What is constantly synchronized between ONTAP and Active Directory?
Applies to
- ONTAP 9
- Active Directory (AD)
Answer
- ONTAP and AD continuously interact to manage authentication and authorization for access to storage resources.
- The integration between ONTAP and AD typically involves the following:
- User and group account information: ONTAP uses AD to authenticate users and to apply appropriate permissions based on group membership.
- Domain information: ONTAP systems join AD domains to participate in the domain's security infrastructure.
- Kerberos tickets: For secure authentication, ONTAP systems use Kerberos tickets provided by AD.
- LDAP queries: ONTAP perform LDAP queries to AD to retrieve user and group details.
- DNS information: ONTAP systems use AD-integrated DNS for name resolution.
- Organizational Units (OUs): ONTAP can be configured to recognize OUs from AD to manage storage resources and access control policies.
Additional Information
additionalInformation_text