Synergy SIS and Synergy SE User Group Synchronization
Description:
Synergy SIS and Synergy SE have been modified to support both the creation of users and the assignment of user groups by using the Light Weight Directory Protocol (LDAP) and Microsoft Active Directory. These two integration types have been added to the System Configuration screen. They provide support for synchronizing user groups and/or the creation of user accounts as well as synchronizing of user groups and staff assignment to school sites.
Tasks
System Configuration Setup
Role Group Setup
The LDAP Name must be added to each Synergy SIS/Synergy SE User Group that will be synchronized between Synergy SIS/Synergy SE and Active Directory. The value entered into the LDAP Name must match the group name in Active Directory. Active Directory users in the group specified, in the LDAP Name property, will be added to this Synergy SIS/Synergy SE User Group. If the “Default Use Menu Group for a new user added to this group” is checked any menu groups defined in the Navigation Tree area of this group will be displayed for any users automatically created by the RT LDAP Monitor service.
In addition to Synergy SIS/Synergy SE User Group membership the school level staff assignments can be created using the User & Group synchronization.
Once a change is made to a user’s active directory group membership they will be reassigned accordingly inside Synergy SIS/Synergy SE. RT LDAP Monitor service will not process organizational site assignments above the school level. This prevents accidental assignment of staff to district level access by RT LDAP Monitor service.
Users created by RT LDAP Monitor and their User Group assignments should never be disabled or have their group assignments changed by an Admin level user using either User or User Group screens. This can lead to differences between Active Directory User or User group membership. This difference could lead to confusion and inappropriate access for users who were modified by hand.
NOTE:
Synergy SIS/Synergy SE User Groups should NOT have their organization tables changed after Allow LDAP monitoring to create staff school year entries has been enabled. Do not make manual changes to Organizations tables to existing groups as these changes will NOT change Staff Assignments for users. It will change users rights in Synergy SIS/Synergy SE. See Business Rules.
It is important to understand Business Rules that govern operation of RT LDAP Monitor application so that correct actions can be taken to maintain staff school assignments in Synergy SIS/Synergy SE.