Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Anthony_Kahwati
Collaborator

Active Directory Objects

Could I create an object in policy that understands if a host (say a VM) is part of a particular AD group?

For example, if I wanted a policy that says Allow "UserVMs" to "[IntranetSites]" on "https".

Is it possible to have UserVMs as an object that is populated from a connection to AD?

Hope it's explained well enough... essentially trying to make policy a little more dynamic by using AD data.

Thanks

0 Kudos
2 Replies
CaseyB
Advisor

Yes, look at Access Roles & Identity Awareness.

R81.20 Identity Awareness Administration Guide 

0 Kudos
Wolfgang
Authority
Authority

@Anthony_Kahwati yes, that‘s possible.

You can get a Connection to AD via AccountUnit. And with Access-roles you can use AD objects like users, groups, machines in your rules. Additional you can connect via the datacenter object to your vitualization platform (VMware, AWS, Azure etc.) and use the objects from these platforms.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events