Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell FluidFS NAS Solutions Administrator's Guide

Active Directory Configuration

FluidFS can join an Active Directory domain. This can be done using the NAS Manager, using Cluster Management > Authentication > System Identity , or the CLI. For more information on joining the Active Directory using the CLI, see the FluidFS Command Line Interface Guide at dell.com/support/manuals.

To join the FluidFS NAS appliance to the Active Directory domain, you must provide credentials for the join operation.
  • NOTE: The join operation is the only time these credentials are required. The credentials are not stored or cached by the FluidFS NAS appliance.
The administrator has three options when determining the credentials that are used to join the FluidFS NAS appliance to the Active Directory:
  • Join the NAS cluster using a Domain Admin account.
    • NOTE: This is the recommended method.
  • Join the NAS cluster to the Active Directory domain, using an account that has been delegated the join a computer to the domain privilege, as well as being delegated full control over all computer objects in the domain.
  • If a Domain Admin account, or an account with full control over all computer objects in the domain, is not available for use, the minimum requirement to join the NAS appliance to the Active Directory domain is:
    • An Organizational Unit (OU) admin that is delegated to join a computer to the domain privilege.
    • The OU admin must also be delegated full control over objects within that OU, including computer objects.
    • Before joining the system to the domain, a computer object must be created by the OU admin for the system; in the OU privileges to administer are provided.
    • The NAS appliance computer object name, and the NetBIOS name used when joining it, must match.
    • When creating the NAS appliance computer object, in the User or Group field under permissions to join it to the domain, select the OU admin account. Then the NAS appliance can be joined using the OU admin credentials.
  • NOTE: FluidFS NAS clusters need read access for the tokenGroups attribute for all users. The default configuration of Active Directory for all domain computers is to allow read access to the tokenGroups attribute. If the permission is not given, Active Directory domain users that are in nested groups or OU’s encounter Access Denied errors, Users that are not in nested OU’s or groups, are permitted access.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\