Synchronizing IAM with an AD Bridge
You can run an bridge to synchronize IAM with Microsoft Active Directory immediately.
As part of configuring an AD bridge, you specified how often, in hours and minutes, you want IAM to use the bridge to import users and groups from Microsoft Active Directory. You're synchronizing IAM with your Microsoft Active Directory enterprise directory structure.
When the interval you specified elapses, IAM synchronizes with the directory structure so that any new, updated, or deleted user or group records are transferred into IAM. Because of this, the state of each record is synchronized between Microsoft Active Directory and IAM.
- Full import: The AD bridge polls Microsoft Active Directory and retrieves data associated with all user and groups that you selected in the Select organizational units (OUs) for users and Select organizational units (OUs) for groups panes of the Configuration tab for the bridge. This data represents users and groups that were created, modified, or removed inMicrosoft Active Directory AD. As a best practice, we recommend that you perform a full import the first time you run the bridge.
- Incremental import: Similar to a full import, but for this type of import, the bridge polls Microsoft Active Directory and retrieves only user and group data that changed since you last used the bridge to import users and groups into IAM.
By running the bridge, you can propagate changes for IAM users in Microsoft Active Directory. After users are imported into IAM through the bridge, if you activate or deactivate a user, modify the user's attribute values, or change the group memberships for the user in IAM, then these changes are reflected in Microsoft Active Directory.
You can also use the bridge to view a synchronization log of the communication between IAM and Microsoft Active Directory.