{"id":97084,"date":"2023-10-26T20:42:21","date_gmt":"2023-10-27T00:42:21","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=97084"},"modified":"2024-08-20T13:23:38","modified_gmt":"2024-08-20T17:23:38","slug":"configure-adi-two-way-sync","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/configure-adi-two-way-sync","title":{"rendered":"Configure ADI: Manage users, groups and passwords in AD, JumpCloud, or both"},"content":{"rendered":"\n

The JumpCloud Active Directory Integration (ADI) enables the syncing of users, groups, and passwords between JumpCloud and on-premise or off-premise AD. As covered in Get Started: Active Directory Integration<\/a>, the ADI uses two agents: an Import Agent and a Sync Agent that can be installed in three (3) configurations which are based on where you want to manage users, groups, and passwords:<\/p>\n\n\n\n

    \n
  1. Manage users, groups, and passwords in AD<\/li>\n\n\n\n
  2. Manage users, groups, and passwords in JumpCloud<\/li>\n\n\n\n
  3. Manage users and passwords in either system, or both<\/li>\n<\/ol>\n\n\n\n

    This article provides a step-by-step guide for configuring ADI to manage users, security groups, and passwords in AD, JumpCloud, or both<\/strong>. This configuration provides the greatest flexibility. It allows AD and JumpCloud to manage user credentials and attributes together in unison, a full two-way sync. Users are able to change passwords within either AD or JumpCloud. It also supports a hybrid approach where specific information is managed in one system and other information is managed in the other system. This configuration supports:<\/p>\n\n\n\n