Active directory synchronization with lotus adsync

Hello,

Excuse me if the answer to this question is obvious, I’m an NT/2K admin who’s just been introduced to the idea of sync’ing our AD with our notes directory in order to allow users single sign on.

I’ve just finished reading through the redbook on this subject and I’m left thinking that adsync will only synchronise the two directorys if user accounts are created by either the domino administrator software or active directory users and computers. In our environment we’re considering using ADSI in order to create our active directory users. Am I correct in assuming that if an automated ADSI process is used to create our AD users then there is no way to sync the newly created accounts with the notes directory ? If this is true, what are the other options in terms of allowing our users single sign on to both systems ?

I’ve seen a few posts regarding IBM directory integrator, but I am unaware as to the cost of this product or even if the product would fulfill our needs.

Could someone please be kind to a ‘newb’ and give me some clues on this ?

Thanks in advance,

Gareth

Subject: Active directory synchronization with lotus adsync

I’m not sure I understood you totally but here you go.

we’re considering using ADSI in order to create our active directory users

So you create the AD user. Does the user already exist in Domino? If no, then use MMC to register the user into Domino. If yes, then use MMC to sync the user with Domino.

Even if you create the user outside of MMC or Domino, you still need to use MMC (adsync plug-in) to syncronize.