<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xml:lang="en" lang="en" xmlns="http://www.w3.org/1999/xhtml">
  <head runat="server">
    <!-- PageID 382 - published by RedDot 7.5 - 7.5.1.69 - 22111 -->
    <META name="PublicArticle" content="True" />
    <META http-equiv="Content-Type" content="text/html; charset=utf-8" />
    <META name="keywords" />
    <META name="summary" />
    <META name="product" content="fp_web,fp_filter" />
    <META name="version" content="v85" />
    <META name="book" content="Administrator Help for Forcepoint Web Security" />
    <title>Adding and editing directory contexts for the hybrid service</title>
    <!--Loading the 2016 fonts.-->
    <script type="text/javascript" src="//fast.fonts.net/jsapi/c504d579-e135-4f75-8335-4906f6c6ce67.js"></script>
    <!--Library content styles.-->
    <link rel="StyleSheet" href="https://help.forcepoint.com/docs/ni/assets/css/help2016.css" type="text/css" media="all" />
    <!--2016 font support -->
    <link type="text/css" rel="stylesheet" href="//fast.fonts.net/cssapi/c504d579-e135-4f75-8335-4906f6c6ce67.css" />
  </head>
  <body>
    <!--googleoff: all-->
    <a href="https://www.forcepoint.com">
      <img class="logo" alt="Forcepoint logo" src="https://help.forcepoint.com/docs/ni/assets/logo1.png" />
    </a>
    <div class="extLinksContainer">
      <a class="extLinks" href="//support.forcepoint.com/documentation">Documentation</a> | <a class="extLinks" href="//support.forcepoint.com">Support</a></div>
    <!--
		<wsApp:UserAccess ID="useraccess1" runat="server" IsSecure="False" />
		-->
    <div class="spacer1"></div>
    <br />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="h_shusr_edir.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="h_usrgrpfilter.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="web_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="hybrid_filtering.aspx">Configure the Hybrid Service</a> &gt; <a class="WebWorks_Breadcrumb_Link" href="h_diragent.aspx">Send user and group data to the hybrid service</a> &gt; Adding and editing directory contexts for the hybrid service</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <!--googleon: all-->
    <div>
      <div class="N2H-Heading2">
        <span class="Heading_Number"></span><a name="635938">Adding and editing directory contexts for the hybrid service</a></div>
      <div class="IN-TopicInfo"><a name="667646">Administrator Help&nbsp;| Forcepoint Web Security &nbsp;| v8.5.x</a></div>
      <div class="B-Body"><a name="629688">Use the </a><span class="B-Bold">Settings&nbsp;&gt; Hybrid Configuration&nbsp;&gt; Shared User Data&nbsp;&gt; Add Context</span> page to refine the way that Directory Agent searches your user directory and packages user and group information for the hybrid service.</div>
      <div class="F-Frame"><a name="664547">&nbsp;</a></div>
      <table class="WarnTable" style="text-align: left" border="0" cellpadding="1" cellspacing="0" summary="">
        <caption></caption>
        <tr>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 36pt">
            <div class="WI-WarnIcon">
              <img src="caution_icon.gif" alt="*" border="0" width="38" height="34" /><a name="664572">&nbsp;</a></div>
          </td>
          <td style="padding-bottom: 3.5pt; padding-left: 4pt; padding-right: 4pt; padding-top: 4.5pt; vertical-align: top; width: 266.4pt">
            <div class="W-Warning">Warning<a name="664574">&nbsp;</a></div>
            <div class="NT-NoteText"><a name="664575">There is a limit to how many groups the hybrid service can support. The limit is affected by a number of factors, but if it is exceeded, user requests are not handled properly. </a></div>
            <div class="NT-NoteText"><a name="664576">If your organization has a large directory forest with thousands of groups, be sure to configure Directory Agent to upload only the users whose requests are sent to the hybrid service.</a></div>
          </td>
        </tr>
      </table>
      <div class="B-Body"><a name="630332">You can select multiple contexts within the directory. It is best to include contexts that include only users managed by the hybrid service: for example, you might have hybrid users in multiple OUs. Alternatively, if you want to synchronize all users in a number of specific groups, then you can select a context for each group where each context is the fully qualified group name.</a></div>
      <div class="B-Body"><a name="632903">By default, Directory Agent uses the user and group filters defined under </a><span class="LEM-LinkEmphasis"><a href="adv_dir_settings.aspx" title="Advanced directory settings">Advanced directory settings</a></span> on the <span class="B-Bold">Settings&nbsp;&gt; General&nbsp;&gt; Directory Services</span> page. If required, you can customize these filters for each hybrid service context, for example to include only users that are members of a group managed by the hybrid service.</div>
      <div class="B-Body"><a name="630537">You can also choose to exclude certain contexts from the Directory Agent search. You might want to do this if you have a particular context that is not required or could cause problems with the hybrid service, such as an administrator group with multiple email addresses in a record. You can only set a context as an exclude context if it is within an included directory context.</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">1.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="630538">Expand the Directory Entries tree to locate the context you want to use when gathering user and group data from the directory. Narrow the context to increase speed and efficiency.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="648262">Use the search field to locate the context name if required. You can search on OUs, groups, users, or all directory entries. If multiple contexts appear in the search results, select a context and click </a><span class="B-Bold">Show in Tree</span> to see the context's location in the Directory Entries tree.