在 SharePoint Server 中使用 SharePoint Active Directory 匯入設定設定檔同步處理Configure profile synchronization by using SharePoint Active Directory Import in SharePoint Server

摘要:了解如何使用匯入使用者設定檔從 Active Directory to SharePoint Server 2013 與 SharePoint Server 2016 Active Directory 匯入工具為使用者設定檔。Summary: Learn how to import user profiles from Active Directory to SharePoint Server 2013 and SharePoint Server 2016 by using the Active Directory import tool for user profiles.

您可以使用 SharePoint Active Directory 匯入] 選項 ([AD 匯入) 另一個到使用 Microsoft Identity Manager (MIM) 匯入使用者設定檔資料從 Active Directory 網域服務 (AD DS) 網域中。You can use the SharePoint Active Directory import option (AD import) as an alternative to using Microsoft Identity Manager (MIM) to import user profile data from Active Directory Domain Services (AD DS) in your domain.

使用 AD 匯入的匯入作業會比相同的作業使用 MIM 大幅更快速。不過,AD 匯入只能與 Active Directory 網域服務 (AD DS),無法與其他目錄服務搭配使用。此外,如果您選擇使用 AD 匯入、 MIM 或其他外部身分識別管理員都不可供如商務應用程式的其他資料來源的連線。Import operations that use AD import are significantly faster than the same operations that use MIM. However, AD import only works with Active Directory Domain Services (AD DS) and does not work with other directory services. Additionally, if you choose to use AD Import, MIM or other external identity managers are not available for connections to other data sources such as business applications.

您必須是伺服器陣列管理員群組的成員才能執行本文中的程序。您也需要網域認證才能設定連線同步處理權限。You must be a member of the Farm Administrators group to perform the procedures in this article. You also need domain credentials with synchronization permissions in order to configure the connection.

注意

MIM 是唯一可用的 SharePoint Server 2016 外部提供者。MIM is an external provider only available in SharePoint Server 2016.

不支援 AD 匯入的情況Situations unsupported by AD import

請考慮下列情況下,然後記下新 AD 匯入選項時,不支援您決定是否要使用此選項:Consider the following situations and note what the AD import option does not support when you determine whether to use this option:

  • AD 匯入選項不會執行雙向同步處理,這表示,對 SharePoint 使用者設定檔進行的變更不會同步處理回網域控制站。The AD import option does not perform bidirectional synchronization. That means changes made to SharePoint user profiles will not be synchronized back to the domain controller.

  • 只會維護單一 Active Directory 樹系內使用者及群組之間的參考完整性。Referential integrity among users and groups is only maintained within a single Active Directory forest.

  • AD 匯入選項可讓您只設定和使用單一的全伺服器陣列屬性對應。The AD import option lets you configure and use only a single, farm-wide property mapping.

  • AD 匯入選項不會不會自動同步處理至 SharePoint Server 2016 從 Active Directory 相片。The AD import option does not automatically synchronize photos from Active Directory to SharePoint Server 2016.

  • AD 匯入選項不支援泛型 (非 AD) LDAP 來源。The AD import option does not support generic (non-AD) LDAP sources.

  • AD 匯入選項不支援來源結構描述探索。The AD import option does not support Source Schema Discovery.

  • AD 匯入選項不例如支援多樹系案例:The AD import option does not support multi-Forest scenarios such as:

    • 如果您有兩個樹系之間的信任,將不匯入信任的樹系物件。If you have a trust between two forests, the trusted forest objects will not be imported.

    • 如果您需要將使用者匯入從多個網域,您必須建立多個同步處理連線。如果您有多個網域管理、 使用 MIM。If you need to import users from multiple domains, you must create multiple synchronization connections. If you have multiple domains to manage, using MIM.

  • AD 匯入選項不支援 Contact objects (也稱為跨物件指標)。The AD import option does not support Contact objects (also known as cross-object pointers).

  • AD 匯入選項不支援 click 使用者和群組的自訂物件類別。The AD import option does not support custom object classes besides User and Group.

  • AD 匯入選項不篩選使用者介面來建立複雜布林值的運算式。The AD import option does not filter user interface to create complex Boolean expressions.

  • AD 匯入選項不提供物件篩選根據物件屬性值 (您必須使用簡單的 LDAP 篩選)。The AD import option does not provide object filtering based on object property values (you must use simple LDAP filters).

