Wait, what is Group Management Server?!
Group Management Server is Thycotic Software’s brand new self service Active Directory group management tool. IT Admins can designate Group Owners to control Active Directory Security Group and Distribution Group membership. Reporting and full audit trails are maintained throughout the system on group management activities including adding, deleting, editing user group membership. These audit trails can be used during security audits to demonstrate compliance.
Group Management Server can be installed quickly and does not require Active Directory Schema Extension. Even very large Active Directory environments can be quickly synchronized and managed from an easy-to-use and secure web interface. Implementing robust Role Based Access Control and an approvals workflow, Group Management Server can automate IT Admin functions to tighten security, minimize risk, and reduce labor costs associated with managing group membership.
Let’s get back to how Group Management Server scales for the enterprise…
One of the highlights in Group Management Server is the performance during Active Directory synchronization. Active Directory synchronization is a process in which Active Directory data (groups and users) are populated in Group Management Server. The synchronization process makes Active Directory group management tasks lightning fast, as opposed to waiting on the Active Directory Users and Computers application to slowly search for the correct group. In our testing, synchronization with 6 domains (one domain contained nearly 150,000 groups and 100,000 users) was completed in well under 5 minutes. See figures 1-3 below for before and after screenshots of Active Directory synchronization with Group Management Server.
In Figure 1, this Group Management Server instance manages groups in six domains. These domains range in size from small (250 objects) to large (100,000+ objects). Note that domain synchronization has been started at 11:34:08 AM (highlighted in red).
In Figure 2, synchronization has completed for all six domains at 11:38:55 AM. The elapsed time for the synchronization was
4 minutes and 47 seconds!
In Figure 3, domain statistics are displayed for synchronization. In less than 5 minutes, Group Management Server synchronized more than 160,000 Active Directory groups and nearly 100,000 user objects spread over six separate domains.
Setting up Active Directory synchronization with Group Management Server
To synchronize with Active Directory, log in as an Administrator for Group Management Server. Then click Administration -> Active Directory. Click on the New Domain button and fill out the fields with your specific domain information and click Save. Group Management Server will begin to synchronize with the newly added domain. As with test example above, synchronization will take a few minutes depending on the number of groups and other objects in your domain.