<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>How can I synchronize Active Directory (AD) groups with Telligent Community roles?</title><link>https://community.telligent.com/community/11/w/user-documentation/62946/how-can-i-synchronize-active-directory-ad-groups-with-telligent-community-roles</link><description /><dc:language>en-US</dc:language><generator>14.0.0.586 14</generator><item><title>How can I synchronize Active Directory (AD) groups with Telligent Community roles?</title><link>https://community.telligent.com/community/11/w/user-documentation/62946/how-can-i-synchronize-active-directory-ad-groups-with-telligent-community-roles</link><pubDate>Thu, 18 Jul 2019 17:27:47 GMT</pubDate><guid isPermaLink="false">dacb0190-1351-4140-8d60-8d3a5fbb3f43</guid><dc:creator>Grant Pankonien</dc:creator><comments>https://community.telligent.com/community/11/w/user-documentation/62946/how-can-i-synchronize-active-directory-ad-groups-with-telligent-community-roles#comments</comments><description>Current Revision posted to User Documentation by Grant Pankonien on 07/18/2019 17:27:47&lt;br /&gt;
&lt;div class="message warning"&gt;This guide assumes that [[How can I enable authentication via Windows / Active Directory (AD)?|Active Directory / Windows Authentication and LDAP integration]] is already properly enabled and configured for your Telligent Community site.&lt;/div&gt;
&lt;p&gt;Active Directory users can be synchronized with Telligent Community site-level roles. As members are added to Active Directory groups, they will be added to the corresponding role in Telligent Community. As members are removed from Active Directory groups, they will be removed from the corresponding role in Telligent Community.&lt;/p&gt;
&lt;p&gt;[toc]&lt;/p&gt;
&lt;h2&gt;&lt;a id="Add_Active_Directory_group_users_to_a_Telligent_Community_role" name="Add_Active_Directory_group_users_to_a_Telligent_Community_role"&gt;&lt;/a&gt;Add a synchronized Telligent Community role&lt;/h2&gt;
&lt;p&gt;An Active Directory group&amp;#39;s membership can easily be synchronized with a Telligent Community role.&lt;/p&gt;
&lt;p&gt;First, a few notes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For Active Directory groups smaller than 500, the accounts will be created immediately. User will&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;em&gt;not&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;receive an email after their account has been created. The creation of individual accounts for groups with 500 or more members will begin when the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;LDAP synchronization&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;job runs next.&lt;/li&gt;
&lt;li&gt;When adding an Active Directory group that contains other Active Directory groups, only the users of the parent group will be added to the community. The child group and its users will not be added. This is for security purposes. The only way to add the child group is to perform a separate import operation.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;AD groups of any combination of&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;a href="http://support.microsoft.com/kb/231273"&gt;group scope and group type&lt;/a&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;may be used.&lt;/li&gt;
&lt;li&gt;Active Directory users must have valid email addresses in their Active Directory records for Telligent Community to create an account for the community.&lt;/li&gt;
&lt;li&gt;The default configuration maps the Active Directory Administrators group to the Telligent Community Administrators role. To change this:
&lt;ol&gt;
&lt;li&gt;Navigate to the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;web&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;folder.&lt;/li&gt;
&lt;li&gt;Edit&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;communityserver.config&lt;/span&gt;:&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Find the line starting with&lt;span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&amp;#39;adminWindowsGroup=&amp;quot;Administrators&amp;quot;&amp;#39;&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;Change&lt;span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&amp;#39;Administrators&amp;#39;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to the name of whatever Active Directory group you would like to map as site administrators on your Telligent site.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To setup a synchronized role:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;As an Administrator, navigate to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Management &amp;gt; Administration &amp;gt; Membership &amp;gt; Roles&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Create an LDAP mapped role&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Type your LDAP group name in the input panel.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Create role&lt;/strong&gt;. This will create a new site role for your community. Additional permissions can be granted to this site role if desired. Note: The name and description for the Active Directory roles may not be changed.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;a id="Remove_Active_Directory_group_users_from_Telligent_Community" name="Remove_Active_Directory_group_users_from_Telligent_Community"&gt;&lt;/a&gt;Remove a synchronized Telligent Community role&lt;/h2&gt;
