Verint | Telligent Community
Verint | Telligent Community
  • Site
  • User
  • Site
  • Search
  • User
Verint Community 11.x
  • Verint Community
Verint Community 11.x
User Documentation How can I synchronize Active Directory (AD) groups with Telligent Community roles?
  • User Documentation
  • Ask the Community
  • API Documentation
  • Manager Training
  • Developer Training
  • Tags
  • More
  • Cancel
  • New
  • Verint Community 11.x User Documentation
  • +How do I install Telligent Community?
  • Getting Started
  • +General Topics
  • +How do I get to the administration panel?
  • +How do I administer members?
  • +How do I change permissions?
  • +What is an application?
  • +What is a group?
  • How should I define groups and applications in my community?
  • +What is a forum?
  • +What is a blog?
  • +What is a gallery?
  • +What is a wiki?
  • +What is a calendar?
  • +What is ideation?
  • +What is a Knowledge Collection?
  • +How do I view reports?
  • +What is a theme?
  • +What is an Achievement and how do I change or manage Achievements?
  • -How can I enable single sign-on (SSO)?
    • How can I enable single sign-on (SSO) with another Microsoft .net-based website?
    • How can I enable visitors to authenticate through Facebook?
    • How can I enable visitors to authenticate through Google?
    • How can I enable visitors to authenticate through Twitter?
    • How can I enable visitors to authenticate through LinkedIn?
    • How can I enable visitors to authenticate through Live Connect?
    • How can I enable visitors to authenticate through Salesforce?
    • How can I enable authentication via Windows / Active Directory (AD)?
    • How can I synchronize Active Directory (AD) groups with Telligent Community roles?
    • How do I implement single sign-on (SSO) with an existing authentication system using cookies?
  • +How do I install chat support?
  • +How do I configure email integration?
  • +How do I translate my community?
  • How do I configure automations for my community?
  • +How can I identify abuse or SPAM within the community?
  • +Community Troubleshooting Guide
  • +How do I monitor the health of my community?
  • +Release Notes for Community 11
  • Accessibility
  • What are Points and how do I change or manage points?
  • Change system defaults for locking out users
  • How do I assign a site role to a user?
  • How do I change my password?
  • How do I change the options in my user profile?
  • How do I configure the available profile options?
  • How do I create an API key?
  • How do I customize my community in an upgrade-safe way?
  • How do I edit my profile?
  • How do I enable Google Analytics on Verint Community?
  • How do I show embedded tweets with videos (or pictures)?
  • IFRAME inclusion in the community
  • Shortened URLs
  • What are profile fields and how do I manage them?
  • What are Ratings?
  • What are the SEO features in Verint Community?
  • What is a leaderboard?
  • What is the difference between Related / Recommended content, and how do they work?

How can I synchronize Active Directory (AD) groups with Telligent Community roles?

This guide assumes that Active Directory / Windows Authentication and LDAP integration is already properly enabled and configured for your Telligent Community site.

Active Directory users can be synchronized with Telligent Community site-level roles. As members are added to Active Directory groups, they will be added to the corresponding role in Telligent Community. As members are removed from Active Directory groups, they will be removed from the corresponding role in Telligent Community.

[toc]

Add a synchronized Telligent Community role

An Active Directory group's membership can easily be synchronized with a Telligent Community role.

First, a few notes:

  • For Active Directory groups smaller than 500, the accounts will be created immediately. User will not receive an email after their account has been created. The creation of individual accounts for groups with 500 or more members will begin when the LDAP synchronization job runs next.
  • When adding an Active Directory group that contains other Active Directory groups, only the users of the parent group will be added to the community. The child group and its users will not be added. This is for security purposes. The only way to add the child group is to perform a separate import operation. 
  • AD groups of any combination of group scope and group type may be used.
  • Active Directory users must have valid email addresses in their Active Directory records for Telligent Community to create an account for the community.
  • The default configuration maps the Active Directory Administrators group to the Telligent Community Administrators role. To change this:
    1. Navigate to the web folder.
    2. Edit communityserver.config: 
      1. Find the line starting with 'adminWindowsGroup="Administrators"'.
      2. Change 'Administrators' to the name of whatever Active Directory group you would like to map as site administrators on your Telligent site.

To setup a synchronized role:

  1. As an Administrator, navigate to Management > Administration > Membership > Roles.
  2. Click Create an LDAP mapped role.
  3. Type your LDAP group name in the input panel.
  4. Click Create role. This will create a new site role for your community. Additional permissions can be granted to this site role if desired. Note: The name and description for the Active Directory roles may not be changed.

Remove a synchronized Telligent Community role

Active Directory group synchronization can be disabled by deleting the associated site role:

  1. As an Administrator, navigate to Administration > Membeship > Roles.
  2. Select the role in the drop-down list.
  3. Click Delete.

If you delete the site role to remove the Active Directory group, the individual Telligent Community accounts will continue to be active. The users will be able to access the community, but all of their memberships related to the Active Directory group synchronized role will be removed.  

Removing a member from a synchronized Telligent Community role

Because the role membership is synchronized with Active Directory and Active Directory is the source of the membership information, the user must be removed from the Active Directory group in Active Directory.

Synchronization frequency

The default configuration for the LDAP synchronization job is to run every morning at 4 a.m. The time can be changed in Administration:

  1. Navigate to Management > Administration > Jobs > Job Status.
  2. Click Jobs.
  3. Locate the LDAP Sync job.
  4. Change the run frequency or time.
  5. Click Save.

Active Directory groups with more than 500 users will be updated every 24 hours. Following our recommended configuration, you can add Active Directory groups with up to 10,000 members. For Active Directory groups with more than 10,000 users, please contact Customer Support.

  • Share
  • History
  • More
  • Cancel
Related
Recommended
  • Telligent
  • Professional Services
  • Submit a Support Ticket
  • Become a Partner
  • Request a Demo
  • Contact Us

About
Privacy Policy
Terms of use
Copyright 2024 Verint, Inc.
Powered by Verint Community