Installation manual
TECHNICAL TIP TT- 20352
2 OF 46
Integrating Sharp MFP User Control
with Active Directory User Attributes
A feature has been added to the newest Sharp products that allow the MFP User Control Function to
integrate with Windows Active Directory User Attributes. This feature is called LDAP Server Access
Control and it permits controlling network users in the same manner as users created locally on the
MFP. The Page Limit Group, Authority Group and Favorite Operation Group can each be applied to
network users when they log into the MFP.
Page Limit Group - Limits the number of prints, scans and copies the user can make.
Authority Group – Controls what functions the user can access on the MFP.
Favorite Operation Group – Customizes the MFP display presented to the user on login.
Currently, the Sharp MX-4100/4101/5001, MX-M283/363/453/503, MX-M623/753, MX-3110/3610 and
MX-4110/5111 series support the LDAP Server Access Control feature.
The following diagram shows the relationship between active directory user attributes and the MFP
custom LDAP server Linkage with User Control Function field values. The default values of these fields
on the MFP are: Page Limit Group = pagelimit; Authority Group = authority and Favorite Operation
Group = favorite.
If these default values were used, new attributes with corresponding names would have to be created
in Active Directory by the domain administrator by extending the schema. This is a complex procedure
rarely undertaken even by domain administrators. However, by utilizing unused user attributes with a
custom LDAP server setup on the MFP, no additional effort is required by the administrator to
incorporate this feature. Changes would only need to be made on the MFP where the default values of
the fields are replaced by the desired unused attributes of the user in active directory as shown below.
In the above case, attributes from the Telephones tab of the user properties are used as links to the
MFP user control function fields. The Page Limit Group field is set to homePhone, Authority Group is
set to pager and Favorite Operation Group is set to ipPhone on the MFP.
(Note: The attribute names are case sensitive and are not the same as the displayed names.)










