The management agent for Active Directory global address list (GAL) is preconfigured with rules that synchronize data in Active Directory forests. These forests are enabled for Microsoft Exchange Server 2000, Microsoft Exchange Server 2003, and Microsoft Exchange Server 2007 to create a GAL across multiple forests.

Connected data source support

Windows 2000 Server Active Directory forest enabled for Microsoft Exchange Server 2000, Microsoft Exchange Server 2003, or Microsoft Exchange Server 2007 to create a GAL across multiple forests.

Windows Server 2003 Active Directory forest enabled for Microsoft Exchange Server 2000, Microsoft Exchange Server 2003, or Microsoft Exchange Server 2007 to create a GAL across multiple forests.

Windows Server 2008 Active Directory forest enabled for Microsoft Exchange Server 2000, Microsoft Exchange Server 2003, or Microsoft Exchange Server 2007 to create a GAL across multiple forests.

Management agent type

This is a call-based management agent.

Schema

The schema is generated based on the dynamic discovery of the data source by the management agent. When you refresh the schema for this management agent, the connected data source schema is rediscovered, the current management agent schema is updated, and Management Agent Designer starts. In Management Agent Designer, you can correct any inconsistencies that were introduced by the updated schema, such as deleted object types or deleted attributes.

Remarks

  • As a security best practice, use minimal Active Directory credentials when creating an Active Directory GAL management agent. If you are creating an Active Directory GAL management agent to only import data into FIM, supply credentials for any valid user account (nonadministrator account) in the target forest to successfully enumerate that forest's directory partitions and read the schema directory partition. However, if you want to use FIM to write to objects in an Active Directory forest, the user account credentials supplied in the Active Directory GAL management agent must, at a minimum, have been delegated the appropriate authority to modify objects in a particular container. Do not use an account in the management agent that is a member of the Domain Admins group or the Enterprise Admins group, unless it is the only available option.

In addition, the user credentials that are used in the Active Directory GAL management agent must have the following permissions and privileges:

  • The same permissions as dirsync control. Dirsync control is a Lightweight Directory Access Protocol (LDAP) server extension that enables an application to search an Active Directory partition for objects that have changed since a previous state.

  • The Read Only Delegation permission on the Exchange Organization object. Without this permission, the management agent is unable to browse Administrative Groups.

  • The SE_SYNC_AGENT_NAME privilege. This privilege enables the caller to read all objects and attributes in Active Directory, regardless of the access protections on the objects and attributes. By default, this privilege is assigned to the Administrator and LocalSystem accounts on domain controllers. For more information about how to set this privilege, see the Microsoft Web site.

  • The DS-Replication-Get-Changes extended right. This right translates into full control rights in the synchronization organizational unit.

  • Write privileges on the proxyAddresses attribute on all authoritative mail recipient objects (users, contacts, groups, and any additional mail recipient objects you might have configured, such as dynamic distribution lists and mail-enabled Public Folders). This privilege is required only when data is being synchronized into the target forest for which you are supplying user credentials.

  • Full control of the organizational unit that was selected during the setup of the Active Directory GAL management agent. This right is required only when data is being synchronized into the target forest for which you are supplying user credentials.

  • The account specified for the management agent must have read permissions on the Configuration container. This is required in order to enumerate the Administrative groups.

  • Each forest participating in the GAL synchronization must be configured by using a separate management agent for Active Directory GAL.

  • If an Active Directory GAL management agent is deleted, it does not change the metaverse schema or the flow rules that apply to other GAL management agents.

  • When you delete a GAL management agent, the schema object types and attributes that were created by that management agent are not removed from the metaverse schema. For example, if a GAL management agent is used to create a custom contact object type (forest1_contact) in the metaverse schema and that GAL management agent is then deleted, the forest1_contact object type remains in the metaverse schema.

  • If you are connecting to a Microsoft Exchange Server 2007, the following requirements must be met:

    • In Synchronization Service Manager, in Properties, select Exchange 2007 in the Provision for dropdown on the Configure Extensions page.

    • In the Exchange 2007 RUS Server (optional) text-box you can enter a target server for the powershell cmdlets.

      Important

      Do not select Exchange 2007 if there are no Exchange 2007 servers in the target forest. An error will be returned for every object being exported.

    • To provision Active Directory accounts, the user account used by the management agent for Active Directory must be an Exchange Administrator.

    • Windows Powershell 1.0 and the Exchange 2007 SP1 Management Console must be installed.

    Note

    You will receive an extension-dll-exception error if you attempt to synchronize to Active Directory without Powershell 1.0 and the Exchange 2007 SP1 Management Console installed.

  • If you are connecting to a Microsoft Exchange Server 2010, the following must be met:

    • In Synchronization Services Manager, in Properties, select Exchange 2010 in Provision for on the Configure Extensions page.

    • In the Exchange 2010 RPS URI enter the remote Exchange server in the format http://CAS_SERVER_NAME/powershell.

