Reference Guide
■ Object Class: user
■ Search Path: cn=Users,dc=<domain>
○ Group Search Settings:
■ Member Attribute: member
■ ID Attribute: cn
■ Object Class: group
■ Search Path: cn=Users,dc=<domain>
■ Search Level:
● Active Directory - Global Catalog server
○ User Search Settings:
■ ID Attribute: UserPrincipalName
■ Object Class: user
■ Search Path: (greyed out)
○ Group Search Settings:
■ Member Attribute: member
■ ID Attribute: cn
■
Object Class: group
■ Search Path: (greyed out)
■ Search Level:
● OpenLDAP server
○ User Search Settings:
■ ID Attribute: uid
■ Object Class: inetOrgPerson
■ Search Path:
○ Group Search Settings:
■ Member Attribute: member
■ ID Attribute: cn
■ Object Class: groupOfNames
■ Search Path:
■ Search Level:
13. Update the search paths or other fields as necessary, then click Apply to save the advanced configuration changes.
For example, if you are configuring forest-level authentication, specify userPrincipalName in the ID Attribute field. If
the LDAP server has a different search path than the default (cn=Users,dc= ) for either users, groups, or both, update the
search paths or other properties as necessary.
14. After all the LDAP configuration information is specified, click Apply to save the configuration.
Next steps
After the LDAP server configuration is saved and to avoid the possibility of data being unavailable, you must verify the
configuration to confirm that the connections to the LDAP server will be successful.
Verify LDAP configuration
About this task
NOTE:
To avoid the possibility of data being unavailable, you must verify the LDAP connection after every LDAP
configuration change.
Directory Services 45










