---
title: LDAP/AD Integration
slug: kronpam-reference-guide-3-5-0/ldapad-integration
description: Learn how to seamlessly integrate LDAP/Active Directory with Kron PAM. Follow our step-by-step guide to enable integration, import users, and configure additional options. Define parameters, save changes, and trigger the LDAP sync job effortlessly. Boost 
docTags: 
createdAt: 2022-08-03T09:57:56.000Z
---

Kron PAM allows LDAP/Active Directory integration with select integration options.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/0beaAwO7dii1Oi3sCOAV1_image.png "LDAP Integration")

1. Click the Integration Options’ **Edit** button.
2. Select the desired integration option and click **Save**.
3. Click the **Synchronize All&#x20;**&#x62;utton to import LDAP users.

**Delete Empty User Groups**: If this option is selected, the empty LDAP user groups are deleted from Kron PAM.

**Allow Duplicated Email**: Allows user import even if the users have the same email address. If this option is not selected, only one user with a unique email address will be imported.

**Import Users With Domain Name**: This value can be set as **TRUE** or **FALSE**. If the value is **TRUE,** the users of the domain name KronPAM\testuser or testuser\@kronpam.com are imported. If the parameter is set as **TRUE**, the **userPrincipalName** value should be added to the LDAP Definition.

**Separator**: The value can be set as “**\\**” or “**@**”. The preferred separator is used to import users from the AD with the domain name. (Example: KronPAM\testuser or testuser\@kronpam.com). The default value is "**\\**".

**Import User Groups With Domain Name**: This value can be set as **TRUE** or **FALSE**. If the value is **TRUE**, the user groups with the domain name KronPAM\TestuserGroup are imported.

| **Parameter Name**                                                       | **Sample Parameter Value**                              |
| ------------------------------------------------------------------------ | ------------------------------------------------------- |
| **sc.integration.ldap.baseDN\_0**                                        | DC=SingleConnectlab,DC=net                              |
| **sc.integration.ldap.baseDN\_1**                                        | DC=SingleConnect,DC=com                                 |
| **sc.integration.ldap.domain\_0**                                        | SingleConnectlab.net                                    |
| **sc.integration.ldap.domain\_1**                                        | SingleConnect.com                                       |
| **sc.integration.ldap.eid\_0**                                           | Administrator\@SingleConnectlab.net                     |
| **sc.integration.ldap.eid\_1**                                           | Admin\@SingleConnect.com                                |
| **sc.integration.ldap.group.import.with.domain.name**                    | TRUE                                                    |
| **sc.integration.ldap.group.search.phrase\_0**                           | (objectClass=group)                                     |
| **sc.integration.ldap.group.search.phrase\_1**                           | (objectClass=group)                                     |
| **sc.integration.ldap.password\_0**                                      | ?                                                       |
| **sc.integration.ldap.principal\_1**                                     | ?                                                       |
| **sc.integration.ldap.source.name\_0**                                   | Ldap                                                    |
| **sc.integration.ldap.source.name\_1**                                   | ldap2                                                   |
| **sc.integration.ldap.url**                                              | ldap\://10.20.30.40#ldap\://10.20.30.41                 |
| **sc.integration.ldap.user.additional.attributes\_0**                    | userPrincipalName                                       |
| **sc.integration.ldap.user.additional.attributes\_1**                    | userPrincipalName                                       |
| **sc.integration.ldap.user.import.with.domain.name**                     | TRUE                                                    |
| **sc.integration.ldap.user.search.phrase\_0**                            | (objectClass=user)                                      |
| **sc.integration.ldap.user.search.phrase\_1**                            | (objectClass=user)                                      |
| **sc.device.integration.ldap.user.membership\_0**                        | false                                                   |
| **sc.device.integration.ldap.import.ou.as.group\_0**                     | true                                                    |
| **sc.device.integration.ldap.device.group.search.phrase\_0**             | (\|(objectClass=group)(objectClass=organizationalUnit)) |
| **sc.device.integration.ldap.allow\.device.in.multiple.groups\_0&#xA0;** | true                                                    |
| **sc.device.integration.ldap.allow\.device.in.multiple.groups\_1&#xA0;** | true                                                    |

After defining the above parameters, apply the steps outlined in sections [Adding Users Automatically](docId\:qincyPBYX-UJFKPZMbtqK) or [Manually Trigger LDAP Sync Job](docId\:Wx5a-5v70m3bOeT_GPe-O).&#x20;

**Add Member Group Users:** If this button is on, the users of the subgroups added to the parent group created in AD will be imported.
