Active Directory for Data Domain questions[1]

           

   Article Number:     529671                                   Article Version: 3     Article Type:    How To 
   

 


Product:

 

Data Domain Boost,Data Domain

 

Instructions:

 

 

Configuring Windows Active Directory authentication for user access to Data Domain.   
    This topic is covered in the DDOS  6.x admin guides under System access management > Directory user and group management.   
    Before you start it’s recommended to have your active directory group and users configured.   
    Below is a quick example “how to” if you have not done it before.   
    To set this up from within Active Directory:   

         
  •         Launch “Active Directory Users and Computers” on the Domain Controller     
  •      
  •         Use an existing or create a new active group and user in the Domain your Data Domain belongs.                
               
    •             In our example we create a new group and user:         
    •        
                  
  •    
User-added image   
   
    User-added image   
        
         
  •         Then create a new user and log in name:     
  •    
User-added image   
    User-added image   
        
         
  •         Enter a suitable password and password options that comply with your organisations security policies.     
  •    
   
    User-added image   
   
        
         
  •         Select your new user and add it to your new group:     
  •    
User-added image   
   
   
    User-added image   
        
         
  •         From your Data Domain console log in with a local admin user (i.e. sysadmin) and navigate to Administration>Access>Authentication> and expand Active Directory / Kerberos Authentication     
  •      
  •         Click on “Configure” and select “Windows / Active directory”     
  •    
User-added image   
        
         
  •         Enter the Realm Name and user credentials that have admin rights to the Realm (Domain):     
  •    
User-added image   
   
        
         
  •         Enter details as required or accept defaults:     
  •    
User-added image   
        
         
  •         Click finish:     
  •    
User-added image   
        
         
  •         Click ok to the message for synchronisation:     
  •    
User-added image   
        
         
  •         Back in Administration > Access > Authentication >                 
               
    •             NOTE: Active Directory Administrative Access is disabled:         
    •        
                  
  •    
User-added image   
   
        
         
  •         Clicked enable and click ok to the message:     
  •    
   
    User-added image   
   
        
         
  •         NOTE: Active Directory Administrative Access is now enabled:     
  •    
   
    User-added image   
        
         
  •         Create a new Windows work Group by clicking on the plus symbol:     
  •    
User-added image   
        
         
  •         Click OK to Create Windows Group, include the domain in the group name:     
  •    
   
    User-added image   
        
         
  •         Click OK to the group access message:     
  •    
User-added image   
   
        
         
  •         Note your new work group has now been created:     
  •    
   
    User-added image   
        
         
  •         Now test log in to the gui with the Active directory user you created at the beginning:     
  •    
User-added image   
   
    User-added image   
   
    User-added image   
        
         
  •         Note: DDBOOST users must be local users and cannot be Active Directory users.                
               
    •             Local users and Active Directory users can co-exist.         
    •        
                  
  •