CB Protection: How to Migrate Active Directory Groups While Active Directory Mappings are in Use
search cancel

CB Protection: How to Migrate Active Directory Groups While Active Directory Mappings are in Use

book

Article ID: 290179

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

To outline the recommended steps for migrating Active Directory groups while Active Directory mappings are in use.

Environment

  • CB Protection Server: 7.x and Higher
  • Microsoft Active Directory

Resolution

  1. Schedule a time to have a Protection admin and the AD admin work together during the migration. 
  2. Create a new group(s) (not moving the existing ones) into the desired location in AD. 
  3. Add the desired users to the new group location. 
  4. Have the Protection admin modify the role mapping to the new AD group. 
  5. Verify the users can log in with the new mapping. 
  6. Delete the old AD group.

Additional Information

  • Simply moving the AD groups into another area in the domain (different or nested OU) can cause issues with the console and console access.
  • Having both a Protection and Active Directory admin on hand and working together can help limit downtime in the event of an issue as changes can be undone quicker.