</div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">2.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="629691">Mark the context, then click </a><span class="B-Bold">Set as Include Context</span>.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">3.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="630421">In the popup window that appears, indicate how far below the root context Directory Agent looks for users and groups.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="630422">Select </a><span class="B-Bold">Context Only</span> to limit searches to the root context only.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="630446">Select </a><span class="B-Bold">One Level</span> to limit searches to the root context and one level below.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="703362">Select </a><span class="B-Bold">All Levels</span> to expand searches to the root context and all levels below.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">4.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="703363">If you selected groups or OUs to </a><span class="B-Bold">Set as Include Context</span>, and then selected One Level or All Levels for group searches, the <span class="B-Bold">Include all users in selected groups, regardless of context</span> option is enabled. Check the box if you want to ensure that all users are included from the groups found in the directory search, even if some of those users are in a different context.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="717020">If you are using Windows Active directory, users can be synchronized inside nested groups and then identified for consistent policy enforcement if the nested groups feature is enabled. To enable the feature:</a></div>
      <div class="SA-StepAlpha_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="SA-StepAlpha_inner" style="width: 18pt; white-space: nowrap">a.	</div>
            </td>
            <td width="100%">
              <div class="SA-StepAlpha_inner"><a name="717049">Use a text editor to edit the file das.ini (in C:\Program Files\Websense\Web Security\bin or /opt/Websense/bin/, by default, on the Directory Agent machine). </a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I2-IndentedText2"><a name="717108">Locate the section labeled "DAS" and set the EnableNestedGroup value to 1 (on).</a></div>
      <div class="SA-StepAlpha_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="SA-StepAlpha_inner" style="width: 18pt; white-space: nowrap">b.	</div>
            </td>
            <td width="100%">
              <div class="SA-StepAlpha_inner"><a name="717126">Restart the Directory Agent service to reload the settings to use the new settings in das.ini.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="717167">EnableNestedGroup works with any context configuration (Context Only, One Level, All Levels, Include all users).</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">5.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="632892">To fine-tune the search filters that Directory Agent uses for this context, click </a><span class="B-Bold">Customize Search Filters</span>.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">6.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="632931">Mark </a><span class="B-Bold">Customize search filters</span>, and edit the user and group search filters as required.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">7.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="648340">Click </a><span class="B-Bold">OK</span> to save the directory context.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">8.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="630487">When you specify that a context is included, by default any contexts below that context in the tree are also included. To exclude a context within an included context, mark the context that should not be sent to the hybrid service, and click </a><span class="B-Bold">Set/Edit/Remove Exclude Context</span>. You can select multiple contexts if required.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">9.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="630589">In the popup window that appears, note that </a><span class="B-Bold">Set as exclude context</span> is selected. The <span class="B-Bold">Remove exclude context</span> option is available only when you select an existing excluded context and click <span class="B-Bold">Set/Edit/Remove Exclude Context</span> to edit it.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">10.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="648477">Indicate how far below the excluded context Directory Agent looks for users and groups.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="630590">Select </a><span class="B-Bold">Context Only</span> to limit searches to the specified context only.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="630591">Select </a><span class="B-Bold">One Level</span> to limit searches to the specified context and one level below.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="630592">Select </a><span class="B-Bold">All Levels</span> to expand searches to the specified context and all levels below.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="I-IndentedText"><a name="630703">Note that the user and group levels for an excluded context cannot be greater than the defined levels for its root context. For example, if the root context's Directory Search level for either users or groups is set to Context Only, the corresponding users or groups search level for the excluded context are also set to Context Only and cannot be changed.</a></div>
