On the Board - Efficiently Manage Hybrid AD/AAD Environments
Administrators struggle to keep up with requests to create, change or remove access with today’s hybrid AD environments and the limited capabilities of native tools of Microsoft Active Directory (AD) and Azure Active Directory (AAD). Thankfully, help has arrived. With One Identity Active Roles, you can solve your security issues and meet those never-ending compliance requirements by securing and protecting on-prem and cloud AD resources simply and efficiently.
Active Roles is optimized to serve the needs of both on-prem AD and Azure AD in a hybrid deployment. It offers a single console, unified workflows, and a consistent administrative experience across the entire hybrid environment. It eliminates the cumbersome, error-prone, and limited nature of using separate tools and manual processes.
Active Roles provides comprehensive privileged account management for Active Directory and Azure Active Directory, enabling you to control access through delegation using a least-privilege model. Based on defined administrative policies and associated permissions, it generates and strictly enforces access rules, eliminating the errors and inconsistencies common with native approaches to hybrid AD management. Plus, robust and personalized approval procedures establish an IT process and oversight consistent with business requirements, with responsibility chains that complement the automated management of directory data.
Active Roles automates a wide variety of tasks, including:
It also automates the process of reassigning and removing user access rights in AD, AAD and AD-joined systems (including user and group de-provisioning) to ensure an efficient and secure administrative process over the user and group lifecycles. When a user’s access needs to be changed or removed, updates are made automatically across all relevant systems and applications in the hybrid AD/AAD environment, as well as any AD-joined systems such as Unix, Linux and Mac OS X.
With Active Roles, you can easily manage all of the following for both the on-prem and Azure AD environments:
Active Roles also includes intuitive interfaces for improving day-to- day administration and help-desk operations of the hybrid AD/AAD environment via both an MMC snap-in and a web interface.
Mitigate risks before an issue occurs through comprehensive insight into user entitlements in a hybrid AD environment. Starling Identity Analytics & Risk Intelligence (an add-on to Active Roles) provides an analysis of users’ rights in Active Directory, Azure Active Directory, and Active Roles itself to highlight areas of unacceptable-risk where those rights may be out of line with peers, organizational policy, or role definitions.
Synchronize AD domain clients with a host AD domain in hosted environments. Active Roles enables user and group account management from the client domain to the hosted domain, while also synchronizing attributes and passwords. Utilize out-of-the-box connectors to synchronize your on-premises AD accounts to Microsoft Office 365, Lync Online and SharePoint Online.
Active Roles complements your existing technology and identity and access management strategy. It simplifies and consolidates management points by ensuring easy integration with many One Identity products, including Identity Manager, Privileged Password Manager, Authentication Services, Defender, Password Manager, Cloud Access Manager and Quest ChangeAuditor. Active Roles also automates and extends the capabilities of PowerShell, ADSI, SPML and customizable web interfaces.
Active Roles comes with all the synchronization technology necessary to manage and secure:
Before installing Active Roles 7.1, ensure that your system meets the following minimum hardware and software requirements.
Active Roles includes the following components:
This section lists the hardware and software requirements for installing and running each of these components.
Any of the following:
Processor speed: 2.0 GHz or faster
For best results, a multi-core processor recommended.
At least 2 GB of RAM. The amount required depends on the total number of managed objects.
100 MB or more of free disk space. If SQL Server and Administration Service are installed on the same computer, the amount required depends on the size of the Active Roles database.
You can install Administration Service on a computer running:
Administration Service requires Microsoft .NET Framework 4.5 (see “Installing the .NET Framework” at http://go.microsoft.com/fwlink/?LinkId=257868).
You can host the Active Roles database on:
On Windows Server 2008 R2, the Administration Service requires Windows Management Framework 3.0 (see “Windows Management Framework 3.0” at http://go.microsoft.com/fwlink/?LinkId=272757).
To manage Exchange 2007 recipients, Active Roles requires the Exchange 2007 SP3 management tools installed on the computer running the Administration Service. For installation instructions, see “How to Install the Exchange 2007 Management Tools” at http://go.microsoft.com/fwlink/?linkid=88090.
