Hello there!

Need Help? We are right here!

Support Icon
miniOrange Email Support
success

Thanks for your Enquiry. Our team will soon reach out to you.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to [email protected]

Search Results:

×

Active Directory Provisioning


Active Directory Provisioning automates the process of creating, updating, and removing user accounts in third-party applications using API endpoints. miniOrange's automated User Provisioning feature seamlessly integrates with Active Directory to provision all user identities automatically, saving time and managing access privileges throughout the user lifecycle.

Bi-directional and automatic user provisioning and de-provisioning actions enhance security by removing access to sensitive applications and content when an employee leaves or changes roles. This improves your organization's security profile.

Automatic Provisioning saves time when setting up new users and teams, and also manages access privileges through the user lifecycle. It is considered as a part of user lifecycle management . miniOrange can create, read, and update user accounts for new or existing users, remove accounts for deactivated users, and synchronize attributes across multiple directories and the applications that the user needs access to.

Active Directory Deprovisioning means deleting a user and removing their access from multiple applications and network systems at once. Automatic Deprovisioning action is triggered when an employee leaves a company or changes roles within the organization. The deprovisioning features increase your organization's security profile by removing access to sensitive applications and content from people who leave your organization.



Automate Provisioning & Automatic Deprovisioning Scenarios


miniOrange provides solutions for all scenarios of provisioning, which includes AD Integration, LDAP Integration and automated provisioning for all External Applications such as Office 365, Google Workspace, Workday, etc



Following is the Step-by-Step Guide given below to setup Provisioning in Microsoft Active Directory (Active Directory)

1. Setup Automatic Provisioning in Microsoft Active Directory (Active Directory)

  • Login into miniOrange Admin Console.
  • Go to the External directories, Click on Add Directory.
  • click Add Directory for Active Directory automatic provisioning

  • Select Directory type as AD/LDAP.
  • click Add Directory for Active Directory automatic provisioning

  • STORE LDAP CONFIGURATION IN MINIORANGE: Choose this option if you want to keep your configuration in miniOrange. If the active directory is behind a firewall, you will need to open the firewall to allow incoming requests to your AD.
  • STORE LDAP CONFIGURATION ON PREMISE: Choose this option if you want to keep your configuration in your premise and only allow access to AD inside premises. You will have to download and install miniOrange gateway on your premise.
  • Configure LDAP for Active Directory automatic provisioning

  • Enter LDAP Display Name and LDAP Identifier name.
  • Select Directory Type as Active Directory .
  • Enter the LDAP Server URL or IP Address against the LDAP Server URL field.
  • Click on the Test Connection button to verify if you have made a successful connection with your LDAP server.
  • Active Directory user Provisioning Setup

  • In Active Directory, go to the properties of user containers/OU's and search for the Distinguished Name attribute.
  • Active Directory user Provisioning: Google Workspace Provisioning Configure

  • Enter the valid Bind account Password.
  • Click on the Test Bind Account Credentials button to verify your LDAP Bind credentials for LDAP connection.
  • Check bind account credentials

  • Search Base is the location in the directory where the search for a user begins. You will get this from the same place you got your Distinguished name.
  • Configure user bind account domain name

  • Select a suitable Search filter from the drop-down menu. Use Users and Group Authentication and Provisioning Filter if you are not sure. If you use User in Single Group Filter or User in Multiple Group Filter, replace the group-dn in the search filter with the distinguished name of the group in which your users are present. To use custom Search Filter select Write your Custom Filter option and customize it accordingly. Please note that, include (objectGUID=?) while writing custom filter, otherwise provisioning will not work.
  • Select user search filter

  • Click on the Next button, or go to the Authentication tab.
  • If you want to set up (AD as External Directory), click here for detailed information. For now, we are skipping this step by clicking Skip on Authentication.
  • In the Provisioning tab, there are two sections: Users and Groups. Each section contains a list of attributes and their functions when enabled. You can enable or disable them as needed.
  • Attribute Description
    Users Create Users Enabling this option will create the user in the selected application upon user creation in miniOrange.
    Edit Users Enabling this option will update the user profile in the selected application if updated in miniOrange.
    Delete Users Enabling this option will delete the user from the selected application if the user is deleted from the miniOrange.
    Password Sync Enabling this option will sync the user password from the miniOrange database to the application selected.
    Account Enable/Disable Sync Enabling this option will sync the user account enable/disable from the miniOrange database to the application selected.

