3.
Ensure that the directory DN of at least one user and the DN of a security group that contains that user
are available. This information is used for validating the directory setup.
4. Install an iLO license that enables Directory Service Authentication
5. Verify that the correct DNS server is specified on the iLO network settings IPv4 or IPv6 page
.
Process overview: Configuring iLO for schema-free directory integration
Procedure
1. Configure the iLO schema-free directory parameters.
2. Configure directory groups.
Schema-free nested groups (Active Directory only)
Many organizations have users and administrators arranged in groups. This arrangement is convenient
because you can associate a group with one or more iLO systems. You can update the configuration by
adding or deleting group members.
Microsoft Active Directory supports placing one group in another group to create a nested group.
In a schema-free configuration, users who are indirect members (a member of a group that is a nested
group of the primary group) are allowed to log in to iLO.
Nested groups are not supported when you use CAC Smartcard authentication.
HPE Extended Schema directory authentication
Using the HPE Extended Schema directory authentication option enables you to do the following:
• Authenticate users from a shared, consolidated, scalable user database.
• Control user privileges (authorization) by using the directory service.
• Use roles in the directory service for group-level administration of iLO management processors and
iLO users.
Advantages of HPE Extended Schema directory integration
• Groups are maintained in the directory, not on each iLO.
• Flexible access control—Access can be limited to a time of day or a certain range of IP addresses.
Process overview: Configuring the HPE Extended Schema with Active
Directory
Procedure
1. Plan
Review the following:
Process overview: Configuring iLO for schema-free directory integration
315