See the Directory Sync Installation & Setup Guide to get started.
Restarting the Domain Controller
You must restart the domain controller during installation for the password sync to start working.
Directory Sync runs automatically without direct interaction. It synchronizes changes from your local Directory to your email accounts every five minutes. Click the "Sync Now" button to synchronize immediately.
Directory Sync is one-way only. It does not synchronize information from Exchange or Rackspace Email back to your Active Directory. If you change any information, such as passwords, using Outlook Web App or Control Panel, your mailboxes will be out of sync with your AD.
Directory Sync will synchronize one local Active Directory domain with multiple email domains.
The domain names may be the same or different. You specify the local AD domain at set up.
Directory Sync uses Active Directory security groups to manage which objects are synchronized with your email service. If you use Hosted Exchange, create a new Security Group for all of your users that will be synchronized with Exchange mailboxes. If you use Hosted Email, create a new Security Group for all of your users that will be synchronized with Hosted Email mailboxes. If you use both Hosted Exchange and Email, you will have two security groups. Directory sync will create and manage mailboxes for all user objects that you add to the security groups.
Directory Sync associates AD User objects with email accounts by their Mail Attribute. The mail attribute is the email address property associated to the user.
*Note: If upgrading to Version 1.4, you MUST UPDATE each user’s email address property to match the current email address.
Password Hook Sync
You must install a password hook on each Domain Controller. The password hook can synchronize user passwords only at the moment the password is changed in AD.
When you install Directory Sync, it cannot automatically sync existing passwords because they are unreadable from Active Directory. Users will continue to use their old email passwords. When a user manually changes their password, then DirSync will sync it with their mailbox.
Assign user objects to email security groups before you change passwords. Otherwise, Directory Sync will not set the new passwords.
When you create new mailboxes, those users must change passwords before they can access their email.
Distribution List Membership Sync. Sync users within distribution lists or security groups from Active Directory to distribution list membership within Email Control Panel. Directory Sync uses the group’s email address property to sync with the hosted Exchange distribution list.
Exchange Contacts. Sync Contact objects within the Active Directory to your Exchange Contacts within the Hosted Exchange environment. Within the Active Directory you will be able to set up the external email address the contact will forward to. Directory sync uses the contact object’s mail attribute to set this.
Add a new mailbox:
*Note: Directory Sync will create a mailbox for the user and synchronize the user's new password. The email address will be based on the user’s email address property (mail Attribute)
Create a mailbox for an existing user:
*Note: Directory Sync will create a mailbox for the user and synchronize the user's new password. The email address will be based on the user’s UPN.
Connect an existing user with an existing mailbox:
*Note: Directory Sync will synchronize the new password with the mailbox.
Remove a user mailbox
*Note: Directory Sync does not automatically delete mailboxes to prevent accidental deletions.
Create a Distribution List
a. New distribution lists, provide an email address before subscribing to the Hosted Exchange security group.
b. Existing distribution lists in active directory, add an email address if it doesn't exist, or update the email address to match the email in Control Panel before syncing. If the email address doesn't match with CP, a new distribution list will be created
* Note: In order for memberships of the distribution list created in step one to sync as members of the distribution list in the control panel, the members must also be subscribed to either the Hosted Exchange group or the Hosted Email group specified in the Directory Sync Settings.
Delete a Distribution List
*Note: After the next synchronization, the distribution list will be deleted from the Email Control Panel.
Create a Contact (Exchange)
*Note: The objectGUID attribute of the contact is used as the username for the contact within the Email Control Panel. AD automatically creates this and you will not need to create one for it and is how Directory Sync references the contact through our API.
*Customer’s with multiple email domains will need to edit the otherMailBox attribute (of the contact object) to contain the desired domain to sync. You will only need to have the desired domain set within this attribute.
Delete a Contact (Exchange)
*Note: After the next synchronization, the contact will be deleted from the Email Control Panel.
Change the external email address of a Contact (Exchange)
Rename a Hosted Service Security Group
User Password Requirements
User passwords must meet the following requirements. Directory Sync will not set an email password that does not meet these criteria. We recommend that you change your domain password rules to meet or exceed these:
Must be at least 8 characters
Cannot include your username, display name, or full name
Must contain 3 of the 4 character groups:
Passwords must contain at least 6 characters
Passwords cannot contain:
You do not have to open any inbound ports form the internet to your domain controllers.
Enable the following ports on the Directory Sync server:
Communications between Directory Sync and Rackspace is secured through HTTPS. Communications between the Active Directory password hook and Directory Sync is secured with Microsoft WCF Transport Security which uses Windows Authentication and encryption.
Directory Sync will synchronize the following user attributes with Exchange and Rackspace Email mailboxes. Some attributes differ between Rackspace and Exchange mailboxes.
List Format: Email Attribute: ADSI property (limitations)
© 2011-2013 Rackspace US, Inc.
Except where otherwise noted, content on this site is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License