30.01.2015 Views

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User Accounts and Groups<br />

Use buttons Add or Edit to open a dialog for a new domain definition and enter parameters of<br />

the mapped domain. For details, see above (Primary domain mapping and Advanced options).<br />

Collision of Active Directory with the local database and conversion of accounts<br />

During Active Directory domain mapping, collision with the local user database may occur if<br />

a user account with an identical name exists both in the domain and in the local database. If<br />

multiple domains are mapped, a collision may occur only between the local database and the<br />

primary domain (accounts from other domains must include domain names which make the<br />

name unique).<br />

If a collision occurs, a warning is displayed at the bottom of the User Accounts tab. Click<br />

on the link in the warning to convert selected user accounts (to replace local accounts by<br />

corresponding Active Directory accounts).<br />

Figure 16.15<br />

Conversion of user accounts<br />

The following operations will be performed automatically within each conversion:<br />

• substitution of any appearance of the local account in the <strong>Kerio</strong> Control configuration<br />

(in traffic rules, URL rules, FTP rules, etc.) by a corresponding account from the Active<br />

Directory domain,<br />

• removal of the account from the local user database.<br />

Accounts not selected for the conversion are kept in the local database (the collision is still<br />

reported). Colliding accounts can be used — the accounts are considered as two independent<br />

accounts. However, under these circumstances, Active Directory accounts must be always<br />

specified including the domain (even though it belongs to the primary domain); username<br />

without the domain specified represents an account belonging to the local database. However,<br />

as long as possible, it is recommended to remove all collisions by the conversion.<br />

234

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!