---
title: "Synchronizing User Groups"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35397703/Synchronizing%20User%20Groups"
format: markdown
---
<span style="color: #000000">When you configure and enable an authentication profile, you can use it to retrieve user group information through the third-party IdP in the profile. For security reasons, the system will delete the user group data after the expiry time. You must define how long you want the system to keep the user group information by setting the expiration window. The default is 48 hours.</span>


> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">Although user group information expires based on your configuration, this information is stored in the system once you have associated the respective user groups with a security policy. However, the user group information will be deleted when you remove the respective security policy. In addition, if the IdP in your authentication profile renames a user group or deletes one, you must resynchronize the user groups to get the latest information.</span>

<span style="color: #000000">To retrieve user group information from an IdP, complete the following on the </span>*<span style="color: #000000">User Group Sync</span>*<span style="color: #000000"> tab:</span>

**<span style="color: #000000">Authentication Profile</span>**<span style="color: #000000">: Choose an enabled authentication profile you want to use to retrieve user groups. </span>**<span style="color: #000000">Only enabled profiles are available for selection</span>**<span style="color: #000000">. </span>

<span style="color: #000000">For information about how to create authentication profiles, see </span>[*<span style="color: #000000">Configuring Authentication Profiles</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35462918)<span style="color: #000000">.</span>

<span style="color: #000000">For LDAP profiles (for MS AD Sync), complete the following:</span>

- **<span style="color: #000000">User Name</span>**<span style="color: #000000">: Enter the username for logging in to the Microsoft Active Directory server.</span>
- **<span style="color: #000000">Password</span>**<span style="color: #000000">: </span><span style="color: #000000">Enter the password for logging in to the Microsoft Active Directory server.</span>
- **<span style="color: #000000">On-prem Host</span>**<span style="color: #000000">: Choose the host with which you have associated the LDAP profile from the list</span>
- **<span style="color: #000000">Expiration</span>**<span style="color: #000000">: Choose the time duration you want the system to keep the user group information. The default is 48 hours.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">Ensure that you enable the </span>**<span style="color: #000000">MS AD Sync</span>**<span style="color: #000000"> service for the synchronization to work. For information, see </span>[*<span style="color: #000000">Enabling and Disabling Services on Servers</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneInfrastructure/pages/184648009)<span style="color: #000000">.</span>

> ℹ️ **Advisory**
> ℹ️ 
> ℹ️ **<span style="color: #172B4D">SSL related error while trying to sync the groups</span>**<span style="color: #172B4D">** **</span>  
> ℹ️ <span style="color: #000000">If you receive the following message: '</span><span style="color: #172B4D">Error status “LDAP Result Code 52 \"Unavailable' it is an indication that </span><span style="color: #172B4D">the login has failed due to the user directory is unavailable for authenticating the user. </span><span style="color: #172B4D">Configuring LDAP over SSL in the Server should resolve the issue. In MS AD  "Active Directory Certificate Services" must be installed in order to have CA installed. If that is not done, SSL related errors may be encountered when attempting to sync the groups. </span>
> ℹ️ 
> ℹ️ <span style="color: #172B4D">Do keep in mind that connectivity between the AD server and Infoblox Platform encrypts the communication channel using SSL/TLS protocol depending upon what’s supported by the server/client. </span><span style="color: #172B4D">It is a requirement that AD Server should have at least SSL protocol enabled and a self-signed certificate applied.</span>
> ℹ️ 
> ℹ️ <span style="color: #172B4D">To remedy this issue, the following checks to the server should be performed: </span>
> ℹ️ 
> ℹ️ - <span style="color: #172B4D">Check if the AD Server has at least SSL protocol enabled and a self-signed certificate applied and is valid.</span>
> ℹ️ - To verify if SSL is enabled or not, please check the value for:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Client\DisabledbyDefault (1 is enabled and 0 is disabled)
> ℹ️ - <span style="color: #172B4D">Please note that SSL and TLS are just sets of protocols but you will still require a certificate to digitally bind a cryptographic key.</span>
> ℹ️ 
> ℹ️ <span style="color: #172B4D">For information on </span><span style="color: #172B4D">how to enable Transport Layer Security (TLS) protocol, see </span>*[<span style="color: #172B4D">Configuring DNS Forwarding Proxy</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneInfrastructure/pages/166134245/Configuring+DNS+Forwarding+Proxy+Settings)*<span style="color: #172B4D">.</span>


<span style="color: #000000">For SAML profiles, complete the following:</span>

- **<span style="color: #000000">Admin Token</span>**<span style="color: #000000">: This is the authorization token from the IdP. Depending on the IdP you have selected in the authentication profile, refer to the respective vendor documentation on how to acquire an admin or API token.</span>
- **<span style="color: #000000">Expiration</span>**<span style="color: #000000">: Choose the time duration you want the system to keep the user group information. The default is 48 hours.</span>

<span style="color: #000000">For SAML profiles, complete the following:</span>

- **<span style="color: #000000">Admin Token</span>**<span style="color: #000000">: This is the authorization token from the IdP. Depending on the IdP you have selected in the authentication profile, refer to the respective vendor documentation on how to acquire an admin or API token.</span>
- **<span style="color: #000000">IdP Domain</span>**<span style="color: #000000">: This is the IdP domain for the IdP you set up.</span>
- **<span style="color: #000000">Expiration</span>**<span style="color: #000000">: Choose the time duration you want the system to keep the user group information. The default is 48 hours.</span>

<span style="color: #000000">Click </span>**<span style="color: #000000">Sync</span>**<span style="color: #000000">. When the synchronization is complete, available user groups are displayed in the </span>*<span style="color: #000000">Synced User Groups</span>*<span style="color: #000000"> panel. </span>

<span style="color: #000000">The synchronized user groups are now available when you configure security policies. For information about security policies, see </span>[*<span style="color: #000000">Configuring Security Policies</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35371559)<span style="color: #000000">.</span>

<span style="color: #000000">The </span>*<span style="color: #000000">Synced User Groups</span>*<span style="color: #000000"> panel displays the following information:</span>

- **<span style="color: #000000">User Group</span>**<span style="color: #000000">: The name of the user group.</span>
- **<span style="color: #000000">Profile</span>**<span style="color: #000000">: The name of the authentication profile used to retrieve the user group.</span>
- **<span style="color: #000000">Identity Provider</span>**<span style="color: #000000">: The IdP used to retrieve the user group information.</span>
- **<span style="color: #000000">Expires At</span>**<span style="color: #000000">: The date and time when the user group information expires.</span>

<span style="color: #000000">For more information about access authentication, see the following:</span>

- [*<span style="color: #000000">Managing Access Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35396331)
- [*<span style="color: #000000">Configuring Authentication Profiles</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35462918)
- [*<span style="color: #000000">Configuring Authentication Settings</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463149)