&lt;p&gt;Active Directory group synchronization can be disabled by deleting the associated site role:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;As an Administrator, navigate to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Administration &amp;gt; Membeship &amp;gt; Roles&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select the role in the drop-down list.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Delete&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you delete the site role to remove the Active Directory group, the individual Telligent Community accounts will continue to be active. The users will be able to access the community, but all of their memberships related to the Active Directory group synchronized role will be removed. &amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;a id="Removing_Active_Directory_synced_roles_from_individual_users" name="Removing_Active_Directory_synced_roles_from_individual_users"&gt;&lt;/a&gt;Removing a member from a synchronized Telligent Community role&lt;/h2&gt;
&lt;p&gt;Because the role membership is synchronized with Active Directory and Active Directory is the source of the membership information, the user must be removed from the Active Directory group in Active Directory.&lt;/p&gt;
&lt;h2&gt;&lt;a id="Synchronization_Frequency" name="Synchronization_Frequency"&gt;&lt;/a&gt;Synchronization frequency&lt;/h2&gt;
&lt;p&gt;The default configuration for the LDAP synchronization job is to run every morning at 4 a.m. The time can be changed in Administration:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Navigate to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Management &amp;gt; Administration &amp;gt; Jobs &amp;gt; Job Status&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Jobs&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Locate the LDAP Sync job.&lt;/li&gt;
&lt;li&gt;Change the run frequency or time.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Save&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Active Directory groups with more than 500 users will be updated every 24 hours. Following our recommended configuration, you can add Active Directory groups with up to 10,000 members. For Active Directory groups with more than 10,000 users, please contact&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;a href="/support/open_ticket.aspx"&gt;Customer Support&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>How can I synchronize Active Directory (AD) groups with Telligent Community roles?</title><link>https://community.telligent.com/community/11/w/user-documentation/62946/how-can-i-synchronize-active-directory-ad-groups-with-telligent-community-roles/revision/1</link><pubDate>Tue, 04 Jun 2019 20:14:26 GMT</pubDate><guid isPermaLink="false">dacb0190-1351-4140-8d60-8d3a5fbb3f43</guid><dc:creator>Ben Tiedt</dc:creator><comments>https://community.telligent.com/community/11/w/user-documentation/62946/how-can-i-synchronize-active-directory-ad-groups-with-telligent-community-roles#comments</comments><description>Revision 1 posted to User Documentation by Ben Tiedt on 06/04/2019 20:14:26&lt;br /&gt;
&lt;div class="message warning"&gt;This guide assumes that [[How can I enable authentication via Windows / Active Directory (AD)?|Active Directory / Windows Authentication and LDAP integration]] is already properly enabled and configured for your Telligent Community site.&lt;/div&gt;
&lt;p&gt;Active Directory users can be synchronized with Telligent Community site-level roles. As members are added to Active Directory groups, they will be added to the corresponding role in Telligent Community. As members are removed from Active Directory groups, they will be removed from the corresponding role in Telligent Community.&lt;/p&gt;
&lt;p&gt;[toc]&lt;/p&gt;
&lt;h2&gt;&lt;a id="Add_Active_Directory_group_users_to_a_Telligent_Community_role" name="Add_Active_Directory_group_users_to_a_Telligent_Community_role"&gt;&lt;/a&gt;Add a synchronized Telligent Community role&lt;/h2&gt;
&lt;p&gt;An Active Directory group&amp;#39;s membership can easily be synchronized with a Telligent Community role.&lt;/p&gt;
&lt;p&gt;First, a few notes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For Active Directory groups smaller than 500, the accounts will be created immediately. User will&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;em&gt;not&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/em&gt;receive an email after their account has been created. The creation of individual accounts for groups with 500 or more members will begin when the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;LDAP synchronization&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;job runs next.&lt;/li&gt;
