Create an AD Bridge License Container
You can install AD Bridge licenses manually on each client, or you can install the licenses in Active Directory and manage them from a central location. In Active Directory, you must create a license container before you can import an AD Bridge Enterprise license key file.
Review the following recommendations for creating a license container.
- Manage licenses in Active Directory and create your license container in a common location at the highest level of the organizational unit (OU) hierarchy to which you have write access.
For instance, if you have separate OUs for your Linux and Mac computers, creating the licensing container in a common location above the OUs for the Mac and Linux computers can simplify license management.
- If you have a default cell, create the license container at the level of the domain.
Any OU may have a license container. The container need not be in the same OU as an AD Bridge cell. The AD Bridge Enterprise agent searches the OU hierarchy for a license container in the same way that it searches for a cell. When a license container is found, the agent stops trying to find a key in another container (even if the container it finds is empty) and checks whether the license is assigned to the computer. When the agent finds a license in Active Directory, it marks it as assigned to the computer.
When you create a license container, computers can automatically acquire a license. You can turn off automatic licensing depending on your requirements. However, after you create the license container you must assign a license to each computer manually.
For more information, please see Assign a License to a Computer in AD
If needed, you can turn on automatic licensing again at any time after you create the container. For more information, please see Turn on Automatic Licensing.
If there is no license container in Active Directory, the agent verifies the license locally. This is a scenario reserved for licenses set with setkey-cli.
You must be a member of the Domain Administrators security group or have privileges sufficient to create and modify containers where you want to create the licensing container. We recommend that you do not create a license container in the Domain Controllers OU.
To create a license container:
- In the BeyondTrust Management Console, expand the Enterprise Console node, right-click the License Management node, and then click Create License Container.
- Uncheck the Allow Computers to Acquire Licenses Automatically box to prevent computers from obtaining a license (Optional).
If you uncheck the box, you must manually assign a license to each computer.
- Select the location where you want to create a container and then click OK.
You are now ready to import a license file, which will populate the AD Bridge Enterprise licenses container in Active Directory with licenses for your Unix, Linux, and macOS computers.
If you turned off automatic licensing when you created the license container, you can turn on the feature at any time.
To turn on automatic licensing:
- In the BeyondTrust Management Console, expand the Enterprise Console node, right-click the License Management node, and then click Assign Policy.
- Check the box to allow automatic licensing and click OK.