The Active Directory connector manages Microsoft AD users and groups over LDAP/LDAPS from an on-prem Nodlyn host.
Capabilities
- Search users and groups, inspect group membership, and authenticate an identity.
- Create, update, move, enable, disable, and assign users to groups.
- Use Active Directory User Changed or Group Changed to poll
whenChanged.
Security
Use a least-privilege service account. Password writes and user creation require LDAPS; use port 636 or enable SSL.
On-prem execution
AD capabilities are not cloud-compatible. Run them on an API host or Runtime Agent with domain controller connectivity.