How to Integrate Arcserve UDP 7.0 with Active Directory Using Active Directory Groups

The role-based administration of Arcserve UDP 7.0 allows user-level permission where the Active Directory (AD) feature is not enabled by default. However, the WSO2 Carbon platform in Arcserve UDP 7.0 does not support AD groups that have secondary user store. You can enable the extension for Arcserve UDP 7.0 that configures the AD groups as Arcserve UDP roles and helps assign the permissions automatically for the members in the AD group.

Follow these steps:

  1. Navigate to the following installation path of Arcserve UDP and open the carbon.xml file:
  2. …\Program Files\Arcserve\Unified Data Protection\Management\IdentityServer\repository\conf\carbon.xml
  3. From the carbon.xml file, disable the contents of HideMenuItemIds using <!-- and --> as displayed in the screenshot below.
  4. Save the carbon.xml file and restart the Arcserve UDP Management service.
  5. Open the user management console using the following link:
  6. https://localhost:8015/carbon
  7. The Arcserve UDP Role-based Access Control Administration Home page appears.
  8. Click the User Store Management option available on the left pane.
  9. The User Store Management page appears.
  10. Click Add Secondary User Store.
  11. The User Store Manager page appears.
  12. Select the required User Store Manager Class option from the drop-down list and enter your domain name in the Domain Name field.
  13. Enter the details in the fields as required under Define Properties For and Optional groups.
  14. The screenshot below is an example of the User Store Manager page after entering the details.
  15. Click Add.
  16. The UDP User Management dialog appears.
  17. Click OK.
  18. The User Store Management page appears and displays the added secondary user store.
  19. Note: If the secondary user store is not displayed, refresh the browser.
  20. (Optional) Click the Users and Roles option from the left pane to view the list of users and roles.
  21. Note: You need to define roles in the domain using AD.
  22. Now, perform the following steps to add the UDP role permissions:
    1. Select an AD user or AD group.
    2. Assign a role from the available list of roles.
    3. Click View Role.
    4. The Role List of User page appears.
    5. Click Permissions.
    6. The list of permissions appear.
    7. Select the Permissions as required.

Now, the secondary user can log into the Arcserve UDP Console with the assigned permissions.