Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Managing domain users using Organization Unit group for Active Directory Synchronization (AD Sync) in Endpoint Encryption

    • Updated:
    • 13 Mar 2020
    • Product/Version:
    • Platform:
    • N/A N/A
This article provides the steps on how to manage domain users using the Organization Unit group for Active Directory Synchronization (AD Sync). 
  1. Create two new Organizational Unit groups [1] in AD as shown below. In this example, two groups, QAGroup1 and QAGroup2, are created.

    Create two new Organizational Unit groups

  2. Get the distinguished name using ADSI Edit in AD then copy the name to group the policy:

    1. Click the group node under default naming context.
    2. Right-click and select Properties.
    3. Click the Attribute Editor tab and find the <distinguishedName> attribute.
    4. Copy the distinguished name to the group policy.

      You can get two similar distinguished names like the following:


      Copy the distinguished name

  3. Go to Policy Server MMC and configure the active directory synchronization of the group policies. You can set multiple Organizational Unit groups in the same group.

    1. Locate Active Directory Synchronization. Right-click it then click Enable.
    2. Locate Distinguished Name then configure the distinguished name "OU=QAGroup1,DC=qatd1,DC=com" from step 2.
    3. Enter the user name and password. The user is a domain user who has permission to access the OU group.
    4. Enter the domain name and hostname.

      Configure active directory synchronization of group policies

All users of the organization unit will sync into this group. You can trigger the AD sync with either of the following:

  • Restart PolicyWindowsService. After starting PolicyServerWindowService and passing 15 seconds, the first AD sync is running.
  • Or wait for about 45 minutes. The AD sync is triggered every 45 minutes.

Frequently Asked Questions

To modify the Sync Interval time:

  1. Open the database table "PolicyServerSettings".
  2. In the row "ADSyncPollingInterval", change the value of the column to "ParameterValue". The unit is minute.
  3. The next run of AD sync will still occur with the interval of 45 minutes and the new interval time is set in this run. Therefore, the new interval time will be applied on the next run or you could just restart the PolicyServerWindowService to apply the new value immediately.

To retrieve exisitng users that disappeared from the encryption group, remove all domain users from the recyle bin on the enteprise level or group level.

  1. Navigate to Users node and right-click and then click Remove All Users.

    Remove All Users

  2. Tick the Remove from Enterprise checkbox.

    Remove from Enterprise

When you delete any user(s) from the Policy Server, there will be a flag in the database that will show that the user(s) were deleted. The moment that the AD sync happens, it will see that the user(s) were deleted and it will not pull them back in. To pull any user(s) back in after being deleted, is to run the external browser, search for the user(s) and manually add them.


If these domain users exist in the enterprise level but there is no option to remove from the reclycle bin, there is a workaround.

You can create a group and add all domain users into this group and then select remove all users from group again.

  1. Create a group. Right-click it then click Add existing Users.
  2. Click Search.
  3. Add all of domain users on the left plane and then click OK.
  4. Right-click then select Remove all users from group and tick the Remove from Enteprise checkbox.
  5. Restart PolicyWindowsService.
  6. Wait for AD sync and all of the domain users will pulled back into the group.

Yes. Change the same distinguished name to DC=qatd1,DC=local. AD sync will sync the entire domain users list into a group.

User management by MMCAddRemove from group and enterpriseOnly remove from group
AD Sync resultUser keep in groupAdd user back to groupDo not add user back to group

If you already added some domain users into the group or after AD syncing, the domain users only are removed from the group. You have to remove all domain users from the recycle bin and restart PolicyWindowServices, then all of domain users will back in the group.

Yes, you can sync from the Security group level and the distinguished name should be changed to CN=QAGroup3,DC=qatd1,DC=local. You can check the distinguished name using ADSI Edit tool in AD.

Solution Id:
Did this article help you?

Thank you for your feedback!

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.