---
title: Session User (LDAP/AD User) Connection
slug: kronpam-reference-guide-3-5-0/session-user-ldapad-user-connection
description: Learn how to integrate target systems and Kron PAM with LDAP/AD to allow users to login using their LDAP/AD credentials. Discover how Kron PAM can login as an LDAP user if no credentials are configured for the device group. Find out how to select users to
docTags: 
createdAt: 2022-07-27T12:24:30.000Z
---

If both the target systems and Kron PAM are integrated with LDAP/AD, users can log in to target systems with their LDAP/AD credentials. This feature can also be used when the username and password of a Kron PAM user is configured as an account with the same username and password in the target system. This user is called a Session User.



If there are no credentials configured for the device group (such a&#x73;**&#x20;Manual Login**,**&#x20;Direct Credential Username/Password**, **Vault**, o&#x72;**&#x20;Assigned Credentials**), Kron PAM logs into the target device as an LDAP user. If any of the credential methods mentioned above are configured, Kron PAM will establish the connection with the configured method.

Kron PAM allows the selection of the authenticated user that will be able to connect to the target devices. This is explained in the following section. Even if any of the methods mentioned above is configured for the connection, a Session User can be added as a choice. Please refer to section the [Multiple User Selection in RDP Proxy](docId:6tYe0J91YyywOdp3nfVfG) or configuration details.

Some remote devices require FQDN addresses, in addition to a username. In this case, the **useEmailAsUsername** property key should be set a&#x73;**&#x20;true&#x20;**&#x69;n the device group properties, to use both properties to log in to target devices.

If the target device requires FQDN addresses, the following  configuration is required, in addition to the session user property:

1. Navigate to **Devices**> **Device Groups**.
2. Click the device group and select th&#x65;**&#x20;Properties** option.
3. Click the **Edit** and **Next** buttons.
4. Select the **Custom Properties**.
5. Create the **useEmailAsUsername** property value a&#x73;**&#x20;true**.
6. **Save.**

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/qzon0hBvzXPe8YX4AV0Gi_image.png" size="50" width="724" height="990" position="center" caption="Device Group Properties Configuration to Use Domain User Credentials to Log In" showCaption="true"}

