If your organization uses Microsoft Active Directory (AD), you can import users, groups, Organizational units (OUs) and computers from multiple AD domains into the Endpoint Security Management Server. After the objects have been imported, you can assign policies.
When you first log in to SmartEndpoint, the Users and Computers tree is empty. To populate the tree with users from the Active Directory, you must configure the Directory Scanner.
The Directory Scanner scans the defined Active Directory and fills the Directories node in the Users and Computers tab, copying the existing Active Directory structure to the server database. For this to succeed, the user account related to each Directory Scanner instance requires read permissions to:
An object deleted from the Active Directory is not immediately erased but moved to the Deleted Objects container. Comparing objects in the AD with those in the Deleted objects container gives a clear picture of network resources (computers, servers, users, groups) that have changed since the last scan.
| 
 | Note - When using multi-domain scanning, you must configure an Active Directory instance for each domain. A Directory Scanner instance has its own account, configured according to the requirements stated above. | 
A scanner instance defines which path of the Active Directory will be scanned and the scan frequency. One scanner instance can include the full Active Directory. You can configure multiple scanner instances to scan different domains or different OUs in the same domain.
Do not create a scanner instance for an OU that is already included in a different scan. If you try to create a scan that conflicts with a different scan, an error message shows.
If the domains use DNS servers, make sure that:
To create a scanner instance:
The scan shows in the Organization Scanner window.
| 
 | Note - Scanning the Active Directory takes time. AD objects show in the sequence they are discovered. | 
In the Deployment tab > Organization Scanners page, you can see all configured scans and their statuses. You can also do these operations:
At the specified interval of a scanner instance, the Directory Scanner synchronizes Endpoint Security nodes in the Users and Computers tree with nodes in the Active Directory. When synchronization occurs:
You can delete these users manually using SmartEndpoint.