  • 登入與資源樹系 AD 匯入選項不提供支援。也就是自訂聯結的多個來源的資料。The AD import option does not provide Logon and Resource Forest support. That is, custom joins of data from multiple sources.

  • AD 匯入選項不支援 Business Connectivity Services 匯入。The AD import option does not support Business Connectivity Services Import.

  • AD 匯入選項不支援的複雜類型類似的圖片和特殊 AD 類型的屬性對應。The AD import option does not support property mappings for complex types like pictures and special AD types.

  • AD 匯入選項不支援將資料從 SharePoint 匯出至目錄來源。The AD import option does not support exporting data from SharePoint to Directory Sources.

  • AD 匯入選項不支援升級/平移 FIM 基礎連線] 或 [同步處理設定 AD 匯入 (或相反順序)。The AD import option does not support Upgrading/Translating FIM based connections or synchronizing configuration to AD import (or in reverse order).

  • AD 匯入選項無法確保單一主圖形的每個物件屬性 (目前,最後一個作者 wins)。The AD import option does not ensure single-master of each object property (currently, the last writer wins).

  • AD 匯入選項不會執行每個租用戶屬性對應。The AD import option does not perform per-tenant property mapping.

設定 SharePoint Active Directory 匯入Set up SharePoint Active Directory Import

在管理中心即可設定 AD 匯入執行三個程序。You perform three procedures in Central Administration to configure AD import.

在第一個程序,您可以設定而不是例如 MIM 外部身分識別管理員使用 AD 匯入 SharePoint 伺服器。In the first procedure, you configure SharePoint Server to use AD Import instead of an external identity manager such as MIM.

在第二個程序,您可以建立 AD DS 的同步處理連線。連接會識別要同步處理的項目及包含可用來與 AD DS 互動的認證。In the second procedure, you create a synchronization connection to AD DS. The connection identifies the items to synchronize and contains the credentials that are used to interact with AD DS.

在第三個程序中,可決定如何在 SharePoint Server 中的使用者設定檔屬性對應至擷取從 AD DS 的使用者資訊。In the third procedure, you determine how the properties of user profiles in SharePoint Server map to the user information that is retrieved from AD DS.

若要設定要使用 AD 匯入 SharePoint ServerTo configure SharePoint Server to use AD Import

  1. 在SharePoint 管理中心網站上,按一下 [應用程式管理] 區段中的 [管理服務應用程式]。On the SharePoint Central Administration website, in the Application Management section, click Manage service applications.

  2. 在 [管理服務應用程式] 頁面上按一下 [User Profile service 應用程式的連結。On the Manage Service Applications page, click the link of the User Profile service application.

  3. 在 [管理設定檔服務] 頁面上的 [同步處理] 區段中按一下 [設定同步處理設定On the Manage Profile Service page, in the Synchronization section, click Configure Synchronization Settings.

  4. 在 [設定同步處理設定] 頁面上的 [同步處理選項] 區段中選取 [使用 SharePoint Active Directory 匯入] 選項,然後再按一下 [確定]On the Configure Synchronization Settings page, in the Synchronization Options section, select the Use SharePoint Active Directory Import option, and then click OK.

若要匯入設定檔,您必須至少一個同步處理連線到 AD DS。您可能需要 AD DS 的多部伺服器的連線。使用下列程序,建立每個您要匯入設定檔的 AD DS 伺服器的同步處理連線。您可以同步處理之後建立每個連線,或在您建立的所有連線之後的一次進行同步處理。雖然同步處理每個連接花費的時間之後,但這麼容易疑難排解任何可能遇到的問題。To import profiles, you must have at least one synchronization connection to AD DS. You may have connections to multiple AD DS servers. Using the following procedure, create a synchronization connection to each AD DS server from which you want to import profiles. You can synchronize after you create each connection, or you can synchronize one time, after you have created all of the connections. Although synchronizing after each connection takes longer, doing this makes it easier to troubleshoot any problems that you might encounter.

若要建立目錄服務匯入連線To create a connection to a directory service for import

  1. 在SharePoint 管理中心網站上,按一下 [應用程式管理] 區段中的 [管理服務應用程式]。On the SharePoint Central Administration website, in the Application Management section, click Manage service applications.

