| • | You have configured Active Directory with Usher on your local lT infrastructure (on-premise). |
| • | You have administrative access to Network Manager. |
| • | You know the URL of your Usher Server. |
| • | You know the location of your CA-signed certificate. When you upgrade, the Usher Agent will not recognize the default CA list. Therefore, the certificate must be re-added to the default CA list. |
| 1 | On the machine where Usher is installed, navigate to the Agent service and stop the Agent. |
| 2 | Create a backup of the /res and /logs folders. |
| 3 | Log in to Usher Network Manager: |
| a | Navigate to the Network Manager home page. |
| b | On your smartphone, open the Usher Security app, then open the QR code reader. |
| c | Scan the QR code displayed on the Network Manager page to log in to your network. |
| 4 | On the main landing page, under Users and Badges, your configured Active Directory Agent is shown. |
| 5 | On the right side of the Agent configuration, click the arrow icon and select Download Agent. Note the location on your computer where the installation file (for example, cluster_AD_installer.exe) is saved. |
| 6 | Copy the registration code as you need the code to complete the Agent update. Be aware that the code expires every 5 minutes. |
| 7 | On the machine where you want to update the Usher Agent for Microsoft Active Directory, open and run the Usher Agent installation file as an administrator by right-clicking on cluster_AD_installer.exe and select Run as administrator. The Usher Agent installation wizard opens. Do the following: |
| a | At the setup screen for upgrading the Usher Agent, click Yes. |
| b | The InstallShield extracts the upgrade for Usher Agent. At the Resuming the InstallShield Wizard for Usher Agent for Microsoft Active Directory screen, click Next. |
| c | The InstallShield installs the upgrade. Click Finish to close the installation wizard. |
| 8 | The Agent Provisioning Tool is launched automatically. Select Update configuration, then click Next. |
| 9 | Re-add the CA certificates. |
If you previously added your CA-signed certificate, the new Agent will not recognize the default CA list. You must re-add your CA-signed certificate to the default CA list. Enter the name of the certificate, and then click Browse to select your certificate. When your certificate name and path are specified, click Add to CA list.
| 10 | Click Next. The Update current configuration page opens. |
| 11 | Enter your information to match the values you selected when Active Directory Agent was configured for the first time. You must be sure to enter the same values, or the Usher Agent won't be updated correctly. Since you specified your certificate information on the previous page, you are not required to re-enter your certificate information. |
| 12 | When finished, click Submit. Usher tests the connection with your Microsoft Active Directory server and completes the configuration of your Usher Agent. If all configuration information is correct, the Usher Agent is restarted automatically. |
| 13 | Check to ensure that your Directory Agent service is running. |
After the AD Agent for Usher has been updated, you can add another agent to create an AD Agent cluster. For steps, see Synchronizing users from Microsoft Active Directory