AssetWise Implementation Guide

Synchronizing a Community with Active Directory

In order for anyone to be able to log in to a community, they must have a person created for them in the community, and that person must have a user account. This user account can be an AssetWise account, a Windows account, or a Bentley account.

If you need to create a person manually, or if you need to add or edit a person's user account information (such as give them an AssetWise account, or change their Windows or Bentley account), use AssetWise Director. To configure the automatic creation of one or more persons with Windows or Bentley accounts, use AssetWise System Management Console.

See the AssetWise Director help for information about creating persons through AssetWise Director. The rest of this section discusses how to use AssetWise System Management Console to synchronize a community with Active Directory in order to automatically create persons in the community with Windows accounts.

In AssetWise System Management Console there is an Active Directory node within each community. This is where you configure synchronization settings for that community. After you configure these settings, then you synchronize the community with Active Directory. A synchronization can be configured to automatically:

  • create a new person with a Windows account in the community, if an Active Directory user is allowed access to the community and does not already exist in the community
  • disable or delete an AssetWise account in the community, if the corresponding Active Directory user is either disabled, or enabled but no longer allowed to access the community
  • enable an AssetWise account in the community, if the corresponding Active Directory user was disabled, but then later found to be enabled at the time of synchronization

A synchronization can also be configured to do nothing, if any of the above situations are encountered.

Separate from the synchronization process, you can also configure AssetWise to automatically create a new person in the community whenever a Windows user who is allowed to access the community attempts to log in to that community using their Windows credentials. The new AssetWise person's details and user account information are automatically populated with the corresponding account information in Active Directory (except for the user's Windows password which is never stored in AssetWise).

Note: Synchronization is only used to create, enable, disable, or delete AssetWise accounts. It does not synchronize the attributes of existing AssetWise persons with those of their Active Directory counterparts, if those attributes happen to change in Active Directory.