Reference Guide
...
LDAP/Active Directory Integrat...
Quick LDAP/AD Definition
3 min
navigate to administrator > ldap manager click add new ldap server enter the related configuration parameters a ldap source name a different name must be defined for each ldap, like ldap1, ldap2, etc b url ldap ip address and port number c domain ldap domain d username read only user credentials to get the user list information e password the username’s password f base dn ldap group area or organization unit g group search phase the search phase of the imported user groups; must be provided as (objectclass=group) h user search phase the search phase of the imported users; must be provided as (objectclass=user) i principal key represents user information which sends to ad for authentication for instance, if we use only the question mark( ? ), the username is only sent to ad for authentication but if we use the domain after the question mark (?domain com) query sends the username with the domain j follow these steps for each ldap definition click the save button advanced settings is active directory if the ldap account is a windows active directory, it should be set as yes nis net group enable this parameter only applies to an oracle 11g ldap the value can be set as yes or no the default value is no in an oracle ldap, there may be a netrgoup entry defined by objectclass with the value nisnetgroup if the value is true , it enables import of users with the netgroup property user search with member of if the users have the memberof attribute in the ldap server, this parameter can be set yes to import users by default, the members attribute in the user group is used to import users user phone number attribute single connect can send sms to users by using the phonenumber property of users when adding users from ad/ldap, the attributes to be looked at first should be included in this advanced parameter to fill out the users phonenumber property multiple attributes can be defined starting from the first defined attribute, the phonenumber user property is filled with the first attribute that is full user personal no attribute when adding users from ad/ldap, the attributes to be looked at first should be included in this advanced parameter to fill out the users personal no property multiple attributes can be defined starting from the first defined attribute, the personal no (personal id in database) user property is filled with the first attribute that is full additional attributes additional attributes can be added with a comma (,) separator without space for ex userprincipalname,objectclass,ubathreshold connector site name if you are using the tenant connector feature, you should select the remote site name usually, ldap user attributes are taken from ad and filled accordingly for a user, but the email attribute is an exception if the email attribute is needed for an ldap user with no email value on ad, this attribute can be filled on the user properties screen if the email attribute is filled on ad, the ldap sync job overwrites this email property the attributes are shown on the user properties window in the following figure