BusinessObjects Enterprise Administrator's Guide

Mapping AD accounts

To simplify administration, BusinessObjects Enterprise supports AD authentication for user and group accounts. However, before users can use their AD user name and password to log on to BusinessObjects Enterprise, their AD user account needs to be mapped to BusinessObjects Enterprise. When you map an AD account, you can choose to create a new BusinessObjects Enterprise account or link to an existing BusinessObjects Enterprise account.

To map AD users and groups

Before starting this procedure, ensure that you have the appropriate AD domain and group information. As well, you must have created a domain user account on your AD server for BusinessObjects Enterprise to use when authenticating AD users and groups.

  1. Go to the Authentication management area of the CMC.
  2. Click the Windows AD tab.
  3.  

  4. Ensure that the Windows Active Directory Authentication is enabled check box is selected.
  5. If you will be using single sign-on, select the Single Sign On is enabled check box.
  6. Note:    If you select this option, you must also configure the IIS for single sign-on. For details, see Setting up AD single sign-on. Failing to configure IIS could compromise your system security if the account that IIS runs under belongs to a mapped group, because users who use one of the web applications would automatically have the same access privileges as the IIS machine account.

  7. In the "AD Administration Credentials" area, enter the name and password of the domain user account you've set up on your AD server for BusinessObjects Enterprise to use when authenticating AD users and groups.
  8. Administration credentials can use one of the following formats:

    Administration credentials must be entered to enable AD authentication, map groups, check rights, and so on.

  9. Complete the Default AD Domain field.
  10. Note:    

  11. In the "Mapped AD Member Groups" area, enter the AD domain\group in the Add AD Group (Domain\Group) field.
  12. Groups can be mapped using one of the following formats:

  13. Click Add.
  14. The group is added to the list.

  15. New Alias Options allow you to specify how AD aliases are mapped to Enterprise accounts. Select either:
  16. Update Options allow you to specify if AD aliases are automatically created for all new users. Select either:
  17. New User Options allow you to specify properties of the new Enterprise accounts that are created to map to AD accounts. Select either:
  18. Click Update.
  19. A message appears stating that it will take several seconds to update the member groups.

  20. Click OK.


Business Objects
http://www.businessobjects.com/
Support services
http://www.businessobjects.com/services/support/
Product Documentation on the Web
http://support.businessobjects.com/documentation/