Specifications

Active Directory ShoreWare Server Release Notes
Page 66
LDAP-GUID: Used internally by the ShoreTel system when performing subsequent user
updates from the AD database.
Authenticating AD Users
ShoreTel supports AD authentication for users logging into Call Manager, Web Client, and
Director, permitting access to these programs without providing the ShoreWare username
or password.
AD Users logging into Director and Call Manager are authenticated through Single Sign
On (SSO) with their current network credentials. Users are not required to re-enter
their credentials to access these applications.
AD users logging into Web Client are authenticated through Explicit Authentication,
which requires re-entry of their credentials each time they access the application.
Director
When AD Integration is enabled, user access to ShoreWare Director is restricted as follows:
only users with a domain account can log into Director
only users with administrative permissions can log into Director
users do not need to be logged into their domain account to access Director
users do not need their ShoreTel account configured for Active Directory (AD Users) to
access Director
The following sections describe Director access scenarios.
AD User Logged into the Domain
Users configured for AD within ShoreWare that are logged into the domain network are
directed to the Director Quick Look panel when they attempt to access Director without
entering their network credentials.
Upon logging off from Director, the browser displays a ShoreWare entry panel that allows
Director access by pressing a button, as shown in Figure 25.
Figure 25 Director Login panel – AD user