|Situation||You want to sync OnPrem Active Directory accounts to Proofpoint Essentials.|
Enable Active Directory Sync according to instructions below, and additional information such as:
The preferred method of user synchronization is via LDAP Discovery using Proofpoint Essentials’ Active Directory connector module. This allows the Proofpoint Essentials Platform to import:
- Active users (including both primary email address and user aliases)
- Distribution lists
- Security groups (both standard and mail enabled)
- Public folders
Enable Active Directory Sync
If you have Active Directory located on your premises, you can use the Proofpoint Essentials Active Directory Sync option to add and automatically sync user accounts and groups between environments.
Before you begin, you will need the following:
- An inbound connection that allows Proofpoint Essentials IP range to connect to your domain controller.
- A user account with read permissions to Active Directory.
- A user account with administrator privileges to Proofpoint Essentials.
- The Base DN (Distinguished Name).
- The Base DN is the starting point for directory server searches
- For example: DC=mycompany,DC=com, the Connector starts from this DN to create the list of users and groups to sync
Support for LDAP and LDAP over SSL
The standard protocol for reading data to Active Directory is LDAP. LDAP traffic is unsecured by default. To make LDAP traffic secure, you can use the Secure Sockets Layer/Transport Layer Security (SSL/TLS) protocols. This combination is referred to as LDAP over SSL -- or LDAPS.
To setup your domain controller to accept LDAP over SSL, please refer to the following Microsoft article: How to enable LDAP over SSL
Configure Active Directory Sync in Proofpoint Essentials
- Log in to the user interface
- Navigate to Administration > User Management > Import & Sync > Active Directory Sync.
- From the Default New User Role dropdown, select the option to use for user accounts added to Proofpoint Essentials.
Silent User A user account with a silent user role will receive the quarantine digest email but will not have login rights to the interface. End User A user account with an end user role Will receive the quarantine digest email and will have login rights to the interface.
- For Active Directory URL, specify the IP address or hostname of your Active Directory that Proofpoint Essentials will connect to.
- Specify the Username and Password of the account.
- From the Port dropdown, select the desired connection port.
- LDAP (389)
- LDAP over SSL (636)
- Enter the Base DN that Proofpoint Essentials should use to connect to your Active Directory.
For example, DC=mycompany,DC=local The Active Directory configuration is stored in the customer creation process and is executed by the administrator once the customer has been created. Active Directory sync requires the customer to allow Proofpoint Essentials to access the environment over Port 389. Connections are over TLS.
- Under What To Sync, enable the options you would like Proofpoint Essentials to sync.
- For How To Sync, enable the desired options.
Add Create new user accounts and groups. Sync Updated Accounts Update existing user accounts and groups. Delete Removed Accounts Remove accounts from Proofpoint Essentials that are no longer found in Active Directory.
- For When To Sync, select the desired frequency from the Sync frequency dropdown.
Manually Perform Active Directory Sync
If you checked a time frequency to sync in the Active Directory settings, a sync is automatically performed. Otherwise, you need to force a sync.
- Navigate to Administration > User Mangement > Import & Sync > Active Directory Sync.
- Click Search Now.
- Review the search results.
- Click Sync Active Directory.