      <div class="I-IndentedText"><a name="648695">If you select All Levels for both users and groups, everything below the selected context is excluded and you cannot browse further levels of the Directory Entries tree.</a></div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">11.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="683855">If only groups are specified as </a><span class="B-Bold">exclude</span> contexts, and <span class="B-Bold">One</span> or <span class="B-Bold">All</span> levels have been selected for exclusion, use the <span class="B-Bold">Exclude all users in selected groups, regardless of context </span>option to determine whether:</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="683856">(Check box marked) Users in exclude contexts are always excluded, regardless of whether they are also defined in other (included) contexts.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B2-Bullet2_outer" style="margin-left: 18pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="B2-Bullet2_inner" style="width: 18pt; white-space: nowrap">
                <img src="b2.png" alt="*" border="0" width="8" height="7" />
              </div>
            </td>
            <td width="100%">
              <div class="B2-Bullet2_inner"><a name="683857">(Check box cleared) Users in exclude contexts are not excluded when they are also defined in other (included) contexts.</a></div>
            </td>
          </tr>
        </table>
      </div>
      <div class="S-Step_outer" style="margin-left: 0pt">
        <table border="0" cellspacing="0" cellpadding="0" summary="" role="presentation">
          <tr style="vertical-align: baseline">
            <td>
              <div class="S-Step_inner" style="width: 18pt; white-space: nowrap">12.	</div>
            </td>
            <td width="100%">
              <div class="S-Step_inner"><a name="630737">Click </a><span class="B-Bold">OK</span> to save the excluded context.</div>
            </td>
          </tr>
        </table>
      </div>
      <div class="B-Body"><a name="630762">When you are finished, click </a><span class="B-Bold">OK</span> to close the Add Context page and update the Root Context for Hybrid Service Users table. You must also click <span class="B-Bold">OK</span> on the Shared User Data page to cache the change.</div>
      <div class="B-Body"><a name="703575">Click a link on the Root Context for Hybrid Service Users table to access the </a><span class="B-Bold">Edit Context</span> page for the selected context.</div>
    </div>
    <!--googleoff: all-->
    <div class="library_search">
      <form class="support_search" action="/content/kb-search.aspx" method="get">
        <label></label>
        <label></label>
        <input type="text" name="q" value=" Search eSupport" onfocus="if (this.value == ' Search eSupport') {this.value = '';}" onblur="if (this.value == '') {this.value = ' Search eSupport';}"></input>
        <input type="submit" value=" "></input>
      </form>
    </div>
    <br class="clear" />
    <!-- New Navigation DIV -->
    <div class="TL_nav" style="text-align: left;">
      <table cellspacing="0" class="toolBarTable" summary="">
        <!-- End New Navigation DIV -->
        <tr>
          <td>
            <!-- New Go To TOC -->
            <a href="toc.aspx"><img src="images/toc.png" alt="Go to the table of contents" border="0" /></a>
            <!-- End Go To TOC -->
          </td>
          <td>
            <!-- New Previous -->
            <a href="h_shusr_edir.aspx"><img src="images/prev.png" alt="Go to the previous page" border="0" /></a>
            <!-- End New Previous -->
          </td>
          <td>
            <!-- New Next (Active) -->
            <a href="h_usrgrpfilter.aspx"><img src="images/next.png" alt="Go to the next page" border="0" /></a>
            <!-- End New Next (Active) -->
          </td>
          <td>
            <!-- New PDF -->
            <a href="web_help.pdf"><img src="images/pdf.png" alt="View or print as PDF" border="0" /></a>
            <!-- End New PDF -->
          </td>
          <!--Start JR breadcrumbs -->
          <td width="20px"></td>
          <td>
            <div class="WebWorks_Breadcrumbs" style="text-align: left;">
              <a class="WebWorks_Breadcrumb_Link" href="hybrid_filtering.aspx">Configure the Hybrid Service</a> &gt; <a class="WebWorks_Breadcrumb_Link" href="h_diragent.aspx">Send user and group data to the hybrid service</a> &gt; Adding and editing directory contexts for the hybrid service</div>
          </td>
          <!--End JR breadcrumbs -->
        </tr>
      </table>
    </div>
    <div class="extFooterContainer">
      <div class="extFooter">
        <div align="center">Copyright 2023 Forcepoint. All rights reserved.</div>
      </div>
    </div>
    <SCRIPT>
   function getFileName() {
      //this gets the full url
      var url = document.location.href;
      //this removes the anchor at the end, if there is one
      url = url.substring(0, (url.indexOf("#") == -1) ? url.length : url.indexOf("#"));
      //this removes the query after the file name, if there is one
      url = url.substring(0, (url.indexOf("?") == -1) ? url.length : url.indexOf("?"));
      //this removes everything before the last slash in the path
      url = url.substring(url.lastIndexOf("/") + 1, url.length);
      //return
      return url;
   }

   var url = document.URL;
   var Docname = getFileName()
   s.pageName = "enu:support:technical library:webhelp_v85x:" + Docname;
   s.prop1 = "enu:support";
   s.prop2 = "enu:support:technical library";
   s.channel = "support";
   // <!--
   s.server = "<%= System.Environment.MachineName %>";
   //--></SCRIPT>
    <script language="javascript1.1" type="text/javascript">
   /********Do Not alter below this line ***********/
   var s_code = s.t(); if (s_code) document.write(s_code)
   //--&gt;</script>
  </body>
  <!--"GENERALQUARTERSALLHANDSMANYOURSTATIONS"-->
</html>