IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB Protection: How to Migrate Active Directory Groups While Active Directory Mappings are in Use

CB Protection: How to Migrate Active Directory Groups While Active Directory Mappings are in Use

Environment

  • CB Protection Server: 7.x and Higher
  • Microsoft Active Directory

Objective

To outline the recommended steps for migrating Active Directory groups while Active Directory mappings are in use.

Resolution

  1. Schedule a time to have a Protection admin and the AD admin work together during the migration. 
  2. Create a new group(s) (not moving the existing ones) into the desired location in AD. 
  3. Add the desired users to the new group location. 
  4. Have the Protection admin modify the role mapping to the new AD group. 
  5. Verify the users can log in with the new mapping. 
  6. Delete the old AD group.

Additional Notes

  • Simply moving the AD groups into another area in the domain (different or nested OU) can cause issues with the console and console access.
  • Having both a Protection and Active Directory admin on hand and working together can help limit downtime in the event of an issue as changes can be undone quicker.

Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎02-20-2019
Views:
539
Contributors