aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
LDAP User Synchronization
Notes:
1. Missing LDAP Attributes and LDAP Attributes with empty values initiate different
synchronization behaviors. If a mapped Attribute is missing on the LDAP Server, the aXsGUARD
Identifier Property is not updated (i.e. the existing value remains). If a mapped Attribute is present
on the LDAP Server with an empty value, the aXsGUARD Identifier Property is updated with the
empty value, (i.e. any existing value is overwritten).
2. If an aXsGUARD Identifier User Account has a Synchronization Profile ID, any manual changes
made by the administrator to properties which are mapped to LDAP Attributes in the profile are
overwritten during synchronization.
14.5
Deleting User Accounts
An activated Synchronization Profile deletes a User Account on the aXsGUARD Identifier if it has the
Synchronization Profile ID, but the corresponding User Account cannot be found on the LDAP Server. This may
occur under the following circumstances:
the User Account has been removed from the LDAP Server
the User Account on the LDAP Server has been moved from the Search Base defined in the profile
the User Account on the LDAP Server has been changed and no longer matches the profile's filter
Synchronization Profile settings have been changed, e.g. the Search Base or filter entries.
14.6
Synchronization Frequency
Synchronization frequency can be configured up to 24 times per day and happens at 14 minutes past the hour, (at
intervals depending on the frequency setting). The aXsGUARD Identifier also checks at five minute intervals
whether any Synchronization Profiles have been changed, and if so initiates a synchronization immediately.
14.7
Multiple Synchronization Profiles
Multiple Synchronization Profiles can be configured. This has three purposes:
1.
To manage synchronizations from multiple LDAP Servers to different domains on a single aXsGUARD
Identifier.
2.
To filter User Accounts on more than one value of a particular LDAP Server Attribute, e.g. to synchronize User
Accounts for which the email address attribute matches both 'able.be'
or
'skynet.be' endings. Entering both
these specifications for a filter match in a single Synchronization Profile would only retrieve accounts which
©
2009 VASCO Data Security
85