Setup
...
Maintenance
How to Change the DC that AD Compliance uses
3 min
background security group compliance manager requires a default domain controller (dc) to communicate with when it is first initialized this is necessary because the dirsync component that is used by activate to obtain all ad changes requires that the same dc be used for each query it is sometimes necessary to change the dc that is being used this document outlines the process for doing this process this process requires a complete resync of the active directory domain into activate and therefore should be complete after hours when activate is not in use depending upon the size of the domain the process may take a few minutes to a few hours 1\ stop the activate orchestrator this is required to stop activate polling active directory during the resync process 2\ ensure that all pending active directory compliance changes have been processed a open activate studio b goto //resources/activedirectory c right click and select connector tasks >show data d process or commit all pending changes 3\ change the domain controller a select the appropriate sub domain under //resources/activedirectory b change the connector adserver parameter to the fully qualified domain name of the new dc note this must be a fixed dc and cannot be a dns alias c delete the connector dirsynccookie this is very important as this cookie is specific the dc above which has not changed 4\ resync the domain note this may take a few minutes to a few hours depending upon the size of the domain this process will reimport all ad objects and regenerate a new connector dirsynccookie this process must be run as a domain administrator as this process requires dirsync rights ideally this process should be run as the activate service account a right click on //resources/activedirectory and select connector tasks >run workflow >import workflow b wait for the resync to complete 5\ check results a open activate studio b go to //resourecs/activedirectory c right click and select connector tasks >show data d check that the pending changes are ok if so leave them to process or commit them so they are not processed 6\ restart activate job service the normal polling and synchonization process can now continue