H3C Technologies H3C Intelligent Management Center User Manual

Page 378

Advertising
background image

360

the sub-base DN. If this option is disabled (No), UAM synchronizes all users in the sub-base DN,

including users in the OUs in the sub-base DN.

{

Inherit Parent Group's Service—This option appears only when the selected LDAP server uses
the following settings:

Manual Assignment is selected for the Service Sync Type field.

The Apply for Service by User Group option is enabled.

Synchronize by OU is selected for the User Group field.

With the Inherit Parent Group's Service option enabled, UAM applies for the services of the

parent user group for the LDAP users who belong to a group of no service.

If the parent user group has no service, UAM uses the services of the parent user group of
that parent group, and so forth until the upper-most user group.

If none of these parent user groups have services, UAM does not apply for any service for
the LDAP users. When the Inherit Parent Group's Service option is disabled, UAM applies

for the same services for each LDAP user as those assigned to the user group to which the

LDAP user belongs.

If a user belongs to a user group of no service, UAM does not apply for any service for the
user.

{

Service Group—Service group that the LDAP synchronization policy belongs to. It is always the

same as the service group that the LDAP server is assigned to.

Basic Information area

{

User Name—Username attribute description used on the LDAP server. UAM uses the value of

this attribute as the username of the LDAP user account when executing the synchronization
policy.

{

Identity Number—Identity attribute description used on the LDAP server. UAM uses the value of
this attribute as the LDAP user identity when executing the synchronization policy.

{

Contact Address—Contact address attribute description used on the LDAP server. UAM uses the
value of the attribute as the LDAP user identity when executing the synchronization policy. An

empty field indicates that user contact addresses are not synchronized from the LDAP server.

{

Telephone—Telephone attribute description used on the LDAP server. UAM uses the value of this
attribute as the user telephone number when executing the synchronization policy. An empty
field indicates that user telephone numbers are not synchronized from the LDAP server.

{

Email—Email attribute description used on the LDAP server. UAM uses the value of this attribute
as the user email account when executing the synchronization policy. An empty field indicates

that user email accounts are not synchronized from the LDAP server.

{

User Group—User group that the LDAP users are assigned to in UAM. This option appears only
when Manual Specify is selected for the User Group field of LDAP server specified in the

synchronization policy.

Additional Information area
Attribute descriptions used on the LDAP server for user additional information fields, which vary
with your choice. UAM uses the values of these attributes to populate the user additional
information fields. An empty field indicates that the additional information settings are not

synchronized from the LDAP server.
Access Information area

Advertising