Configuration of LDAP connection pools

You can manage LDAP connections and access permissions for domain users on the SystemSSO page.

Creating a LDAP connection

To create a LDAP connection:In the LDAP connection table, click .Enter a LDAP connection name.Enter the LDAP server IP address or full domain name.Enter the port number.If necessary, enable a secure connection to the LDAP server.In the User search base box, enter the name of the directory record where to start searching for user accounts.In the User search filter box, enter a search condition.Enter the credentials of a user who has permissions to read objects from the directory.If necessary, enable automated user synchronization and specify its interval.Enter username and email attribute names to search for users.Click Create.The LDAP connection is now created. Now, you must configure access permissions for domain users.

Editing a LDAP connection

To edit a LDAP connection:Next to the LDAP connection, click .Make changes.To check the LDAP connection after the changes were made, click Synchronize.Click Save.The LDAP connection is now edited. Domain users' access rules will be updated according to the synchronization interval.

Deleting a LDAP connection

Only administrators of the general tenant can delete a LDAP connection. The LDAP connection will be deleted in all tenants. In addition, the previously configured access permissions will be deleted for domain users associated with this LDAP connection. At the same time, the domain users' sessions will remain active until their lifetime expires.

To delete a LDAP connection:Next to the LDAP connection, click .Click Delete and confirm deletion.

Mapping PT AF roles and Microsoft Active Directory groups

The domain users' permissions in the tenant are determined by the mapping between Microsoft Active Directory groups and PT AF roles. It is recommended that each domain user has access to only one tenant and one role in it.

In other cases, at their first login to PT AF, the user will be authenticated only in one of the available tenants according to the internal algorithm. This tenant will be assigned as the only tenant available to the user (default tenant). According to the algorithm, a user will be assigned only one role from several matching roles.

To map roles and groups:In the mapping table, click .Select the LDAP connection to the directory you want to map.Enter an attribute name that contains the list of user groups in the directory.Enter a condition for filtering groups.Select a role that matches groups.Click Create.The mapping is now configured. Domain users' access rules will be updated according to the synchronization interval.

Changing mapping between PT AF roles and Microsoft Active Directory groups

To change a mapping between roles and groups:Next to the mapping, click .Make changes.Click Save.The mapping is now changed. Domain users' access rules will be updated according to the synchronization interval.

Deleting a mapping between PT AF roles and Microsoft Active Directory groups

Whether or not a domain user can log in after a mapping is deleted depends on the presence of other configured mappings for this user, as well as on the fact of their authorization in PT AF before the mapping was deleted.

If other mappings are configured for a user, they can log in to the same tenant with another role or to a different tenant according to the mapping selected by the internal algorithm. (The default tenant will be changed.) Access rules will be updated after synchronization with Microsoft Active Directory (scheduled or started manually).

If other mappings are missing and the user has previously logged in to PT AF, the user can continue working in PT AF with the previous role. If other mappings are missing and the user has not previously logged in to PT AF, the user will not be able to log in.

To delete a mapping between roles and groups:Next to the mapping, click .Click Delete and confirm deletion.

Starting synchronization with Microsoft Active Directory manually

Only administrators of the general tenant can start the synchronization process.

To start synchronization with Microsoft Active Directory manually:Next to the LDAP connection, click .Click Synchronize.Next to Last synchronization, the icon and the synchronization progress (in percent) will appear.

The website uses cookies according to the cookie policy.