    • The account used by the AD MA must have permission to call the Update-Recipient cmdlet.

    • Windows Powershell 2.0 must be installed.

    For both Microsoft Exchange 2007 and 2010 the following must also be met:

    • The FIM service account must be a domain account

    • The server running FIM must be joined to a domain.

  • This management agent does not support password management.

See Also


Объявления:

  1. Солевые лампы-отличный подарок!
    Солевые лампы-прикоснись к тайне.Принесут гармонию в Ваш дом.Дарим подарки!
    klubzdorovia.ru

     
  2. Ягуар
    Двери Ягуар. Полный каталог продукции, цены.
    www.2dveri.ru

     
  3. Banyan
    Забронируйте отель онлайн. Бесплатное бронирование.
    www.booking.com

     
  4. лизинг автомобилей москва
    лизинг автомобилей москва здесь. Профессионально. Бесплатно!
    eifp.ru

     
  5. Задумываешься о собственном деле?
    Быстрый старт проекта и его раскрутка через социальные сети. Узнай как!
    social.infolessons.ru

     
  6. Transcend 16 GB SDHC Class 10
    Карты памяти по низкой цене. Мы подскажем, где дешевле!
    toriava.ru

     
  7. Страйкбольные винтовки в продаже
    Страйкбольные винтовки - пневматическое оружие, снаряжение. Большой выбор!
    cybergun.su

     
  8. Квартира г электросталь
    Все о недвижимости Москвы и подмосковья! Вся информация в один клик.
    realty.smi2.ru

     
  9. Направления психолога
    Семинары, тренинги и события по психологии! On-line консультанты!
    razmir.ru

     
  10. Поиграть в браузерные игры
    Коллекция браузерных онлайн игр. Выбирай, что нравится!
    site-online-games.ru

     
  11. Радиатор Renault 1483 руб.
    Радиатор Renault 1483 руб. Кузовные детали. Оптика. Доставка
    77rus.com

     
  12. Аренда магазина запчастей
    Помещения под магазин в аренду? Реальные предложения. Выгодные цены
    апекс-недвижимость.рф

     
  13. Софт для Андроидов!
    Софт для Андроидов! Обзоры популярных программ, читайте тут.
    android-live.net

     
  14. Каталог домашних метеостанций!
    Продажа метеостанций! С радио, проекционные, цифровые и аналоговые!
    www.mircli.ru

     
  15. Мокасины D&G!
    Мужская обувь D&G - новые модели! Доставка по РФ!
    luxury-trend.ru

     
  16. Спутниковые телефоны
    Цифровая и медийная техника на выставке Связь-Экспокомм-2013 !
    www.sviaz-expocomm.ru

     
  17. Новости России на сегодня
    Актуальные новости. Статьи, репортажи, трансляции. Будьте в курсе!
    publicpost.ru

     
  18. Купить Мезолифт от Лиерак.
    Магазин косметики Лиерак. Купить Мезолифт от Лиерак. Скидки на Лиерак!
    www.krason.ru

     
  19. Atrium. Краков. Польша
    Гостиница Atrium. Краков. Польша.
    hotels.turizm.ru

     
  20. Рецепты салатов с рыбой
    Простые и вкусные рецепты салатов. Фото. Читайте на
    wictoria.ru

     
  21. Где проводить корпоратив?
    Где проводить корпоратив? Смотрите спец предложение! Гарантия 100% Жмите!
    emf-event.ru

     
  22. Квартиры. Конный 4
    Продажа квартир по адресу Конный 4
    www.realestate.ru

     
  23. Двигателя А-01 А-41 Д-442 АМЗ
    Двигатели А-01, А-41. Новые. Заводская гарантия. В наличии в Москве.
    www.tt4track.com

     
  24. Бухгалтерские и налоговые услуги
    Бухгалтерские и налоговые услуги для ООО, ИП, ЗАО. От 2500 р/мес. Звоните!
    whaudit.ru

     
  25. Отличные цены на путевки!
    Подбор лучших цен на туры и отдых. Все туроператоры. Онлайн бронирование.
    www.otdihayu.ru

     
  26. Гибкий вал к вибратору для бетона
    Продажа портативных вибраторов. Предложения Москвы! Лучшие цены!
    www.badi-beton.ru

     
  27. Женские сапоги - большой выбор!
    Стильная женская обувь на любой вкус. Предложения интернет-магазинов.
    any-brand.ru

     
  28. Автоматические ворота. Цены
    Продажа и установка ворот «под ключ». Адекватные цены. Доставка, гарантия!
    www.antaspb.ru

     
  29. Mazda 3 Хетчбек
    Mazda 3 от 569 000 руб. Кредит 2,7%. Взнос от 0%. Скидки.
    autovcredit.com

     
  30. Квартиры в Москве посуточно
    Апартаменты в Москве на сутки. От 4000 р./сутки. Большой выбор!
    www.sutkirent.ru