Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Question about users backed sync: password sync?

Hello,

Currently, our user portal is configured with Active Directory and users (that are allowed to access user portal) are created automatically. Their email addresses and real name are also synced since we enabled backend sync.

However, I've to add an email manually for a use (SPAM management) and so I've to disabled backend sync option to do that. Indeed, if I let the option activated, the manually added email address is deleted.

Question is: what happen if user domain password is changed? Can I remove backend sync option and still have the password sync? We change our domain password every 6 months and so it has to be changed automatically in the Sophos through an AD backend sync.

I read help and saw this:

"Backend sync: Some basic settings of the user definition such as the real name or the user's email address can be updated automatically by synchronizing the data with external backend authentication servers (only available if you selected Remote as authentication method). Note that the option will automatically be set according to the Enable Backend Sync on Login option on the Authentication Services > Advanced tab, if the user is selected for prefetching.

Note – Currently, only data with Active Directory and eDirectory servers can be synchronized."

There is no mention about the user password sync with the "backend sync" option of each user object. Can you confirm this?

Kind Regards :)



This thread was automatically locked due to age.
  • Hello,

    Any idea about this issue?

    Kind Regards,

    DeltaSM

  • Salut,

    I thought that there was no sync of the password and that the UTM always checked AD for authentication.  I'm pretty certain that shutting down the AD server will result in no AD users being authenticated by the UTM.  Passwords are cached for five minutes (default), so you would have to leave the server off for at least that long to test.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?