    Attribute Description
    Groups Create Group Enabling this option will create the Group in the selected application upon Group creation in miniOrange.
    Delete Group Enabling this option will delete the Group from the selected application if the Group is deleted from the miniOrange.
    Add/Remove Group membership of User Enabling this option will add/remove the Group membership of a user from the selected application if the respective user group membership is updated from the miniOrange.

    Click here link for AD authentication

  • Click on the Next button, or go to the Attributes tab.
  • Attributes Mapping from AD

  • By default userName, firstName, lastName, email are configured. Scroll down and click on Save Configurations.
  • Active Directory Attribute Mapping Configuration

    Attributes Mapping from Active Directory to Application

2. Create Group

  • To create a group, follow these steps:
  • Go to the Manage Groups section in the Groups tab, located on the left side and click on Create Group Button
  • Create Group from Manage Groups section in Active Directory Provisioning

  • Enter the group name and click the Create Group button.
  • You will receive a success notification upon group creation, and the group will be displayed in the Manage Groups section of the Groups tab.
  • Group created successfully in Active Directory and listed under Manage Groups section

3. App Policy (Connects Group to Active Directory App)

  • Go to the App Login Policy section under Policies, and click Add Policy.
  • Add App Login Policy to connect group with Active Directory Application

  • Select the application you have configured in the External Directories tab.
  • Enter the group name you created.
  • Enter a policy name of your choice.
  • In First Factor there are two options:
    • Password
    • OTP/PUSH/Mobile Token (Password-Less Login)
  • Click on Submit button to create a policy.
  • Active Directory App Policy creation

  • You will receive a success notification upon policy creation, and the policy will be displayed in the App Login Policy section of the Policies tab.
  • Policy creation success notification and policy listed under App Login Policy section

  • Provisioning configuration is complete now.
  • Now, we can verify whether provisioning is working as expected.
  • Go to the Manage Groups section in the Groups tab, click Select, and then choose Assign Users.
  • Assign users to the group from the Manage Groups section to verify provisioning

  • Ensure that users are already present in miniOrange or import them into the user list. This allows you to assign the user you want to provision in Active Directory.
  • From the list below, select the user you want to provision, choose the Assign to Group option, and click Apply. This will automatically create the user in Active Directory.
  • Assign user to group for provisioning in Active Directory

  • To update a user, go to the User List, select the user you want to update, click Select, and then choose Edit.
  • Edit user details by selecting the user from the User List

  • After updating the user, click the Save button. This will automatically update the user in Active Directory.
  • Click Save after editing user to update in Active Directory

  • To delete a user, go to the Manage Groups section of the Groups tab. Then, navigate to the group from which the user needs to be deleted. In the Users column, click on the displayed number of users.
  • View list of users in a group from Manage Groups section

  • Select the user you want to delete, choose Remove from Group as the action, and click the Apply button. This will automatically remove the user from Active Directory as well.
  • Remove user from group to automatically delete user from Active Directory



View Provisioning Reports

How to access Provisioning Reports?

  • Navigate to the Reports in the left-hand navigation pane and select Provisioning Report.
  • Provisioning Report

  • Filter the reports by specifying Enduser Identifier and Application Name criteria. Additionally, choose the desired timespan for the reports. Once done, click on the Search.
  • Search Provisioning Report

  • Alternatively, you can directly click on Search to retrieve all provisioning reports based on time without applying any specific filters.


External References

Want To Schedule A Demo?

Request a Demo
  



Our Other Identity & Access Management Products

OSZAR »