Active Directory synchronization using TNI

Synchronizing with Active Directory allows you to automatically replicate the OU structure in the Network tree. A group will be created for each OU in the current domain, and each computer in the domain will be moved to the corresponding group. You can synchronize the entire Storage or an individual group within it.

To synchronize the Storage with AD, you must set the AD object’s LDAP address in the properties of the Storage root or a group. Then right-click the root node or a group and choose one of the two synchronization options:

Synchronize Storage with AD will prompt you to synchronize groups, devices, and AD users. Synchronize with AD is limited to groups and devices.

Next, a confirmation window will appear.

In the confirmation window, you can select specific groups, assets, or users and confirm the corresponding operations.

In the lower part of the window, the following buttons are available for selecting display modes for the task tree synchronization:

Group view mode – displays operations in a hierarchical tree structure with groups, assets, and users nested accordingly.
Simple view mode – displays all synchronization tasks in one list with minimal nesting, organized by task category.

To synchronize an individual group in the Storage, set the AD object’s LDAP address in the group properties. Then right-click the group node and choose Synchronize with AD.

During the synchronization, assets will receive the Location and Description information from AD, if available, as well as the OS Version (for assets that have connected to the domain at least once).

Users are also synchronized with AD during every Storage synchronization and can be synced separately by going to the Users tab and clicking Synchronize with AD. This function retrieves AD users, including their names, job titles, contact information, and other details, and adds them to the Storage for easier searching and report building.

Placeholders are stubs created for each device that has been discovered in the domain but has not yet been scanned. These placeholders are empty nodes that can be rescanned to retrieve inventory information. They are displayed with the following icon  in the Network tree, and the following hint will be displayed in the Viewer & reports General information tab for such assets:

Placeholders contain some basic information from AD: Description, Location, OS name and version, and installed Service Pack. To retrieve the full inventory information, right-click a stub and select Rescan from the context menu. You can also select Convert it to a custom asset Convert it to a custom asset to convert the stub into a custom asset.

You can also choose what to do if a previously scanned PC is not found in the domain during synchronization: move it to a separate group or delete it.

The main Active Directory synchronization settings are located in Options General (the Advanced settings mode)

You can also configure TNI to synchronize on startup, select the synchronization targets, and configure other synchronization settings by going to Scheduler and adding the appropriate task.

Active Directory synchronization is one-way only: data can only be imported from AD to TNI at this time.

In some cases, additional configuration of Active Directory synchronization may be required, for example if the computer that performs the synchronization is not joined to the domain or is not located on the same local network as the domain controller.

In this case, select the appropriate group in the network tree and open its Properties. In the synchronization settings, specify the domain controller’s network address, such as an IP address, hostname, or FQDN.

The synchronization settings also include a Secure connection option, which encrypts the connection using LDAPS (LDAP over TLS). This option can be enabled in the properties of the storage root or the selected group.

To use a secure connection, LDAPS must be enabled on the Active Directory server and a valid certificate must be installed and properly configured. By default, LDAP uses port 389 and LDAPS uses port 636. When synchronizing from a computer outside the domain, the certificate must be installed in the Trusted Root Certification Authorities store.

Contents