Document toolboxDocument toolbox

Microsoft Active Directory

Before creating a third-party DNS provider in the Infoblox Portal, you must deploy a NIOS-X Server and associate the Microsoft Active Directory (AD) Sync service with it.

If the Microsoft AD DNS and IPAM objects are more than 100k each, the best practice is to configure sync operation on two hosts: one for DNS, and one for IPAM. For information about creating hosts, see Creating NIOS-X Servers.

To create a new third-party provider for Microsoft AD, do the following:

  1. Go to Configure > Networking > DNS > Third-party DNS Providers.

  2. Click Create > Microsoft Active Directory.

  3. Configure the following options on the Create Third-party DNS Provider screen:

    • Name: Create a name.

    • Description: Create a description.

    • Credentials: Choose the credentials. Alternatively, click Create New Credentials and configure the following:

      • Name: Create a name.

      • Description: Create a description. Click Next.

      • Configure the following settings on the Microsoft Active Directory Credentials screen:

        • Domain\User Name: Specify the domain name and the user name for the AD server.

        • Password: Specify the password for the AD server.

      • Click Next.

      • Review the configuration settings, and click Save.

    • Active Directory Server: Specify the IP address or FQDN. If you are using the FQDN as the value, make sure the BloxOne NIOS-X Server can resolve it.

    • Service Instance: Choose the Microsoft AD Sync service’s instance you want to associate with the third-party DNS provider.

    • Sync Interval (min): Specify the sync interval, in minutes. The default value is 180 minutes. If you have a large amount of data, we recommend setting the sync interval to a value between 180 and 1440 minutes (inclusive).

  4. Click Next.

  5. Review the configuration, and click Save & Close.

We recommend the following settings for the sync interval:

  • 3 hours if you have less than 100k objects of Microsoft AD to sync.

  • 6 hours if you have less than 500k objects of Microsoft AD to sync.

  • 24 hours if you have more than one million objects of Microsoft AD to sync.

The new destination’s DNS View is created automatically. When a third-party DNS provider is deleted, the view and all objects associated with it are unassigned. You must delete the view manually.