Users Guide

Table Of Contents
Related information
Manage OpenManage Enterprise users on page 141
Import AD and LDAP groups
NOTE:
The users without Administrator rights cannot enable or disable the Active Directory (AD) and Lightweight Directory
Access Protocol (LDAP) users.
Before importing AD groups in OpenManage Enterprise, you must include the user groups in a UNIVERSAL GROUP while
configuring the AD.
AD and LDAP directory users can be imported and assigned one of the OpenManage Enterprise roles (Admin,
DeviceManager, or Viewer). The Single-Sign-On (SSO) feature stops at login to the console. Actions run on the devices
require a privileged account on the device.
Post upgrade of OpenManage Enterprise to version 3.6.x, the AD/LDAP and OIDC (PingFederate or KeyCloak)
device managers would need to recreate all the previous-version entities as these entities are only available to the
administrators post upgrade. For more information, see the Release Notes at https://www.dell.com/support/home/
en-yu/product-support/product/dell-openmanage-enterprise/docs
1. Click Import Directory Group.
2. In the Import Active Directory dialog box:
a. From the Directory Source drop-down menu, select an AD or LDAP source that must be imported for adding groups.
For adding directories, see Add or edit Active Directory groups to be used with Directory Services on page 149.
b. Click Input Credentials.
c. In the dialog box, type the username and password of the domain where the directory is saved. Use tool tips to enter the
correct syntax.
d. Click Finish.
3. In the Available Groups section:
a. In the Find a Group box, enter the initial few letters of the group name available in the tested directory. All the groups
names that begin with the entered text are listed under GROUP NAME.
b. Select the check boxes corresponding to the groups be imported, and then click the >> or << buttons to add or remove
the groups.
4. In the Groups to be Imported section:
a. Select the check boxes of the groups, and then select a role from the Assign Group Role drop-down menu. For more
information about the role-based access, see Role and scope based access control in OpenManage Enterprise on page 15.
b. Click Assign Role.
The users in the group under the selected directory service are assigned with the selected user roles.
c. For the Device Manager role, the scope is defaulted to All Devices, however, the administrator can restrict the scope by
choosing the Assign Scope option followed by selecting the device group(s).
5. Repeat steps 3 and 4, if necessary.
6. Click Import.
The directory groups are imported and displayed in the Users list. However, all users in those groups will log in to
OpenManage Enterprise by using their domain username and credentials.
It is possible for a domain user, for example john_smith, to be a member of multiple directory groups, and also for those groups
to be assigned different roles. In this case, multiple roles such as Device Manager and Viewer are displayed upon a mouseover
on the username on the appliance masthead right-hand corner. Such users will receive the highest level role for all the directory
groups the user is a member of.
Example 1: The user is a member of three groups with admin, DM, and viewer roles. In this case, user becomes an
administrator.
Example 2: The user is a member of three DM groups and a viewer group. In this case, the user will become a DM with
access to the union of device groups across the three DM roles.
Managing OpenManage Enterprise appliance settings
147