Registering an AD domain using a DNS server

Ops Center Administrator User Guide

Version
11.0.x
Audience
anonymous
Part Number
MK-99ADM001-21

The preferred method for registering an AD domain registration is by using DNS, which uses Ops Center Administrator security settings and locates AD servers based on DNS-based SRV records. If this method fails in your environment, which can happen when there are a large number of SRV records, you can register an AD domain by using VAM.

Note: Currently, only Microsoft Active Directory is supported for AD authentication.
  • Supported AD platforms: Currently, only Microsoft Active Directory is supported for AD authentication.
  • AD domain registration is via DNS or by VAM:

    Two methods can be used to register a Microsoft Active Directory account domain with Ops Center Administrator. The first uses the Ops Center Administrator security settings and locates AD servers based on DNS-based SRV records. The second method, using VAM, should be used only in the case that the first solution doesn't work. The one known reason why the first solution might fail is a large number of SRV records.

Verify the following:

  • DNS server in Ops Center Administrator points only to DNS servers that are able to resolve SRV records for your AD environment. In a Microsoft AD environment, Microsoft DNS servers for a specific domain can resolve the SRV records for your AD environment.
  • User has a Security Administrator role.
  • If you plan to enable SSL / TLS, a Root Certification Authority Certificate is saved to a location that you can access.
  1. Open a browser, enter the IP address of your Ops Center Administrator host machine, and log in to Ops Center Administrator.
  2. Click Settings and select Security Settings to open the Security window.
  3. Click the pencil icon to open the Account Credentials window.
  4. Enter a valid user name in UPN format (for example: FirstName.LastName@example.com) and the user password. Click OK.
  5. In the Account Domain field, enter your Active Directory DNS domain name.
  6. (Optional) To enable SSL or TLS, select Enable SSL/TLS, and then click Import Certificate to import a Root Certification Authority Certificate.
  7. Click Submit.
    A job starts to create an account domain.

    You can view the status of the job in the Jobs window.

  8. When the job completes successfully, you can add Active Directory groups in Group Name in Security Settings.