Action summary
This article explains the procedure for customers who use the HENNGE One Directory Sync Tool to synchronize users from Active Directory to Access Control.
Notes
- Make sure that the requirements for the machine on which you will run the tool are met. Please refer to [HENNGE Directory Sync Tool] in the following Help Center article.
HENNGE One System Requirements
* HENNGE Directory Sync Tool refers to the proxy settings in Internet Options.
Log on to the server with the account that will start the service and configure the proxy settings. -
If you encounter the following error, please refer to the following article and install the root certificate.
How to Install Root Certificate for HENNGE Directory Sync Tool<urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:590)> - Users in Active Directory and users in Access Control have a one-to-one correspondence. Many-to-one correspondence is not supported.
- An Access Control administrator account is required to perform these procedures.
- You must log in to the HENNGE Directory Sync Tool server with an account that has the following permissions:
* All of the following Active Directory permissions: [Enterprise Admins], [Domain Admins], and [Schema Admins] - The content of this article is based on the product specifications as of July 2026 and is subject to change without notice.
Procedure
Test synchronization
- Launch PowerShell with administrator privileges.
-
Run the HENNGE Directory Sync Tool.
* You can perform a test with the "/n" option.
* If you do not specify the "/n" option, synchronization will be executed. Please be careful.Command
cd "C:\Program Files\HDE One Directory Sync" .\console.exe /nIf there are no users to be synchronized, the following will be output.
##### Sync set [sync01] ##### Active Directory ---> HENNGE Access Control * No sync data *
Manual synchronization
-
After confirming the output result of the test synchronization, run "console.exe" without the "/n" option.
cd "C:\Program Files\HDE One Directory Sync" .\console.exe
Scheduled synchronization
Configure scheduled synchronization for the [HENNGE One Directory Sync] and [HENNGE One Password Sync] services.
* Depending on the version of the sync tool you are using, these may be displayed as [HDE One Directory Sync] and [HDE One Password Sync].
- Start [Services].
-
Open the properties of the target service and configure the following:
[General] – [Startup type]: Automatic
[Log On] – [Account]: Set an account with the following permissions.
* All of the following Active Directory permissions: [Enterprise Admins], [Domain Admins], and [Schema Admins] - Save the settings and start both services.
Check scheduled sync logs
- Access the Access Control Administration.
How to Access the Access Control Administration - Click [Sync Logs] on the left side of the screen.
-
Set the desired date in the search menu at the top of the screen and click the magnifying glass icon.
-
Confirm that the sync logs are displayed as search results.
* If the sync logs are not displayed as search results, there may be an issue on the device running the HENNGE Directory Sync Tool.
In such cases, please contact your HENNGE One implementation representative or Technical Support. -
Confirm that there are no errors in the sync logs displayed in the search results.
* If there is a value in the [Failure] column of the sync log search results, synchronization has failed due to some reason.
In such cases, please contact your HENNGE One implementation representative or Technical Support.
There are two types of sync logs displayed as search results:
- Synchronization of user information from Active Directory to Access Control
- Synchronization of user passwords from Active Directory to Access Control
You can click each log to view the details.
Case 1: User synchronization is successful
By default, scheduled synchronization runs every 2 hours.
Changes to user account properties (such as username, UPN, etc.) in Active Directory will be reflected in Access Control at the next synchronization.
Even if there are no changes to any user accounts in Active Directory, the sync log will still appear in the search results.
If "Start syncing" is displayed in the expanded log, it is a user sync log.
If this sync log is executed regularly and there are no errors, synchronization is working properly.
Case 2: Password synchronization is successful
By default, scheduled synchronization runs every 3 minutes.
Changes to user account passwords in Active Directory will be reflected in Access Control at the next synchronization.
Password sync logs are output only when a user's password is changed in Active Directory.
If "Start password syncing" is displayed in the expanded log, it is a password sync log.
If this sync log is executed regularly and there are no errors, synchronization is working properly.
Translation Disclaimer
This article has been automatically translated from the original Japanese version for your convenience.
While we strive to ensure accuracy, we cannot guarantee its reliability or completeness.
In the event of any discrepancies or questions regarding the content, the official Japanese version shall prevail.