|Published Date : 18 Jul 2014
Last Updated : 07 Jul 2020
Content Ref: DWN3182456
RM Cloud Service Delivery can assist you with your RM Unify AD Sync installation.For further information, please speak to your Sales representative on 0845 070 0300 or email firstname.lastname@example.org, quoting this article.
RM Unify AD Sync is available to RM Unify Premium account customers, or customers who have purchased RM SafetyNet. It allows network managers to synchronise local school user accounts and passwords with RM Unify. This service ensures that students and school staff can access RM Unify with the same user account details that they use to access their local network resources.
There are two components: RM Unify AD Sync and the RM Unify Password Filter. This download article provides:
- RM Unify AD Sync v4 for Community Connect® 4 (CC4) Release Note.
- RM Unify AD Sync v4 for Microsoft® Windows Server® networks Release Note.
- The file rm_unify_ad_sync_v4.zip, which contains installers for:
- RM Unify AD Sync
- RM Unify Password Filter
What's new and changed with RM Unify AD Sync v4
- When a disabled AD account is modified, AD Sync now uploads the user changes to RM Unify, provided the AD user account still matches an AD filer and role mapping.
- When a disabled AD user account is deleted, AD Sync now uploads the delete message to RM Unify provided the AD user account still matches an AD filter and role mapping.
- When an OU is deleted, AD Sync now uploads delete messages to RM Unify for users in the OU.
- Enabling the 'mail' attribute in one AD filter no longer enables it for all filters.
- When a 'resync with delete' is run, AD Sync no longer uploads a delete message for disabled users, provided the AD user account still matches an AD filter and role mapping.
- The 'with delete' feature of AD Sync resync has been moved from the Settings page and is now enabled from the resync screen. Once a 'resync with delete' has been completed, the 'with delete' option is toggled off.
RM Unify AD Sync can be installed on the following networks:
- CC4 networks (including CC4 Matrix):
- CC4.5/CoP Connect on Prem (Windows Server 2012 R2 and 2016)
- CoP Connect on Prem (Windows Server 2019)
- Other Active Directory networks based on:
- Windows Server 2012 R2
- Windows Server 2016
- Windows Server 2019
|**Important - Pre-existing AD Sync RM Unify accounts**|
If you already have an RM Unify establishment populated with AD Sync provisioned user accounts from a different Active Directory or CC4 network, you must perform an AD Sync migration as per TEC4061769 'Migrating RM Unify AD Sync provisioning to a new Active Directory', which can be found in the Other Useful Articles section below.
If you do not, you risk duplicating all of your RM Unify accounts and also all your Office 365 and/or G Suite accounts etc.
|Pre-requisites and installation:|
- Prerequisites for installing RM Unify AD Sync:
- Microsoft .NET Framework v3.5 SP1
- Prerequisites for installing RM Unify Password Filter:
- Microsoft .NET Framework v3.5 SP1
- The appropriate version of Microsoft Visual C++ 2010 Redistributable Package for your server (32-bit and 64-bit, depending on the operating system version)
Passwords are captured when they are changed on the network.
- For schools installing RM Unify AD Sync for the first time, all users must change their password in order to fully synchronise local network accounts and passwords with RM Unify. The release notes give instructions for forcing a password change.
- Installation of the RM Unify Password Filter will require a reboot of all domain controllers.
- Refer to the appropriate release notes for full information on requirements, how to check the prerequisites and how to install the components.
|Active Directory requirements for installing RM Unify AD Sync multiple schools in a single AD domain|
RM Unify AD Sync allows LAs, academy trusts or clusters of schools that have consolidated their Active Directory into a single domain to use a single instance of RM Unify AD Sync.
The set of users in each school is identified by an Active Directory organisational unit (OU) and optional group membership. This means that either each school should be identifiable in the Active Directory by a unique OU or if all schools are in the same OU, then each school must have a unique Active Directory group.
Once the set of users in a school is identified, RM Unify AD Sync can use either child OU, Active Directory group membership or profile path to derive the user role for that school. This set of users is then assigned one of the standard set of roles understood by RM Unify (Student, Teaching Staff, Non-Teaching Staff, Governors, Other).
If this is a new installation of RM Unify AD Sync or if you are upgrading from RM Unify AD Sync v2 or v3, you need to download these files:
- RM Unify AD Sync v4 Release Note relevant to your network.
To download a file from the Download section below:
- Right-click the disk icon for the file you want and choose Save Target As.
- When the Save As window prompts you for a destination, browse to the folder where you want to save it and click Save.
- When it has downloaded, click Close.
For instructions, please refer to the appropriate release note for your network:
- For CC4 networks, follow the instructions in the rm_unify_ad_sync_v4_for_cc4_release_note.pdf from the Download section.
- For other Windows Server networks, follow the file instructions in the rm_unify_ad_sync_v4_for_ws_release_note.pdf file from the Download section.
|Post-installation server checks|
- Log on to the server as an administrator.
- Click Start, Control Panel.
- Follow the appropriate steps given below on your server operating system:
- Click Programs, 'Uninstall a program'.
- Select each component in turn and check its version number.
- Close the 'Uninstall or change a program' window.
For any additional servers, repeat these steps.
|RM Unify AD Sync*
|RM Unify Password Filter 64-bit**
|RM Unify Password Filter 32-bit***
* Only on the server where you have chosen to install RM Unify AD Sync.
** On all 64-bit domain controller servers.
*** On all 32-bit domain controller servers.
|Post-installation user checks|
- For new installations and upgrades, provision a new user into RM Unify. Once provisioned, change their network password and confirm you can log on to RM Unify.
- For upgrades only, change the network password of a user that was already provisioned into RM Unify and confirm you can log on to RM Unify with the new password.
If this article has not helped provide a solution then it is also possible to
log a call...
Document Keywords: download, install, unify, provisioning, administration, synchronisation, ad sync v4, ad sync, adsync, config tool