Active Directory Integration with Pronestor
Pronestor supports Active Directory integration, allowing you to:
Import users directly from Active Directory
Maintain Pronestor users through Active Directory groups
Have several user imports in Pronestor
Configure the Active Directory import tool for on-premise customers by:
When running an on-premises solution, the Active directory integration is an integrated part of the Administration Module in Pronestor. It just needs to be configured. Follow these steps:
Create the Active Directory import in Pronestor
Click Administration
Click Settings
Click import users
Click New import job
Then fill out the new window. For example, name it "Active directory".
Configuring Active Directory Import Tool
Fill out the fields and save.
Relative path can just be *
Open the import.
Choose the "General" tab
Enable automatic scheduling
Your import will now run daily at your chosen time.
Please note, if the import runs at the same time as any application pool recycling on the server, the import will fail. You can avoid this by moving the daily run time of the ad import.
First import
For cloud customers, this will happen automatically when you trigger the PowerShell script.
For on-premise customers, this can be triggered manually. This can take some time, depending on the size of your Active directory. Open your import by pressing the pencil.
Importing Data in Pronestor
!! Note: The import process can take a long time.
To import data in Pronestor:
Choose the tab called Sessions
Press "Perform import"
After the import, users won't enter Pronestor until after the groups are linked as shown in the next chapter.
Group linking in Pronestor
After the first import of your Active Directory, you need to link the Active Directory groups to Pronestor rights. This is handled inside Pronestor's administration module.
Click "Settings"
Click "Import users"
Find your import job
Click "Edit"
Click "Linking"
Here you can see all the accesses within Pronestor and you can connect them to a group. Please note that these pictures are from a demo solution with just one location and no departments nor VIP groups, so yours might have a lot more accesses in here.
Click "Load AD structure"
Please link your Active Directory groups to the accesses you want them to give, by clicking the drop down menu.
Managing user imports
Link the groups as desired. Remember the rules about what accesses are needed for users to be imported as described in the chapter called Setting up active directory
Do another import.