You can map any combination of users and groups from an Active Directory service to a Portfolio catalog. Once you save a mapping, you can edit it to add more users or groups, remove users or groups, or exclude specific users from a catalog.
To edit your directory service mappings, click Directory Services on the left, then click Mappings at the top of the Directory Services panel.
The Portfolio Mappings dialog consists of two parts: the Service Browser on the left, which lists users and groups, and the Mappings on the right, which lists the users mapped to a catalog.
In the service browser, you query the directory service for existing users and groups.
The AD Users and Groups list shows the users and groups that match the query criteria.
Use the query Filter to restrict the listing to certain users or groups within the directory service.
The available filters are:
Security Groups: Displays all security groups within the directory service.
Distribution Groups: Displays all distribution groups within the directory service.
Users: This filter displays all the directory service users in a flat (non-hierarchical) list.
Entire Tree: Displays the highest level of the directory service tree. Use this if you want to browse to a specific entry manually.
Name: Use this filter to locate users by name. This filter includes the options to search if a name equals, contains, or starts with the entered text.
Directory service mapping is a simple, flexible, and powerful way to give users on your network access to Portfolio catalogs. It is important to understand how account mapping works, in order to maintain a secure and steady workflow for your Portfolio users.
To create a directory service mapping:
Choose the catalog to map to from the Catalog pop-up menu in the Mapping panel on the right.
If you have created a mapping for that catalog already, it will be displayed, and you can proceed to modify it.
There are three types of mapping targets that you can choose from:
Specific catalog: This is ideal for complex user and group mappings
All Catalogs: Useful if you need to map users to many catalogs.
None: This allows you to import directory service users, automatically creating Portfolio accounts for them, which you can manually assign to catalogs.
Select entries in the service browser on the left.
You can select any combination of users and groups
.
Click Create Mapping at the bottom of the service browser.
To exclude individual users from a mapping, select the users in the service browser, then click Exclude User.
You can choose a specific role for each user from the drop-down menu next to the user’s entry in the Mapping panel.
Click Save and Sync. This will cause Portfolio to synchronize to the directory service, and add the specified users to the selected catalog.
The major benefit of mapping a group instead of the individual members in that group is that all future members added to that group will become members of the same catalog, and their network logins will immediately work to give them access to the catalog.
Click Exclude User to deny catalog access to individual users, even if they are part of a group that has access.
You can edit a mapping that you saved; click Directory Services, click Mappings, then choose the desired catalog from the Catalog pop-up menu in the right-hand panel.
You can use the service browser to filter users and groups at any time while editing your map.
To remove a user or group from an existing mapping, choose the user or group name in the right-hand panel, then click Remove Mapping.
To add new users or groups to a mapping, select one or more users or groups (or both) in the service browser on the left, then click Create Mapping .
To exclude a user from accessing a Portfolio catalog, select the user in the service browser and click Exclude User. The user will be added to the mapping with this icon to indicate that user is specifically excluded regardless of group membership.
To cancel any changes without saving them, click Revert Changes.
To save your mapping changes, click Save and Sync.
You can use a directory service mapping to create user accounts, and then later assign those accounts to catalogs.
Bind Portfolio to your directory service. See Configuring Active Directory.
Click Mappings.
Choose one or more groups or users.
Choose None from the Catalog pop-up menu on the right.
Click Create Mapping.
Repeat steps 3–5 as necessary, then click Save and Sync.