Best practice for connecting IDM to Active Directory -- VIP vs. individual domain controllers
search cancel

Best practice for connecting IDM to Active Directory -- VIP vs. individual domain controllers

book

Article ID: 130956

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Governance CA Identity Portal

Issue/Introduction

You want to connect IDM to the VIP of Active Directory for provisioning. Initially, you were connected to individual DCs (Domain Controllers). You need to understand which would be best: VIP or DC.

Environment

Identity Suite Virtual Appliance 14.x

Resolution

When configuring Active Directory endpoints, specify the AD domain controller address, not the VIP.

When creating AD accounts, it is a multi-step process (i.e. create account, set password, set useraccountcontrol, set groups, set other attributes, create mailbox).

What happens if the requests get spread out to different DCs is that you can end up with replication latency and collision objects.

The AD Connector provides a failover list of DCs, so you should just point to DCs and have the backup DC list.