Active Directory Manager Pro Quick start Guide Software version 5.0.0.0 General Information: info@cionsystems.com Online Support: support@cionsystems.com Copyright 2017 CionSystems Inc., All Rights Reserved Page 1
2017 CionSystems Inc. ALL RIGHTS RESERVED. This guide may not be reproduced or transmitted in part or in whole by any means, electronic or mechanical, including photo copying and recording for any purpose other than the purchaser's use under the licensing agreement, without the written permission of CionSystems Inc. The software application in this guide is provided under a software license (EULA) or non-disclosure agreement. This product may only be used in accordance with the terms of the applicable licensing agreement. This guide contains proprietary information protected by copyright. For questions regarding the use of this material and product, contact us at: CionSystems Inc. 6640 185 th Ave NE Redmond, WA-98052, USA http://www.cionsystems.com Ph: +1.425.605.5325 Trademarks CionSystems, CionSystems Inc., the CionSystems Inc. logo, CionSystems Active Directory Manager Pro are trademarks of CionSystems. Other trademarks and registered trademarks used in this guide are property of their respective owners. Copyright 2017 CionSystems Inc., All Rights Reserved Page 2
Table of Contents 1. Introduction... 4 2. Highlights... 5 3. System Requirements... 5 3.1 Getting Ready... 6 Software Requirements... 6 4. Installation... 9 4.1 Installing from a CD... 9 4. 2 Installing from the Web... 9 4.3 Installation Wizard ADM PRO... 10 4.4 Installation Wizard Blackberry component... 15 5. Configuring CionSystems Active Directory Manager Pro... 16 Troubleshooting Installation issues... 18 Windows Server 2008 R2... 18 1. Error: This setup requires Microsoft.NET Framework version 4.0 displays during installation... 18 2. Error: You do not have sufficient privileges to complete this installation displays during installation... 19 3. Error: This setup requires Internet Information Server 5.1 or higher displays during installation... 20 4. Changing Application pool Identity for DefaultAppPool in IISManager... 22 5. Error: Server Error in /ActiveDirecotory Manager Application... 24 6. Error: SQL Login failed during the database configuration of application... 25 Windows Server 2012... 33 1. Error: Installation Incomplete displays during installation... 33 Windows Server 2016... 37 1. Error: Installation Incomplete displays during installation... 37 Copyright 2017 CionSystems Inc., All Rights Reserved Page 3
1. Introduction Active Directory Manager Pro - For every organization identity and access management is far more than a security technology. Identity management gives the users and applications access to the right access information. It is critical to ensure that the right and appropriate permissions are in place for users and applications. This is a major factor in driving regulatory compliance initiatives. Building and managing identity strategy can be complex because it touches all users, applications, resources of the companies and customers. Majority of enterprises faces challenges in maintaining consistent policies thereby incurring high administrative cost and direct impact on security and compliance requirements. CionSystems Active Directory Manager Pro provides a simple and cost effective identity management solution to help you manage accounts across Microsoft directory services. With CionSystems Active Directory Manager Pro you can: Centrally manage identities (users, passwords, computers, contacts, groups, OU, GPO, Exchange, terminal server, site, schema, ACL and more) across Windows - saving time, money and resources. Automate the provisioning process across Windows platforms to reduce costly errors. Manage enterprise-wide password policies, and reduce costly calls to the help desk. Automate Role-Based Access Management. Tighten Security and Auditing processes. Perform global Search and Replace. Reports - Complying with regulatory requirement can be a very complex, time-consuming and expensive. Generating reports for the compliance may not be a cakewalk. It will require accessing a glut of raw data coming from numerous organizations and making sense out of it. Additionally keeping the Identity Management running smoothly requires administrators to know the state of the Active Directory Systems on a proactive basis. A reactive solution can turn out to be a very expensive ordeal for organization as it can effect applications, users and network productivity. Built-in Active Directory auditing lacks many important features and doesn't have reporting capabilities. CionSystems Active Directory Manager Pro helps with compliance and day to day status check by accessing and presenting the raw data into meaningful reports that allows administrator, senior management and auditors to gain correct insight into the Windows Active Directory Infrastructure. Copyright 2017 CionSystems Inc., All Rights Reserved Page 4
