Reasons to use this feature¶
User account management can be an ongoing challenge for On-Premise administrators:
- Onboarding: New employees get hired, contractors start work, customers or partners need to be granted access to systems.
- Management: Users are dynamic; they change names, addresses, responsibilities, and more. Changes experienced by users in the physical world must be reflected by user objects on systems and applications.
- Support: Users will experience problems with systems and applications. For example, they may forget their password or require new security entitlements. “End user support” means changing user data in systems and applications, resetting user passwords, and so on, to resolve user problems.
- Deactivation: Users have a finite lifespan and normally an even shorter relationship with an organization where a system or application is managed. When users leave; through termination, resignation, retirement, and so on; their access to systems and applications should likewise be deactivated.
Consider a situation where you need to roll out aPriori to many employees. You can define an LDAP group called "aPriori Users" consisting of employees who require aPriori user accounts. As employees join or leave the organization, they are added or removed from this LDAP group. Without aPriori LDAP synchronization, an aPriori administrator would need to update the aPriori user accounts from LDAP manually. In a large organization, this could be a frequent occurrence. With LDAP Synchronization, you can define jobs that perform this task automatically on a set schedule.
Features¶
aPriori LDAP Synchronization is a web-based service that uses the same infrastructure and has the same look and feel as all aP Admin modules. This allows an administrator to:
- Configure and schedule multiple synchronization jobs for one or more LDAP connections.
- View the status of synchronization activity for all connections.
- Review the history of prior sync jobs, including success and failure details.
- Report synchronization details such as how many users were added, deleted, or modified, etc.