Active Roles retains all features and functions when managing Active Directory on domain controllers running any of these operating systems, any edition, with or without any Service Pack:
NOTE:
Active Roles is capable of managing Exchange recipients on:
NOTE: Microsoft Exchange Server 2003 is not supported.
Any of the following:
Processor speed: 2.0 GHz or faster
At least 2 GB of RAM. The amount required depends on the total number of managed objects.
About 100 MB of free disk space.
You can install Web Interface on a computer running:
Web Interface requires Microsoft .NET Framework 4.5 (see “Installing the .NET Framework” at http://go.microsoft.com/fwlink/?LinkId=257868).
On Windows Server 2008 R2, Web Interface requires the Web Server (IIS) server role with the following role services:
On Windows Server 2012 or Windows Server 2012 R2, Web Interface requires the Web Server (IIS) server role with the following role services:
Internet Information Services (IIS) must be configured to provide Read/Write delegation for the fo;llowing features:
Use Feature Delegation in Internet Information Services (IIS) Manager to confirm that these features have delegation set to Read/Write.
You can access Web Interface using:
You can use a later version of Firefox, Google Chrome or Internet Explorer to access Web Interface; however, Web Interface 7.1 has been tested only against the browser versions listed above.
Web Interface is optimized for screen resolutions of 1280 x 800 or higher. The minimum supported screen resolution is 1024 x 768.
Any of the following:
Processor speed: 1.0 GHz or faster
At least 1 GB of RAM. The amount required depends on the total number of managed objects.
About 100 MB of free disk space.
You can install Active Roles console on a computer running:
Active Roles console requires Microsoft .NET Framework 4.5 (see “Installing the .NET Framework” at http://go.microsoft.com/fwlink/?LinkId=257868).
Active Roles console requires Internet Explorer 11.
Management Tools is a composite component that includes the Active Roles Management Shell, ADSI Provider, and SDK. On a 64-bit (x64) system, Management Tools also include the Active Roles Configuration Center.
Any of the following:
Processor speed: 1.0 GHz or faster
At least 1 GB of RAM.
About 100 MB of free disk space.
You can install Management Tools on a computer running:
Management Tools require Microsoft .NET Framework 4.5 (see “Installing the .NET Framework” at http://go.microsoft.com/fwlink/?LinkId=257868).
On Windows Server 2008 R2 or Windows 7, Management Tools require Windows Management Framework 3.0 (see “Windows Management Framework 3.0” at http://go.microsoft.com/fwlink/?LinkId=272757).
To manage Terminal Services user properties by using Active Roles Management Shell, Management Tools require Remote Server Administration Tools (RSAT) for Active Directory. See Microsoft’s documentation for instructions on how to install Remote Server Administration Tools appropriate to your operating system.
Any of the following:
Processor speed: 2.0 GHz or faster
For best results, a multi-core processor recommended.
At least 2 GB of RAM. The amount required depends on the number of objects being synchronized.
250 MB or more of free disk space. If SQL Server and Synchronization Service are installed on the same computer, the amount required depends on the size of the Synchronization Service database.
You can install the Synchronization Service on a computer running:
Synchronization Service requires Microsoft .NET Framework 4.5 (see “Installing the .NET Framework” at http://go.microsoft.com/fwlink/?LinkId=257868).
You can host the Synchronization Service database on:
On Windows Server 2008 R2, the Synchronization Service requires Windows Management Framework 3.0 (see “Windows Management Framework 3.0” at http://go.microsoft.com/fwlink/?LinkId=272757).
The Synchronization Service can connect to:
To connect to Active Roles version 6.9, 6.8 or 6.7, the Active Roles ADSI Provider of the respective version must be installed on the computer running the Synchronization Service. For installation instructions, see the Quick Start Guide for the appropriate Active Roles version.
To connect to Exchange Server 2007, the Exchange 2007 SP3 management tools must be installed on the computer running the Synchronization Service. For installation instructions, see “How to Install the Exchange 2007 Management Tools” at http://go.microsoft.com/fwlink/?linkid=88090.
