Import LDAP User Groups for JIT Provisioning
Learn how to import LDAP user groups that contain the MSSQL users and groups that require Just in Time (JIT) provisioning.
This topic describes how to import LDAP user groups that contain the MSSQL users and groups that require JIT provisioning.
Follow these steps:
- Connect to PAM using the PAM client.
- Navigate toUsers,Manage User Groups,Import LDAP Groups. The LDAP Browser opens.
- SelectFile,Connect.
- In theConnect to LDAP Domaindialog that opens,select the LDAP domain that you configured to communicate with your LDAP domain server and selectOK.
- Locate and expand theUsersfolder from the LDAP tree in theleft pane.
- Locate and select the checkbox beside each user group that you want to import.
- (Optional) Review the device groups that are selected for import:
- SelectPAM Groups,Manage selected groups to register with the PAM appliance.The list of the Distinguished Names for all selected groups displays.
- Select and edit any group DN, or remove it from the staging list.
- SelectPAM Groups,Register selected groups with the PAM appliance. A window opens displaying a list of the staged groups from which you can monitor progress, and can display any messages that are associated with the actions.Note: When you import a group, all the users that are members of that group are imported into PAM automatically.
- SelectRegister Groupsin the lower-left corner. PAM imports the groups in the order that they are listed. The browser provides feedback and cancellation options throughout the process
- When the import is complete and verified, close the LDAP browser.
- In the PAM UI, navigate toUsers,Manage User Groups, and confirm that the imported user groups appear.
- Navigate toUsers,Manage Users, and confirm that the users in the imported user groups appear on the page.
- Update the definition of each imported user to define anRDP User Namethat specifies the LDAP domain name and the user name specified in the user information using the following format:LDAP_Domain\SAM_Account_NameFor example: JITDOMAIN\joeNote: If you have imported a large number of users, we recommend that you use the External API to automate the RDP User Name update for those users.
- Assign appropriate PAM roles to each user and group based on your organizational requirements.