LDAP/AD User Connections
If both the target systems and Kron PAM are integrated with LDAP/AD, users can log in to target systems with their LDAP/AD credentials. This feature can also be used when the username and password of a Kron PAM user is configured as an account with the same username and password in the target system. This user is referred to as the Session User.
Please check LDAP/Active Directory Integration for integration details. If there are no credentials configured for the device group (such as Manual Login, Direct Credential Username/Password a.k.a. Global Username, Vault, or Assigned Credentials), Kron PAM logs into the target device as an LDAP user. If any of the credential methods mentioned above are configured, Kron PAM will establish the connection with the configured method.
It is possible to choose the account to be used to connect to the target system. This is explained further in the following section. Even if there are other methods configured for the connection, the Session User can be added as a choice to connect to the target system. Please refer to the following Multiple User Selection in the RDP Proxy section for the necessary configurations.