To connect to the Office 365 directory, the following software must be installed on the computer running the Synchronization Service:
For installation instructions, see “Install the Azure AD Module” at http://go.microsoft.com/fwlink/?linkid=320628.
To connect to the Lync Online service, Windows PowerShell Module for Lync Online must be installed on the computer running the Synchronization Service. For installation instructions, see “Windows PowerShell Module for Lync Online” at http://go.microsoft.com/fwlink/?LinkId=294688.
To connect to the SharePoint Online service, SharePoint Online Management Shell must be installed on the computer running the Synchronization Service. For installation instructions, see “SharePoint Online Management Shell” at http://go.microsoft.com/fwlink/?LinkId=255251.
To connect to One Identity Manager 7.0, One Identity Manger Connector must be installed on the computer running the Synchronization Service. This connector works with RESTful web service and SDK installation is not required.
To connect to One Identity Manager 6.0, the Quest One Identity Manager Connector must be installed on the computer running the Synchronization Service. This connector works only when the Q1IM API SDK is installed on the system. For installation instructions, see Knowledge Article 100525 at https://support.oneidentity.com/kb/SOL100525.
To connect to cloud directories or online services, the computer running the Synchronization Service must have a reliable connection to the Internet.
Microsoft .NET Framework 4.5
To synchronize passwords from an Active Directory domain to some other connected data system, you must install the Sync Service Capture Agent on all domain controllers in the source Active Directory domain.
The domain controllers on which you install Sync Service Capture Agent must run one of the following operating systems with or without any Service Pack (both x86 and x64 platforms are supported):
For more information, see the Active Roles Synchronization Service Administrator Guide.
For instructions on how to upgrade Active Roles, refer to the Active Roles Quick Start Guide.
When performing the upgrade, keep in mind that the components of the earlier version may not work in conjunction with the components you have upgraded. To ensure smooth upgrade to the new version, you should first upgrade the Administration Service and then upgrade the client components (Console and Web Interface).
Custom solutions (scripts or other modifications) that rely on the functions of Active Roles may fail to work after an upgrade due to compatibility issues. Prior to attempting an upgrade, you should test your existing solutions with the new version of the product in a lab environment to verify that the solutions continue to work.
Impact on add-ons
After an upgrade of Active Roles components to the Active Roles 7.1, the add-ons which were supported in the earlier versions of Active Roles, cease to work. Hence, it is recommended to uninstall the add-ons prior to the upgrade of Active Roles.
Note: Office 365 add-ons are not supported on the Active Roles 7.1.
The following table shows the version upgrade path that you can take from one version of the product to another. Source version refers to the current product version that you have installed. Destination version refers to the highest version of the product to which you can upgrade.
6.9.0
7.1
7.0
7.1
Managing on-prem AD is hard enough, but when you throw Azure AD into the mix things can get out of control quickly. This eBook discusses the top five challenges facing those with a hybrid AD environment and offers actionable solutions to ease the pain.
It’s often thought that identity and access management (IAM) is a term that is reserved for large-scale, strategic projects that focus on governance, enterprise provisioning and privileged account management (PAM). Without question, these things are very
The 12 essential tasks for managing Active Directory Domain Services
Use Active Directory groups to manage access control
The university needed to streamline IT management by migrating 22,000 users from legacy environments to Active Directory® and Microsoft® Exchange Server. Active Roles provided flexible delegation of AD permissions and role-based security features
Keep Active Directory secure by separating administration roles
GDPR is fast-approaching. Are you ready? use this checklist to find out.
Streamline user identity management, privilege access and security
Extend the compliance and security of Active Directory to your enterprise
Enhance security with two-factor authentication.
Give users the power to reset forgotten passwords securely
Get unified and secure access to overcome your most-pressing challenges
Self-service tools will help you to install, configure and troubleshoot your product.
Find the right level of support to accommodate the unique needs of your organization.
Training courses delivered through online web-based, on-site or virtual instructor-led.