Reference Guide
...
LDAP/Active Directory Integrat...
LDAP/AD Integration
kron pam allows ldap/active directory integration with select integration options click the integration options edit button select the desired integration option and click save click the synchronize all button to import ldap users delete empty user groups if this option is selected, the empty ldap user groups are deleted from kron pam allow duplicated email allows user import even if the users have the same email address if this option is not selected, only one user with a unique email address will be imported import users with domain name this value can be set as true or false if the value is true, the users of the domain name kronpam\testuser or testuser\@kronpam com are imported if the parameter is set as true , the userprincipalname value should be added to the ldap definition separator the value can be set as “ \ ” or “ @ ” the preferred separator is used to import users from the ad with the domain name (example kronpam\testuser or testuser\@kronpam com) the default value is " \ " import user groups with domain name this value can be set as true or false if the value is true , the user groups with the domain name kronpam\testusergroup are imported parameter name sample parameter value sc integration ldap basedn 0 dc=singleconnectlab,dc=net sc integration ldap basedn 1 dc=singleconnect,dc=com sc integration ldap domain 0 singleconnectlab net sc integration ldap domain 1 singleconnect com sc integration ldap eid 0 administrator\@singleconnectlab net sc integration ldap eid 1 admin\@singleconnect com sc integration ldap group import with domain name true sc integration ldap group search phrase 0 (objectclass=group) sc integration ldap group search phrase 1 (objectclass=group) sc integration ldap password 0 ? sc integration ldap principal 1 ? sc integration ldap source name 0 ldap sc integration ldap source name 1 ldap2 sc integration ldap url ldap\ //10 20 30 40#ldap\ //10 20 30 41 sc integration ldap user additional attributes 0 userprincipalname sc integration ldap user additional attributes 1 userprincipalname sc integration ldap user import with domain name true sc integration ldap user search phrase 0 (objectclass=user) sc integration ldap user search phrase 1 (objectclass=user) sc device integration ldap user membership 0 false sc device integration ldap import ou as group 0 true sc device integration ldap device group search phrase 0 (|(objectclass=group)(objectclass=organizationalunit)) sc device integration ldap allow\ device in multiple groups 0 true sc device integration ldap allow\ device in multiple groups 1 true after defining the above parameters, apply the steps outlined in sections docid\ ddgx ql7ob1wrjmbxjnvu or docid\ dltusogcqv1mwwwdpdurh add member group users if this button is on, the users of the subgroups added to the parent group created in ad will be imported