about authentication pop-ups that repeatedly fail, and
the subdomain groups may disappear from the Configuration > Group Policy > Default
Groups page. Although this situation may resolve itself automatically in certain circumstances,
it will likely recur. Enabling the global catalog on all domain controllers, including those
configured as backup domain controllers on your Active Directory server, is the only complete
solution for this problem.
1. Near the top of the page, next to User authentication via Active Directory, click On.
The three Active Directory Settings text boxes in the leftmost column become available.
Note: On a joined Web Appliance, the On/Off button is not functional. It only shows the status as
set on the Management Appliance.
2. [Optional] On a joined Web Appliance, you can change some of the Active Directory settings
to access a different domain controller by selecting the Configure Active Directory settings
locally check box.
Joined Appliance Considerations
The setting to Configure Active Directory settings locally is only available on a joined Web
Appliance. It is typically used to access a local Primary Domain Controller in a branch location
instead of the main Domain Controller in the central office. The settings are similar to those required
on an appliance that is not joined and are documented in steps 3 and 4. Read the remainder of
this section for information about configuration differences. Once these steps are complete, you
must verify and apply the settings on the joined appliance, as described in steps 5 and 6.
When Configure Active Directory settings locally is selected, only the Username and Password
text boxes are functional, allowing you to set a different Active Directory account for accessing
Active Directory authentication. LDAP user data is not synchronized on a joined Web Appliance;
this data is synchronized on the Management Appliance only and downloaded to the joined Web
Appliances.
Active Directory access from a joined Web Appliance is for authentication only, LDAP
synchronization is only performed by the Management Appliance.
On a joined Web Appliance with the Configure Active Directory settings locally check box
selected and the Auto-detect advanced settings check box cleared, only the Primary Domain
Controller and Active Directory Kerberos server text boxes are functional, allowing you to
select a different Active Directory server. The server that you select must not be a child domain
of the Active Directory domain, although it can be a secondary Domain Controller.
3. Enter the Active Directory Settings required to access the server:
■
Active Directory domain: Enter the domain name of your organization’s Active Directory
server.
■
Username: Enter the username to access the Active Directory server.
Important: To connect the appliance to an Active Directory domain, you must use a
pre-existing account on the Active Directory server with permissions to join a computer to
the Active Directory domain and to authenticate users. Also, if you intend to access the
Sophos Web Appliance | Configuration | 125