Create or Identify Accounts for Synchronization (Optional)

The Keyfactor Windows EnrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). Gateway provides the option to synchronize Active Directory user and group accounts from the local forestClosed An Active Directory forest (AD forest) is the top most logical container in an Active Directory configuration that contains domains, and objects such as users and computers. to the managed forest. When you configure this option, shadow accounts are created in the managed forest for each user and group configured for synchronization (including users within these groups). These shadow accounts can be used to grant access to resources in the managed forest. They are often used in conjunction with federated single sign-on to provide SSO to the hosted instance of Keyfactor Command.

Note:  Account synchronization is not supported if OAuth is used as the authentication option to connect to the managed instance of Keyfactor Command.
Important:  The passwords for the accounts are not replicated to the managed forest.

There are three configuration options related to account synchronization:

Important:  The account synchronization function requires installation of the Active Directory module for Windows PowerShell, one of the options within the Remote Server Administration Tools Windows feature (see Add Remote Server Administration Tools).