Reference Guide
...
User Management
LDAP/Active Directory Integrat...

Multi-Domain for AD Users

Every Active Directory user has a unique ID, and any configuration made for the user is bound with this unique ID. Therefore, Object GUID information from the LDAP is located in a column that the user accounts page.

ObjectGUID attribute in User Accounts
ObjectGUID attribute in User Accounts
ο»Ώ

When a username changes on the LDAP, it is also changed in Kron PAMt according to ObjectGUID. Therefore, Audit logs, Activity Logs, and Session Logs can be followed easily in case the username changes on the source. Username changes are available on the user group properties.

To see user information changes on the LDAP:

  1. Navigate to User Accounts > User Definition.
  2. Right-click on the AD user’s drop-down menu options button and select Show Properties.
  3. Click on the User History.

If more than one domain exists on Kron PAM, users are able to select a domain on the WEB GUI page by configuration.

  1. Navigate to System Config Manager.
  2. Set the show.sc.portal.login.domain as true.
  3. Save this property.
Select the domain for AD users
Select the domain for AD users
ο»Ώ

ο»Ώ