Set up Active Directory sync

Synchronize your Active Directory Users and Groups to enable content filter policy assignment to AD-managed people groups (rather than network devices via IP address).

1. Configure your AD server for synchronization

Your AD server must have Security Certificates configured for LDAPS to work. See Preparing your Windows Server for LDAPS access for more information and instructions.

2. Configure the DrawBridge for AD Sync

4. Next Steps

This how-to guide is the prerequisite procedure to setting up filter policies for Directory Groups. For further instructions, see the articles:

Troubleshooting Resources

  • On all of your DC's, look at the Directory Service event log.
  • Search for event 2887.
  • If exists that means you still have clients using non-secure LDAP requests and how many.
  • If you change the diagnosting logging level for LDAP, you can find the IP address of these clients: HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics
  • Change the value of 16 LDAP Interface Events from 0 to 2.
  • After the change you should see event 2889 logged whenever one of these requests come in.

Revision #23
Created 27 September 2022 12:58:31 by Marvin M.
Updated 27 March 2024 16:15:17 by Marvin M.