- 02 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Multiple Synchronization Profiles
- Mis à jour le 02 Jan 2025
- 1 Minute à lire
- SombreLumière
- PDF
Multiple synchronization profiles can be configured for the following purposes:
- To manage synchronization from multiple LDAP servers to different domains on a single OneSpan Authentication Server Appliance instance.
- To filter user accounts on more than one value of a particular LDAP server attribute, e.g. to synchronize user accounts for which the email address attribute matches both domainA.com or domainB.com endings. Specifying both these specifications for a filter match in a single synchronization profile would only retrieve accounts that had both values for the email address attribute. Retrieving accounts that have one or the other value therefore requires two profiles.
- To help manage source and destination organizational hierarchies.
With multiple synchronization profiles, synchronizations are completed one after another, i.e. not simultaneously, and are grouped according to their LDAP server and Bind DN to optimize re-use of connections and authentications.
If a server cannot be contacted, further synchronizations from the same server are skipped until the next scheduled synchronization.
More than one synchronization profile can be applied to a particular user account record, although this is not recommended, because it may cause user account properties in the OneSpan Authentication Server Appliance data store to alternate between different values synchronized from the different profiles.