Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup and NetBackup Appliances Hardening Guide
  3. Steps to protect Access Appliance
  4. Configuring user authentication using digital certificates or smart cards
  5. Configuring AD server settings
NetBackup and NetBackup Appliances Hardening Guide

Configuring AD server settings

The network ad commands are used to configure the Active Directory (AD) client for authentication. These commands configure the Access Appliance to use AD users and groups when logging into the Access Appliance.

If the AD client's domain controller is set to refuse NTLM authentication, run the following command to disable NTLM prior to configuring the Active Directory client:

CLFS> set ntlm_auth no

To set the AD client configuration

  • You can set the AD client's domain, domain controller, workgroup and domain user. To set the AD client configuration details, enter the following:
    Network> ad set domain domaincontroller workgroup
    domainuser idmapupperbound

    domain

    Active Directory domain name or Windows NT domain name

    domaincontroller

    Primary[,backup] domain-controller names

    workgroup

    Windows WORKGROUP name or NetBIOS domain name

    domainuser

    domain user name which is used for authentication in the domain join operation

    idmapupperbound

    idmap upper bound for AD users

Access Appliance displays the cluster time as well as the time on the Active Directory Domain Controller.

If NTP has been configured correctly, there will be no time skew. Otherwise, you will need to reconfigure NTP correctly.

You will be prompted to enter the password of domainuser.

To enable the AD client

  • To enable the AD client to use Active Directory for authentication, enter the following:
    Network> ad enable

To display the AD client configuration

  • To display the AD client configuration, enter the following:
    Network> ad show

To disable the AD client

  • To disable the AD client so that Active Directory is not used for authentication, enter the following:
    Network> ad disable

To clear the AD client configuration

  • To clear the AD client configuration, enter the following:
    Network> ad unset

Feedback

Was this page helpful?
Previous

Configuring LDAP server settings

Next

About multifactor authentication

Feedback

Was this page helpful?