Grant sufficient permissions in Active Directory to enable user access control in Trend Vision One.
The following table outlines the permission scope options available when configuring the Active Directory (on-premises) connector in Third-Party Integration.
Permission Scope |
Description |
---|---|
Read |
Allows you to sync Active Directory data, such as user lists and group memberships. Important:
To use this permission scope, ensure you configure the Active Directory server connection using an Active Directory account with at least domain user permissions. |
Read & Write |
Allows you to:
Important:
To use this permission scope, ensure you configure the Active Directory server connection using an Active Directory account with sufficient read and write permissions |
To enable user access control response actions on connected Active Directory accounts, you must configure the Active Directory server connection using a service account with sufficient permissions. You can grant the necessary permissions using one of the following three options.
Option 1: Assign the service account to an Active Directory security group with sufficient permissions. The following groups have sufficient permissions:
Administrators
Domain Admins
Enterprise Admins
Account Operator
Option 2: Delegate the following Active Directory common task to the service account:
Create, delete, and manage user accounts
Option 3: Configure the following permission settings in Advanced Security Settings:
Trend Micro does not recommend this option because it may become invalid unexpectedly as new features are added to Trend Vision One.
Setting |
Value |
---|---|
Principal |
Specify the service account used in Trend Vision One. |
Type |
Allow |
Applies to |
Descendant User objects |
Permissions |
Reset password |
Properties |
|