Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

Domain Admin Service Account Required for ADSI Connector?

lewisa12
New Contributor
New Contributor

Hello,

As we're attempting to get a successful connection for an  ADSI connector and we're running into error.  Leadership has been reluctant to provide the Service Account we're using Domain Admin privileges in AD. 

The errors we're getting state "User does not have access to create group" and "User does not have access to manage group". The current service account we're using doesn't have access to administrate groups in a handful of OUs (as we're attempting "least privilege"), other then that it has full create, manage, move, and delete permissions throughout the forest.

lewisa12_1-1708568805271.png

Link to "Preparing for ADSI Integration" guide below. It mentions that Domain Admin is required, then goes on to say that "Least Privilege" can be applied. 

https://docs.saviyntcloud.com/bundle/ADSI-v2021x/page/Content/Preparing-for-Integration.htm#Preparin

lewisa12_0-1708568470733.png

Can anyone help clarify what it needed for the Service Account permissions for ADSI?

Thank you!
Adam

7 REPLIES 7

rushikeshvartak
All-Star
All-Star

Below permissions are required for the Import/Provisioning operations:

Import:

-Directory Replication permission 

Provisioning:

-Read
-Write

Create/Delete child object provisioning:

-Create all child objects
-Delete all child objects

Move operation:

-Migrate SID history

 

Refer

https://forums.saviynt.com/t5/identity-governance/service-account-for-adsi-connector-minimum-privile...

https://forums.saviynt.com/t5/identity-governance/connection-issue-for-adsi-connector-type-for-ad-in...


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

Thank you, Rushikesh,

What privileges are required for installation?

Best,
Adam

installation of ?


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

For clarity this is the error we're getting during the initial "save and test" on the connection. 

lewisa12_1-1708710076991.png

lewisa12_0-1708709995877.png

 

Above are saviynt features access. Does logged in users have ROLE_ADMIN or sav role with feature added for ADSI ?


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.

lewisa12
New Contributor
New Contributor

Yes, user has SAV_ADMIN role.

Add below features in custom Sav roles

 

rushikeshvartak_0-1709003971352.png

 

 


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.