LDAP Overview

Here you can establish a connection to your Active Directory via LDAP to mass import users and groups. The sync has to be performed manually. You can configure multiple LDAP connections to different systems or with different configurations/filter.

Edit

Server Name



The Display Name of the Server



Type



Currently only Active Directories which support LDAP are supported



LDAP Domain



The primary LDAP Domain (e.g. example.com)



LDAP Host



Only necessary if the LDAP host is not reachable under the given LDAP Domain.



Port



Leave empty to use Standard Port (389 or 636 for SSL)



Username



E.g. CN=John,OU=Users,DC=EXAMPLE,DC=COM Note: Most systems require the username in this format and do not accept “John” as Username



Password



Confirm Password



Connection Security



Note: when using SSL or TLS, the certificate of the Active Directory will be checked. If this is self-signed you have to add the root CA to the trust storage of the OnPremise Machine. If you are on Cloud the Active Directory has to provide a trusted certificate or the connection will only work with no Encryption



Automatic Sync.



Enables the automatic synchronization of the LDAP directory in the time interval specified in the general LDAP settings.



Base DN



If you don’t want to synchronize the whole directory, you can specify an OU here.E.g. OU=AndroidUsers,OU=Users,DC=EXAMPLE,DC=COM



Member of



All imported users will be added to the selected group



Only activated users?



When enabled, the attribute userAccountControl will be considered, users without that attribute won’t be imported.



LDAP Filter



You can use LDAP Filter to filter which Users get imported



Regex Filter



You can use Regex Filter to filter which Users get imported



Test Connection



Tests the connection when saving the configuration



Reset directory structure on sync?



If true all LDAP entries will be moved back to their original location in the LDAP tree. Recommended to be enabled.



Re-import deleted users and groups?



When enabled, users and groups that have been deleted will be recreated. Recommended to be enabled.



Sync deletions?



When enabled, groups and users will be deleted when they are deleted on the LDAP server. Also devices of deleted users will be deleted.


Below the list of your LDAP Configurations you can define the period in which the system sync automatically. Only uses the LDAP Configurations for automatic sync which have the according option activated.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.