  2. 在 [管理服務應用程式] 頁面上按一下 [User Profile service 應用程式的連結。On the Manage Service Applications page, click the link of the User Profile service application.

  3. 按一下 [管理設定檔服務] 頁面上的 [同步處理] 區段中的 [設定同步處理連線]。On the Manage Profile Service page, in the Synchronization section, click Configure Synchronization Connections.

  4. 在「同步處理連線」頁面上,按一下 [建立新連線]。On the Synchronizations Connections page, click Create New Connection.

  5. 在「新增同步處理連線」頁面的 [連線名稱] 方塊中,輸入同步處理連線名稱。On the Add new synchronization connection page, type the synchronization connection name in the Connection Name box.

  6. 從 [類型] 清單中,選取 [ Active Directory 匯入From the Type list, select Active Directory Import.

  7. 完成下列步驟以填入 [連線設定] 區段中:Fill in the Connection Settings section by completing the following steps:

  8. 在 [完整網域名稱] 方塊中輸入網域的完整網域名稱。In the Fully Qualified Domain Name box, type the fully-qualified domain name of the domain.

  9. 在 [驗證提供者類型] 方塊中,選取驗證提供者的類型。In the Authentication Provider Type box, select the type of authentication provider.

  10. 如果選取 [表單驗證] 或 [信任的宣告提供者驗證],請從 [驗證提供者執行個體] 方塊中選取驗證提供者。If you select Forms Authentication or Trusted Claims Provider Authentication, select an authentication provider from the Authentication Provider Instance box.

    [驗證提供者執行個體] 方塊只會列出 Web 應用程式目前使用的驗證提供者。The Authentication Provider Instance box lists only the authentication providers that are currently used by a web application.

  11. 在 [帳戶名稱] 方塊中輸入您想要 AD 匯入工具用來執行同步處理帳戶的名稱。使用表單_<網域>\ <UserName>。同步處理帳戶必須具備複寫目錄權限或更高層根 AD DS 的 OU。In the Account name box, type the name of the account you want the AD import tool to use to perform the synchronization. Use the form <DOMAIN>\ <UserName>_. The synchronization account must have Replicate Directory permissions or higher on the root OU of AD DS.

  12. 在 [密碼] 和 [確認密碼] 方塊中,輸入帳戶的密碼。In the Password and Confirm password boxes, type the password for the account.

  13. 在 [連接埠] 方塊中輸入您想要 AD 匯入工具用來連線到 AD DS 時便會執行同步處理連線連接埠。In the Port box, type the connection port you want the AD import tool to use to connect to AD DS when it performs the synchronization.

  14. 如果目錄服務的連線需要使用 Secure Sockets Layer (SSL) 連線,請選取 [使用 SSL 安全連線]。If a Secure Sockets Layer (SSL) connection is required to connect to the directory service, select Use SSL-secured connection.

    重要

    如果您使用 SSL 連線時,您必須從 AD DS 伺服器匯出網域控制站的憑證與憑證匯入同步處理伺服器。If you use an SSL connection, you must export the certificate of the domain controller from the AD DS server and import the certificate into the synchronization server.

  15. 如果您想要篩選出已停用在 AD DS 中的使用者,選取 [篩選出已停用使用者] 核取方塊。If you want to filter out users that are disabled in AD DS, select the Filter out disabled users check box.

  16. 如果您要篩選您從目錄服務匯入的物件中的 Active Directory 匯入的 LDAP 語法的篩選條件] 方塊中輸入標準的 LDAP 查詢運算式來定義篩選器。If you want to filter the objects that you import from the directory service, in the Filter in LDAP syntax for Active Directory Import box, type a standard LDAP query expression to define the filter.

  17. [容器] 區段中按一下 [填入容器] 中,然後再從您要同步處理的目錄服務中選取容器。所有組織單位 (Ou) 您所選取將與及其子 Ou 同步處理。目前有任何公用程式,可讓您選取父系 OU 及其任何子 Ou 排除從同步處理時。In the Containers section, click Populate Containers, and then select the containers from the directory service that you want to synchronize. All organizational units (OUs) that you select will be synchronized with their child OUs. There is currently no utility that allows you to select a parent OU while excluding any of its child OUs from synchronization.

  18. 按一下 [ OK ]。Click OK.

    同步處理連線] 頁面會列出新建立的連線。The newly created connection is listed on the Synchronization Connections page.

