Add a directory

Before you begin

Deploy an identity connector. For more information, see Create and download an identity connector.

Complete this procedure to add any of these directory types:
  • Active Directory (AD)
  • Lightweight Directory Access Protocol (LDAP)
  • Active Directory Lightweight Directory Access Services (AD LDS)

After you add a directory, you must associate the directory service to an identity provider (IdP).

How to

  1. In the navigation menu, select Identity > Directories.
    Note: If you are trying the new Enterprise Center interface, in the navigation menu, select Identity & Users > Directories.
  2. Click the plus sign icon.
  3. In the name and description fields, enter a name and description for the directory.
  4. In the Service Type menu, select one of these directory types:
    • AD
    • LDAP
    • AD LDS
  5. Click Add New Directory.
  6. To configure the host information:
    1. Click the General settings tab.
    2. In the host menu, select either LDAP or LDAPS (secure LDAP) based on how your native directory is setup (LDAP is most common).
    3. Enter either a valid IP address, the fully qualified domain name (FQDN) of your native directory, or the URL to access the directory within your network.
    4. Only modify the port number if necessary. If needed, enter the port number to access the directory internally.
    Note: If firewalls are used, administrators should allow the ports so that ETP can communicate with the LDAP or LDAPS FQDN and port for authentication operations.
  7. Depending on directory type, enter the AD domain or the LDAP domain. For AD domain, enter the Windows domain where your Active Directory is located. For an LDAP domain, enter the LDAP domain where your directory is located.
  8. In the Admin Account field, enter an administrator account that ETP can use to connect to this directory. The administrator account should have read-only access or higher. For example, use the format NetBiosDOMAIN\administrator. For a Microsoft Windows AD integration, enter the Distinguished Name from the Microsoft Windows AD.
  9. In the Admin Password field, enter the password that’s associated with the admin account.
  10. Select the login preference. This is the identifier for the user’s principal in the directory. The user provides this identifier when they are prompted to login or authenticate to access a website. Depending on the directory, you can choose from one of these identifiers.
    • For AD, you can select Email, SAM Account Name, User Principal Name, or Domain/SAM Account Name.
    • For LDAP, you can select Email or UID.
    • For AD LDS, you can select Email, UID, or User Principal Name.
  11. In the other tabs, configure the directory setting as they apply for your implementation.
  12. To configure password management, see Manage password complexity for the Login Portal from the Active Directory (AD).
  13. Associate an identity connector to the directory:
    1. In the Connectors tab, click the chain icon and select the identity connector or connectors that you want to associate with the directory.
    2. Click Associate.
  14. Click the Users tab to view the users assigned to the directory. You can click the number in the Groups column to view the groups a user is associated with.
  15. Click the Groups tab to view the groups that are configured in this directory. You can view the users that are assigned to the group. You can also click the sync icon to synchronize ETP with the latest group information from your directory.
  16. To import a group from an AD, LDAP, or AD LDS:
    1. In the Groups tab, click the plus sign.
    2. In the provided text field, enter the group name. You can use wildcards to perform the search. You add an asterisk (*) on one or both ends to your search terms. Group searches are case sensitive.
    3. Click Search Group.
    4. Select the group or groups that you want to import, and click Add.
  17. Click Save.