&lt;li&gt;When adding an Active Directory group that contains other Active Directory groups, only the users of the parent group will be added to the community. The child group and its users will not be added. This is for security purposes. The only way to add the child group is to perform a separate import operation.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;AD groups of any combination of&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;a href="http://support.microsoft.com/kb/231273"&gt;group scope and group type&lt;/a&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;may be used.&lt;/li&gt;
&lt;li&gt;Active Directory users must have valid email addresses in their Active Directory records for Telligent Community to create an account for the community.&lt;/li&gt;
&lt;li&gt;The default configuration maps the Active Directory Administrators group to the Telligent Community Administrators role. To change this:
&lt;ol&gt;
&lt;li&gt;Navigate to the&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;web&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;folder.&lt;/li&gt;
&lt;li&gt;Edit&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span&gt;communityserver.config&lt;/span&gt;:&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Find the line starting with&lt;span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&amp;#39;adminWindowsGroup=&amp;quot;Administrators&amp;quot;&amp;#39;&lt;/span&gt;.&lt;/li&gt;
&lt;li&gt;Change&lt;span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&amp;#39;Administrators&amp;#39;&lt;/span&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;to the name of whatever Active Directory group you would like to map as site administrators on your Telligent site.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To setup a synchronized role:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;As an Administrator, navigate to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Management &amp;gt; Administration &amp;gt; Membership &amp;gt; Roles&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Create an LDAP mapped role&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Type your LDAP group name in the input panel.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Create role&lt;/strong&gt;. This will create a new site role for your community. Additional permissions can be granted to this site role if desired. Note: The name and description for the Active Directory roles may not be changed.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2&gt;&lt;a id="Remove_Active_Directory_group_users_from_Telligent_Community" name="Remove_Active_Directory_group_users_from_Telligent_Community"&gt;&lt;/a&gt;Remove a synchronized Telligent Community role&lt;/h2&gt;
&lt;p&gt;Active Directory group synchronization can be disabled by deleting the associated site role:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;As an Administrator, navigate to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Administration &amp;gt; Membeship &amp;gt; Roles&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Select the role in the drop-down list.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Delete&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you delete the site role to remove the Active Directory group, the individual Telligent Community accounts will continue to be active. The users will be able to access the community, but all of their memberships related to the Active Directory group synchronized role will be removed. &amp;nbsp;&lt;/p&gt;
&lt;h2&gt;&lt;a id="Removing_Active_Directory_synced_roles_from_individual_users" name="Removing_Active_Directory_synced_roles_from_individual_users"&gt;&lt;/a&gt;Removing a member from a synchronized Telligent Community role&lt;/h2&gt;
&lt;p&gt;Because the role membership is synchronized with Active Directory and Active Directory is the source of the membership information, the user must be removed from the Active Directory group in Active Directory.&lt;/p&gt;
&lt;h2&gt;&lt;a id="Synchronization_Frequency" name="Synchronization_Frequency"&gt;&lt;/a&gt;Synchronization frequency&lt;/h2&gt;
&lt;p&gt;The default configuration for the LDAP synchronization job is to run every morning at 4 a.m. The time can be changed in Administration:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Navigate to&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Management &amp;gt; Administration &amp;gt; Jobs &amp;gt; Job Status&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Jobs&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Locate the LDAP Sync job.&lt;/li&gt;
&lt;li&gt;Change the run frequency or time.&lt;/li&gt;
&lt;li&gt;Click&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;strong&gt;Save&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Active Directory groups with more than 500 users will be updated every 24 hours. Following our recommended configuration, you can add Active Directory groups with up to 10,000 members. For Active Directory groups with more than 10,000 users, please contact&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;a href="/support/open_ticket.aspx"&gt;Customer Support&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>