    提示

    在 [同步處理連線] 頁面上您可以按一下 [同步處理連線名稱,和 [編輯刪除來編輯或刪除連線。On the Synchronization Connections page, you can click the name of a synchronization connection, and then click Edit or Delete to edit or delete the connection.

    若要將使用者設定檔屬性對應To map user profile properties

  19. 在SharePoint 管理中心網站上,按一下 [應用程式管理] 區段中的 [管理服務應用程式]。On the SharePoint Central Administration website, in the Application Management section, click Manage service applications.

  20. 在 [管理服務應用程式] 頁面上按一下 [User Profile service 應用程式的連結。On the Manage Service Applications page, click link for the User Profile service application.

  21. 按一下 [管理設定檔服務] 頁面上的 [人員] 區段中的 [管理使用者屬性]。On the Manage Profile Service page, in the People section, click Manage User Properties.

  22. 在 [管理使用者屬性] 頁面上,按一下您想要對應至目錄服務屬性、 屬性的名稱和 [編輯On the Manage User Properties page, click the name of the property that you want to map to a directory service attribute, and then click Edit.

  23. 若要移除現有對應,請在 [同步處理屬性對應] 區段中,選取您要移除的對應,然後按一下 [移除]。To remove an existing mapping, in the Property Mapping for Synchronization section, select the mapping that you want to remove, and then click Remove.

  24. 若要新增對應,請執行下列動作:To add a new mapping, do the following:

  25. 在 [新增對應] 區段的 [來源資料連線] 清單中,選取代表您要將使用者設定檔屬性對應的目錄服務的資料連線。In the Add New Mapping section, in the Source Data Connection list, select the data connection that represents the directory service to which you want to map the user profile property.

  26. 在 [屬性] 方塊中輸入您要對應屬性的目錄服務屬性的名稱。In the Attribute box, type the name of the directory service attribute to which you want to map the property.

  27. 按一下 [新增]。Click Add.

    注意

    您無法新增多個對應或編輯對應。若要變更屬性的對應設定,您必須先移除現有對應,然後再新增對應。You cannot add multiple mappings or edit a mapping. To change mapping settings for a property, you must first remove the existing mapping, and then create a new mapping.

  28. 按一下 [確定]。Click OK.

  29. 重複步驟 4 到 7,以對應其他屬性。Repeat steps 4 through 7 to map additional properties.

    若要啟動設定檔同步處理To start profile synchronization

  30. 在SharePoint 管理中心網站上,按一下 [應用程式管理] 區段中的 [管理服務應用程式]。On the SharePoint Central Administration website, in the Application Management section, click Manage service applications.

  31. 在 [管理服務應用程式] 頁面上按一下 [User Profile service 應用程式的連結。On the Manage Service Applications page, click the link for the User Profile service application.

  32. 按一下 [管理設定檔服務] 頁面上的 [同步處理] 區段中的 [啟動設定檔同步處理]。On the Manage Profile Service page, in the Synchronization section, click Start Profile Synchronization.

  33. 在 [啟動設定檔同步處理] 頁面上選取 [啟動完整同步處理如果這是第一次同步處理或如果您已新增或修改任何同步處理連線自上次同步。選取 [啟動累加同步處理同步處理上次同步後已變更的資訊。On the Start Profile Synchronization page, select Start Full Synchronization if this is the first time that you are synchronizing or if you have added or modified any synchronization connections since the last time that you synchronized. Select Start Incremental Synchronization to synchronize only information that has changed since the last time that you synchronized.

  34. 按一下 [ OK ]。Click OK.

    會顯示 [管理設定檔服務] 頁面上,在右窗格中顯示的設定檔同步處理狀態。The Manage Profile Service page is displayed, showing the profile synchronization status in the right pane.

另請參閱See also

概念Concepts

管理 SharePoint Server 中的使用者設定檔同步處理Manage user profile synchronization in SharePoint Server

規劃 SharePoint Server 2013 Preview 的設定檔同步處理Plan profile synchronization for SharePoint Server 2013

同步處理 SharePoint Server 2013 中的使用者與群組設定檔Synchronize user and group profiles in SharePoint Server 2013

在 SharePoint Server 中排程設定檔同步處理Schedule profile synchronization in SharePoint Server

其他資源Other Resources

Update-spprofilephotostoreUpdate-SPProfilePhotoStore