Documentation for Intellect 4.11.0-4.11.3. Documentation for other versions of Intellect is available too.

Previous page Active Directory configuration  Connecting the Intellect and Active Directory users Next page


The joint operation of Intellect and Active Directory means that the Intellect users and user permissions are connected with the Active Directory users and security groups. User accounts are pre-imported into Intellect from the LDAP address book—see Configuration of the LDAP Service.

Prior to configuring the Intellect and Active Directory joint operation, it is necessary to create the groups in Active Directory that correspond to the user permissions in Intellect. It is not recommended to use the Active Directory groups created earlier for other purposes. Each user should be included in only one of the created groups, otherwise the correct joint operation of Intellect and Active Directory is impossible.

The Active Directory operation is configured as follows:

  1. Configuration of the LDAP Service.
  2. Users import from LDAP address book to Intellect database—see Example macro for user import from LDAP address book.
  3. Connecting the Intellect and Active Directory users.
  4. Connecting the Intellect user permissions to Active Directory groups.
  5. Starting the Active Directory synchronization.

Attention!

The connection between the Intellect user permissions and Active Directory security groups must be configured by an administrator who has full Active Directory rights in Windows.

After the Intellect and Active Directory joint operation is configured, the Active Directory users are able to launch, use and configure Intellect using their Windows account in accordance with the Intellect user permissions. The Active Directory users which are connected with the Intellect users, but do not belong to any of the groups associated with the Intellect user permissions, will not be able to launch Intellect.

Important! The automatic changes synchronization is not supported, that is, if the Active Directory user is deleted, disabled, moved to another group, etc., it is necessary to perform the Active Directory synchronization in order to apply these changes in Intellect.


  • No labels