---
title: Quick LDAP/AD Definition 
slug: kronpam-reference-guide-3-5-0/quick-ldapad-definition
description: Learn how to add a new LDAP server in the administrator settings with this comprehensive guide. Discover the necessary configuration parameters, advanced settings, and how to populate attributes such as email and manager information. Visual aids are inclu
docTags: 
createdAt: 2022-08-03T09:57:57.000Z
---

To use the Kron PAM Setup Wizard to configure an LDAP/Active Directory integration:

1. Navigate to **Administration > System Configuration Manager > Integrations > Ldap Integration.**

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/nhfgzg13dcl-KIiE9-Qfq_image.png" size="78" width="752" height="276" position="center" caption="LDAP Manager" showCaption="true"}

- Click **Add New Ldap Server.**

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/YThnT9p1H2UR4SNt6TTvW_image.png" size="50" width="606" height="724" position="center" caption="LDAP account settings" showCaption="true"}

1. Enter the related configuration parameters:
   a.	**LDAP Source Name**: a different name must be defined for each LDAP, like ldap1, ldap2, etc.
   b.	**URL**: LDAP IP address and port number
   c.	**Domain**: LDAP domain
   d.	**Username**: read-only user credentials to get the user list information
   e.	**Password**: the username’s password
   f.	**Base DN**: LDAP group area or organization unit
   g.	**Group Search Phase**: The search phase of the imported user groups; must be provided as (objectClass=group).
   h.	**User Search Phase**: The search phase of the imported users; must be provided as (objectClass=user)
   i.	**Principal Key**: Represents user information which is sent to AD for authentication. For instance, if we use only the question mark(**?**), the username is only sent to AD for authentication but if we use the domain after the question mark (?domain.com) query sends the username with the domain.
   j.	Follow these steps for each LDAP definition.
2. Click the **Save** button.

**Advanced Settings**:

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/KfGzxkTZdDL1q2pn-rYEd_image.png" size="60" width="724" height="626" position="center" caption="LDAP Account Advanced Settings" showCaption="true"}

**Is Active Directory**: If the LDAP account is a Windows Active Directory,
it should be set as **YES**.

**NIS Net Group Enable**: This parameter only applies to an Oracle
11g LDAP. The value can be set as **YES** or **NO.** The default value is
**NO**. In an Oracle LDAP, there may be a netgroup entry defined by
**objectClass** with the value **nisNetGroup**. If the value is
**TRUE**, enables the import of users with the **netgroup** property.

**User Search With Member Of**, if the users have the MemberOf attribute
in the LDAP Server, this parameter can be se&#x74;**&#x20;to Yes** to import users. By
default, the Members attribute in the User Group is used to import users.

**User Phone Number Attribute**: Kron PAM can send SMS to users by
using the **phoneNumber** property of users. When adding users from AD/LDAP, the
attributes to be looked at first should be included in this advanced parameter
to fill out the user's **phoneNumber** property. Multiple attributes can be
defined. Starting from the first defined attribute, the **phoneNumber** user
property is filled with the first full attribute.

**User Personal No Attribute**: When adding users from AD/LDAP, the attributes to be looked at first should be included in this advanced parameter to fill out the user's Personal No property. Multiple attributes can be defined. Starting from the first defined attribute, the **Personal No&#x20;**(personal\_id in the database) user property is filled with the first full attribute.

**Additional Attributes**: Additional attributes can be added with a comma (,) separator without space.&#x20;
For example, *userPrincipalName,objectClass,ubaThreshold.*

**Connector Site Name:** If you are using the Tenant Connector feature, you should select the remote site name. Usually, LDAP user attributes are taken from AD and filled accordingly for a user, but the email attribute is an exception. If the email attribute is needed for an LDAP user with no email value on AD, this attribute can be filled on the **User Properties** screen. If the email attribute is filled on AD, the LDAP sync job overwrites this email property. The Manager attribute is automatically added to the user properties when LDAP is imported. However, it is mandatory to import the AD user managers to Kron PAM. If the AD managers are not imported, the Manager attribute won’t be added to the user properties. The attributes are shown on the **User Properties&#x20;**&#x77;indow in the following figure.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/96QrzvSgiLz0EDkkbZojS_image.png" size="68" width="724" height="620" position="center" caption="LDAP User Properties" showCaption="true"}

