Connect to an LDAP directory
- Create an LDAP account for UEM that is located in the relevant LDAP directory. The account must meet the following requirements:
- The account must have permission to read all users in the directory.
- The password must be configured to not expire and does not need to be changed at the next login.
- If the LDAP connection is SSL encrypted, verify that you have the server certificate for the LDAP connection and that the LDAP server supports TLS 1.2. If SSL is enabled, the LDAP connection to UEM must use TLS 1.2.
- Verify the LDAP attribute values that your organization uses (the steps below give examples for typical attribute values), you will use them in the steps below.
- If you want to use an LDAP directory configuration to connect to Active Directory, and your organization's Active Directory uses the new policy settings to enforce channel binding and signing requirements, you must use LDAPS (SSL) to connect (see steps 5 and 6). For more information, see Microsoft KB4520412.
- In the UEM management console, on the menu bar, click Settings > External integration > Company directory.
- Click
> LDAP connection.
- In the Directory connection name field, type a name for the directory connection.
- In the LDAP server discovery drop-down list, do one of the following:
- To automatically discover the LDAP server, click Automatic. In the DNS domain name field, type the domain name for the server that hosts the company directory.
- To specify a list of LDAP servers, click Select server from list below. In the LDAP server field, type the name of the LDAP server. To add more LDAP servers, click
.
- In the Enable SSL drop-down list, perform one of the following actions:
- If the LDAP connection is SSL encrypted, click Yes. Beside the LDAP server SSL certificate field, click Browse and select the LDAP server certificate.
- If the LDAP connection is not SSL encrypted, click No.
- In the LDAP port field, type the TCP port number for communication. The default values are 636 for SSL enabled or 389 for SSL disabled.
- In the Authorization required drop-down list, do one of the following:
- If authorization is required for the connection, click Yes. In the Login field, type the DN of the user that is authorized to log in to LDAP (for example, an=admin,o=Org1). In the Password field, type the password.
- If authorization is not required for the connection, click No.
- In the User search base field, type the value to use as the base DN for user information searches.
- In the LDAP user search filter field, type the LDAP search filter that is required to find user objects in your organization's directory server. For example, for an IBM Domino Directory, type (objectClass=Person).
- In the LDAP user search scope drop-down list, do one of the following:
- To search all objects following the base object, click All levels. This is the default setting.
- To search objects that are one level directly following the base DN, click One level.
- In the Unique identifier field, type the name of the attribute that uniquely identifies each user in your organization's LDAP directory (must be a string that is immutable and globally unique). For example, dominoUNID.
- In the First name field, type the attribute for each user’s first name (for example, givenName).
- In the Last name field, type the attribute for each user’s last name (for example, sn).
- In the Login attribute field, type the login attribute to use for authentication (for example, uid).
- In the Email address field, type the attribute for each user's email address (for example, mail). If you do not set the value, a default value is used.
- In the Display name field, type the attribute for each user's display name (for example, displayName). If you do not set the value, a default value is used.
- In the User Principal Name field, type the user principal name for SCEP (for example, mail).
- If you are using the LDAP directory configuration to connect to Active Directory, and if you want to use SCEP profiles to distribute user credential certificates to devices, in the User Security Identifier field, you must enter the following: objectSid
- In the Department field, type the attribute for each user's department.
- In the Job Title field, type the attribute for each user's job title.
- If you want to synchronize additional fields from the LDAP directory, select the Synchronize additional user details check box. Type the attributes for the additional fields as necessary.
- To enable directory-linked groups for the directory connection, select the Enable directory-linked groups check box.
- In the Group search base field, type the value to use as the base DN for group information searches.
- In the LDAP group search filter field, type the LDAP search filter that is required to find group objects in your company directory. For example, for IBM Domino Directory, type (objectClass=dominoGroup).
- In the Group Unique Identifier field, type the attribute for each group's unique identifier. This attribute must be immutable and globally unique (for example, type cn).
- In the Group Display name field, type the attribute for each group's display name (for example, type cn).
- In the Group Membership attribute field, type the name of the attribute for group membership. The attribute values must be in DN format (for example, CN=jsmith,CN=Users,DC=example,DC=com).
- In the Test Group Name field, type an existing group name for validating the group attributes specified.
- If you want to enable paged searching for group members, select the Enable paged group search check box.
- Click Save.
- Click Close.
- Do any of the following optional tasks:
- If you want to remove a directory connection, you must first remove all of the associated directory users and directory-linked groups from UEM.