2. Highlights Benefits Lower cost of operation Centralized access, single point of access Fast, automate user group provisioning Full reporting and auditing Enforce policies and prove compliance Reliably manage access rights Helps with migration efforts Easy install and ramp-up All functionality included in one file, no need for multiple modules Task approvals decrease errors and inconsistencies Automates the provisioning and de-provisioning process Schedule the tasks of adding and removing objects Monitor the execution of tasks Ability to accept or operations deny requests Approval for entitlement/group membership Easy compliance Multi directory support Features Browser-based UI, customized by role No coding or command line scripting Secure provisioning and de-provisioning Granular password, ACL management 200+ ready-to-use reports, customizable Exchange mailbox management Centrally manage multiple domains Bulk object management Customizable templates increase functionality Real-time notifications inbox size, password expiry, etc Change Approval process Temporary User and Group management Schedule object addition and removal Automated Active Directory cleanup Attestation for user and group LDAP support Permission reports 3. System Requirements CionSystems Active Directory Manager Pro needs: 4GB RAM (6GB Recommended). 50 MB of disk space. Web Browser IE 8 or higher. Windows Server 2003, 2008, 2008R2, 2012, 2012R2, 2016 IIS server 5.1 or higher. Microsoft Exchange administrative tools. For exchange 2007 & 2010 support, please install Exchange management tool on the system where you install ADMPRO Microsoft.NET 4.0 Framework. Access to Exchange Server 2007, 2010 or higher Access to Windows Active Directory (2000, 2003, 2008, 2012, 2016). SQL Server 2008 or higher Full or Express Edition. GPMC Copyright 2017 CionSystems Inc., All Rights Reserved Page 5
3.1 Getting Ready Before installing CionSystems Active Directory Manager Pro, ensure the system has pre-requisites installed and configured correctly. Software Requirements A system with Windows server 2003, Windows server 2003 R2, Windows server 2008, Windows server 2008 R2, Windows server 2012, Windows server 2012 R2 and Windows server 2016 Active Directory Manager Pro is web-based application that is hosted in IIS. Enable IIS server roles, see the below screenshot of IIS services to enable. The picture is from IIS version 7. Copyright 2017 CionSystems Inc., All Rights Reserved Page 6
To install the roles, follow the below process: Go to Control Panelclick on Turn Windows features on or off under ProgramsSelect Roles under Server ManagerClick on Add Roles link button. Add Roles wizard will be startedselect Server Roles link buttonconfigure the Web Server roles as shown below: Click Next Copyright 2017 CionSystems Inc., All Rights Reserved Page 7
Click Install Click Close after installation completed Active Directory Manager Pro asks for IIS username and password during installation. Ensure the username has local administrative privileges on the system. For a domain joined system, ensure the user name appears in local administrative group by going to user manager. In addition, ensure this same user must have access to SQL database, verify it via Microsoft SQL studio manager. When installing on a non-domain joined system, install Microsoft SQL server on this system or use SA account to connect to Microsoft SQL server that is on a different system. Active Directory Manager Pro uses Microsoft SQL database for storing configuration and other information. Before installing the application ensure that you have either installed a local copy of Microsoft SQL server or have appropriate access to a SQL server that is hosted on a different system. Microsoft SQL server two types of authentication, SA or Windows authentication. Please choose the desired SQL authentication at installation. Ensure browser service is running to be able to connect to Microsoft SQL server on a different system Ensure TCP/IP is enabled for SQL Ensure appropriate SQL ports are opened in firewall. To check these settings, please see the troubleshooting section Copyright 2017 CionSystems Inc., All Rights Reserved Page 8
4. Installation CionSystems Active Directory Manager Pro can be installed using a CD or from the web. 4.1 Installing from a CD To install Active directory Manager Pro from CD: 1. Insert CionSystems Active Directory Manager Pro CD into your CD drive. 2. Click on start button. 3. Click on My Computer. 4. Double click on CD drive. 5. Double click on ADManagerPro.msi 6. Setup process will start. 7. Go to Picture 1 in Installation Wizard. 4. 2 Installing from the Web After registration of the Active Directory Manager Pro trial version, an email will be sent with the link to download ADManagerPro.msi To install from the website: 1. Open email. 2. Click on the Download Free Trial link. 3. Save ADManagerPro.msi file to the hard drive. 4. When the download is complete, go to start > windows explorer. 5. Open the file where ADManagerPro.msi file was saved. 6. Double click on ADManagerPro.msi file. 7. Setup process will start. 8. Go to step 1 in Installation Wizard. Copyright 2017 CionSystems Inc., All Rights Reserved Page 9
4.3 Installation Wizard ADM PRO A welcome screen will be opened 1. Click Next 2. Click Next in System Requirements and Info screen Copyright 2017 CionSystems Inc., All Rights Reserved Page 10
3. Select I Agree and click Next 4. Click Next Copyright 2017 CionSystems Inc., All Rights Reserved Page 11
5. Active Directory Manager Pro will start installing. 6. Application Authentication pop up will appear, enter Username and Password, click OK button. If the system is joined in domain, give domain name\username If the system is not joined in domain, give system name\username Copyright 2017 CionSystems Inc., All Rights Reserved Page 12
7. Active Directory Manager Pro installation will be continued 8. SQL Server Configuration popup will appear, if you are installing the application for the first time then click Copyright 2017 CionSystems Inc., All Rights Reserved Page 13
on Create New Database. In Configuration Details, you can select SQL Authentication or Windows Authentication. For SQL Authentication, enter SQL database Server name, Select SQL Authentication, enter Login and Password. Enter valid details and click Test Connection. If Test Connection displays Connected Successfully message, then click on Next For Windows Authentication, enter SQL database Server name, Select Windows Authentication, here, Login and Password will be grayed out. Enter valid details and click Test Connection. If Test Connection displays Connected Successfully message, then click on Next Note: To use the Use Existing Database radio button, AD Manager Pro database should be already exist in the selected SQL database server. If AD Manager Pro database already exist in the selected SQL database server and if you choose Create New Database radio button, then old database will be deleted and new database will be created. Copyright 2017 CionSystems Inc., All Rights Reserved Page 14
9. When installation is complete, click Close 4.4 Installation Wizard Blackberry component Double click on zip file and click on the.msi file to start the installation. Walk through the installation wizard by clicking on next and complete the installation of the mobility component. Copyright 2017 CionSystems Inc., All Rights Reserved Page 15
5. Configuring CionSystems Active Directory Manager Pro To configure ADManagerPro 1. Click on Start Button> All Programs> CionSystems> ADManagerPro icon. (OR) Click ADManagerPro Icon on desktop. 2. The login screen will open in the default web browser, to login on to the application for the first time; Enter admin in the User Name dialogue box. Enter admin in the Password dialogue box. Note: It is recommended that user name and password should be changed after the application has been launched. Copyright 2017 CionSystems Inc., All Rights Reserved Page 16
3. Enter all required domain details and configure the domain. Domain Name. Domain User Name It is critical that this user have highest privileges otherwise some of the functionality may not work. Application uses this account as is context. Domain Password. Enter Domain Controller name Click on Get Domain controllers It will show all the domain controllers for that domain. Select primary radio button of primary domain controller Click on Save. 4. The installation and configuration is complete and you should see the following screen. Copyright 2017 CionSystems Inc., All Rights Reserved Page 17
Once Active Directory Manager Pro is successfully installed and launched, the dashboard window will appear with a view of the active directory categories of reports and task list. For instructions on how the Active Directory Manager Pro dashboard can be customize to meet individual user needs please refer to Active Directory Manager Pro Help Guide. Troubleshooting Installation issues Windows Server 2008 R2 1. Error: This setup requires Microsoft.NET Framework version 4.0 displays during installation If you see the following screen during installation, you need to install the.net Framework version 4.0 Copyright 2017 CionSystems Inc., All Rights Reserved Page 18
To install the.net Framework version 4.0, click on below link. This will redirect to.net Framework 4.0 download page. http://www.microsoft.com/en-in/download/details.aspx?id=17718 Download and install.net Framework4.0, ensure appropriate.net versions are installed. 2. Error: You do not have sufficient privileges to complete this installation displays during installation If you see the following screen during installation, you don t have the privileges to install the.msi file of the application. You have to login as an administrator or you have admin privileges to run the.msi file. Otherwise you may run the.exe file of the application as an administrator by holding down shift key and right click the mouse, choose Run as administrator. Copyright 2017 CionSystems Inc., All Rights Reserved Page 19
3. Error: This setup requires Internet Information Server 5.1 or higher displays during installation If you see the following screen during installation, you need to install the Application Development and IIS6 Management Compatibility roles Make sure you have installed the following roles in Server Manager. Copyright 2017 CionSystems Inc., All Rights Reserved Page 20
Go to Control Panelclick on Turn Windows features on or off under ProgramsSelect Roles under Server ManagerClick on Add Roles link button. Add Roles wizard will be startedselect Server Roles link buttonconfigure the Application Development and IIS6 Management Compatibility roles as shown below: Copyright 2017 CionSystems Inc., All Rights Reserved Page 21
After installing the roles, restart the server to apply the changes. 4. Changing Application pool Identity for DefaultAppPool in IISManager In some case, you have to change the application pool identity to the username and password you provided at install. Process is Start Run commandtype inetmgr IIS Manager Window will be opened. Go to Application PoolsDefaultAppPoolright click and select Advanced SettingsSelect Identity under Process Modelclick on ellipsis buttonselect Custom account click on Set Provide User name, Password and Confirm password detailsclick OKclick OK Copyright 2017 CionSystems Inc., All Rights Reserved Page 22
Copyright 2017 CionSystems Inc., All Rights Reserved Page 23
5. Error: Server Error in /ActiveDirecotory Manager Application If the login fails after trying admin & admin (without quotes): see the solution below Start the sql server management studio and note the sql connection string and username. You have to provide this username during the install of ADManagerPro (refer page 12 - Application Authentication popup window). Otherwise whatever username you provided you have to provide SQL privileges. Also, check the IIS role and ensure the Windows and Basic authentication are enabled. Copyright 2017 CionSystems Inc., All Rights Reserved Page 24
6. Error: SQL Login failed during the database configuration of application SQL Login fails This can happen because the firewall is blocking ports. Check the firewall and SQL to ensure the right SQL ports are open. Probably TCP/IP channel is disabled under SQL Server Configuration Manager. So go there and enable all TCP/IP options Below is an example Click on start All programsmicrosoft SQL Server 2008 R2Click on Configuration ToolsClick on SQL Server Configuration Manager Make sure all TCP/IP channels are enabled Copyright 2017 CionSystems Inc., All Rights Reserved Page 25
Make sure TCP/IP Port has 1433 Select TCP/IP, go to properties, in properties window select IP Addresses tab. In IP1 set TCP Port as 1433 and in IPAll set TCP port as 1433, Click on OK Copyright 2017 CionSystems Inc., All Rights Reserved Page 26
Restart SQLServer and SQL Server Browser services To open above ports in Windows firewall, run the below command from command prompt netsh advfirewall firewall add rule name = SQLPort dir = in protocol = tcp action = allow localport = 1433 remoteip = localsubnet profile = DOMAIN Connecting to remote database: To connect remote database, please check the following settings: 1. Make sure SQL Browser Service is in running state in SQL Server Configuration Manager Copyright 2017 CionSystems Inc., All Rights Reserved Page 27
6. Check is if Remote Connections are enabled on your SQL Server database. Connect to the server, right click the server and open the Server Properties. Copyright 2017 CionSystems Inc., All Rights Reserved Page 28
Navigate to Connections and ensure that Allow remote connections to this server is checked. 7. In firewall enable UDP port (By Default 1434) for SQL Browser Open the Control Panel and navigate to Windows Firewall. Copyright 2017 CionSystems Inc., All Rights Reserved Page 29
Click on Advanced Settings on the left hand side and you should see the Windows Firewall with Advanced Security. Select the Inbound Rules on the left hand side and click on New Rule on the right hand side. This opens the New Inbound Rule Wizard, under the Rule Type choose Port and click the Next button Copyright 2017 CionSystems Inc., All Rights Reserved Page 30
Select the UDP protocol and in the Specific local ports enter port number 1434. To proceed with the settings SQL Browser services, click the Next button In the Action dialog choose Allow the connection and click the Next button Copyright 2017 CionSystems Inc., All Rights Reserved Page 31
In the Profile dialog choose all three profiles and click the Next button Give the rule a name as SQL Browser and click the Finish button. Copyright 2017 CionSystems Inc., All Rights Reserved Page 32
Note: To connect to remote database through windows authentication, the system must be member of that domain and that domain user has to be added in SQL database security logins Windows Server 2012 1. Error: Installation Incomplete displays during installation If you see the following screen during installation, you need to install the Application Development and IIS6 Management Compatibility roles. Copyright 2017 CionSystems Inc., All Rights Reserved Page 33
Make sure you have installed the following roles in Server Manager. Click Server Manager on task bar to open, if not available on task bar then click the Start button to open the start screen. In start screen you can see the Server Manager In Server Manager window, click Manager tab and select Add Roles and Features Copyright 2017 CionSystems Inc., All Rights Reserved Page 34
Click Server Selection, click Next In Server Roles, install the Application Development and IIS6 Management Compatibility roles as shown below: Copyright 2017 CionSystems Inc., All Rights Reserved Page 35
Click Next In Features, make sure.net Framework 3.5 & 4.5 features are installed, if they were not installed configure them as shown below to install. Click Install button After installation completed, click Close button Copyright 2017 CionSystems Inc., All Rights Reserved Page 36
Restart the server to apply the changes Now try to install the application. Windows Server 2016 1. Error: Installation Incomplete displays during installation If you see the following screen during installation, you need to install the Application Development and IIS6 Management Compatibility roles Make sure you have installed the following roles in Server Manager. Copyright 2017 CionSystems Inc., All Rights Reserved Page 37
Click Server Manager on task bar to open, if not available on task bar then click the Start button to open the start screen. In start screen you can see the Server Manager In Server Manager window, click Manager tab and select Add Roles and Features Click Server Selection, click Next Copyright 2017 CionSystems Inc., All Rights Reserved Page 38
In Server Roles, install the Application Development and IIS6 Management Compatibility roles as shown below: Copyright 2017 CionSystems Inc., All Rights Reserved Page 39
Click Next In Features, make sure.net Framework 3.5 & 4.6 features are installed, if they were not installed configure them as shown below to install. Click Install button After installation completed, click Close button Restart the server to apply the changes Now try to install the application. Copyright 2017 CionSystems Inc., All Rights Reserved Page 40
Contact Notes: For technical support or feature requests, please contact us at Support@CionSystems.com or 425.605.5325 For sales or other business inquiries, we can be reached at Sales@CionSystems.com or 425.605.5325 If you d like to view a complete list of our Active Directory Management solutions, please visit us online at www.cionsystems.com Disclaimer The information in this document is provided in connection with CionSystems products. No license, express or implied, to any intellectual property right is granted by this document or in connection with the sale of CionSystems products. EXCEPT AS SET FORTH IN CIONSYSTEMS LICENSE AGREEMENT FOR THIS PRODUCT, CIONSYSTEMS INC. ASSUMES NO LIABILITY WHATSOEVER AND DISCLAIMS ANY EXPRESS, IMPLIED OR STATUTORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING BUT NOT LIMITED TO THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL CIONSYSTEMS INC. BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS INTERRUPTION OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS DOCUMENT, EVEN IF CIONSYSTEMS INC. HAS BEEN ADVISED IN WRITING OF THE POSSIBILITY OF SUCH DAMAGES. CionSystems may update this document or the software application without notice. CionSystems Inc 6640 185 th Ave NE, Redmond, WA-98052, USA www.cionsystems.com Ph: +1.425.605.5325 This guide is provided for informational purposes only, and the contents may not be reproduced or transmitted in any form or by any means without our written permission. Copyright 2017 CionSystems Inc., All Rights Reserved Page 41