Drive Encryption acquires users through the Microsoft Active Directory (AD) or through the ePO - On-prem User Directory. You must have a registered LDAP server or have the User Directory installed to use Policy Assignment Rules to enable dynamically assigned permission sets, and to enable manual and automatic user account creation.
Note
Drive Encryptioncan also acquire users through standalone user management using the User Directory feature, which removes the dependency on LDAP server. For more information, see User management through User Directory.
How does LDAP Sync work
In Active Directory, it is possible to create a group structure where a group contains several other groups. With LDAP Sync, all the groups can be synchronized recursively.
Consider the following AD structure, where:
Group A contains Group B and Group C
Group B contains Group D
If EEAdmin registers for Group A to perform recursive sync, the users of Group B, Group D, and Group C are synchronized recursively.