User's Manual

170 Using the CMC With Microsoft Active Directory
Figure 7-1. Typical Setup for Active Directory Objects
The Association Object allows for as many or as few users and/or groups as
well as RAC Device Objects. However, the Association Object only includes
one Privilege Object per Association Object. The Association Object
connects the "Users" who have "Privileges" on the RACs (CMCs).
Additionally, you can configure Active Directory objects in a single domain or
in multiple domains. For example, you have two CMCs (RAC1 and RAC2)
and three existing Active Directory users (user1, user2, and user3). You want
to give user1 and user2 an administrator privilege to both CMCs and give
user3 a login privilege to the RAC2 card. Figure 7-2 illustrates how you set up
the Active Directory objects in this scenario.
When adding Universal Groups from separate domains, create an Association
Object with Universal Scope. The Default Association objects created by the
Dell Schema Extender Utility are Domain Local Groups and will not work
with Universal Groups from other domains.
Association Object
User(s) Group(s) Privilege Object RAC Device Object(s)
RAC Privilege Object