Hi,
Is it possible to synchronize AD groups with ePO groups? Because we have got domain policies enforced on OUs. In ePO we also have got different policies which should be enforced on different groups and we have got same groups in AD. What I need is to synchronize AD groups (which are under AD OUs) with ePO groups. Is it possible or should I do it manually?
Thanks,
There is an option in ad sync settings to pull systems and system tree structure. This will mirror your AD group in epo system tree. Be very careful doing this, if your systems are in a different system tree structure. What I would suggest before doing that is to turn off the epo server service (apache) on epo and any agent handlers to prevent clients from getting any policy changes. Then you can run your ad sync and once that reorganizes your system tree, make sure all the right policies and tasks are assigned properly. Then you can turn apache back on.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thank you for your reply.
I seem not to be able to find the option you are referring to. Could you please let me know what option and where allows us to "pull systems and system tree structure"?
Thank you in advance.
That is the option checked that I am referring to. You would choose systems and container structure, then second option move systems from current system tree location as I have checked.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thank you so much for your guide.
To me it seems that I am doing something wrong. If you kindly take a look at the screenshot attached I have got two groups in the root of AD but they are not synced at all. Could you please let me know what I am misunderstanding here?
Thank you in advance.
Which specific group names are you referring to?
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
I have got only two groups, "allow-usb" and "test-dlp" as you might see in the bottom of the picture. I want these two groups to be synced with McAfee System Tree.
Thank you
Those are user groups, not computers. The AD sync in system tree only syncs computers.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thank you for your reply.
So in that case groups cannot be synced at all and talking of groups is meaningless. Are there any other type of groups except what we see in my picture?
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: