Installation Manual

148 Using the iDRAC6 Directory Service
The iDRAC Device object is the link to the iDRAC firmware for querying
Active Directory for authentication and authorization. When a iDRAC is
added to the network, the Administrator must configure the iDRAC and its
device object with its Active Directory name so users can perform
authentication and authorization with Active Directory. Additionally, the
Administrator must add the iDRAC to at least one Association Object in
order for users to authenticate.
Figure 7-1 illustrates that the Association Object provides the connection
that is needed for all of the Authentication and Authorization.
Figure 7-1. Typical Setup for Active Directory Objects
You can create as many or as few association objects as required. However,
you must create at least one Association Object, and you must have one iDRAC
Device Object for each iDRAC on the network that you want to integrate with
Active Directory for Authentication and Authorization with the iDRAC.
The Association Object allows for as many or as few users and/or groups as
well as iDRAC Device Objects. However, the Association Object only
includes one Privilege Object per Association Object. The Association Object
connects the Users who have Privileges on the iDRACs.
The Dell extension to the
Active Directory Users and Computers
MMC
Snap-in only allows associating the Privilege Object and iDRAC Objects from
the same domain with the Association Object. The Dell extension does not
allow a group or an iDRAC object from other domains to be added as a
product member of the Association Object.
iDRAC
User(s)
Group(s)
Privilege Object
iDRAC
Device Object(s)
Association Object