Configure LDAP authentication

Perform this task to manage LDAP servers and synchronization settings. An authentication server manages and verifies user accounts. Synchronization settings are used for synchronizing OU configuration from authentication servers after authentication servers are configured.

Configure authentication servers

About this task

An authentication server manages and validates user accounts. The system supports the following types of authentication servers:

Application scenarios

Authentication servers are applicable to scenarios with high network security and unified user management.

Configuration workflow

  1. Create an authentication server—Associate the actual deployed authentication servers with Space Console.

  1. Synchronize OU configurations immediately—Synchronize user information from the authentication server.

Prerequisites

Deploy Microsoft AD or generic LDAP servers on the network and configure users on the servers.

Restrictions and guidelines

For domain users that use cloud desktops in a desktop pool to be added to a domain, assign the desktop pool to domain users and specify an OU for the pool. Local LDAP users are not required to join a domain.

Authentication servers of type Microsoft AD are not supported by the ARM architecture.

Create an authentication server

·          The system supports multiple Microsoft AD servers and generic LDAP servers.

·          If an authentication server is specified by its domain name, the cloud disk feature cannot synchronize domain configuration with the authentication server.

 

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Click Create Authentication Server.

  1. Configure the authentication server parameters as described in "Parameters."

  1. Click Connectivity Test to verify that the server is reachable.

  1. Click Save.

Parameters

After you enable trust domain configuration for an authentication server, and configure Mutual Trust or One-Way Trust for the authentication server, desktops can be assigned to the trust domain.

Edit an authentication server

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Click Edit from the Actions column of an authentication server, and edit parameters as described in "Parameters."

  1. Click Connectivity Test to verify that the server is reachable.

  1. Click Save.

Delete an authentication server

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Click Delete from the Actions column of an authentication server to be deleted.

  1. In the dialog box that opens, click OK.

Synchronize all OUs immediately

Perform this task to synchronize OUs on all servers in the list. If a user with the same login name exists on a generic LDAP authentication server, you must modify the login name before synchronizing all OUs.

To immediately synchronize OUs:

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Click Sync OUs Now.

Synchronize OUs on schedule

Perform this task to set the time for periodically synchronizing all OUs on authentication servers.

To synchronize OUs on schedule:

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Click Scheduled OU Sync.

  1. In the dialog box that opens, set the execution time, and click OK.

Synchronize OU configurations

Perform this task to synchronize OU configuration information from authentication servers after authentication servers are configured. An OU is a container that you use to organize objects, such as user accounts, groups, computers, printers, applications, files, and other OUs.

Restrictions and guidelines

After you synchronize OU configurations from authentication servers to Space Console, user accounts on the authentication servers are synchronized. To use the user accounts to log in to teacher or student clients or campus space in education scenario, you must first change the type of the users to Teaching Staff or Student. For more information about how to change the user type, see the guide for AD users, AD user groups, LDAP users, or LDAP user groups.

Create an OU configuration

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Select an authentication server to add synchronization settings, and click Create.

  1. Configure the name of the OU configuration, and select a subdomain base DN.

  1. Select Synchronize to LDAP Server.

  1. Click OK.

Synchronize OU configurations immediately

About this task

Perform this task to synchronize OU configuration information (such as user accounts in OUs) from the selected authentication servers immediately. After synchronization finishes, you need to refresh the page. If a user with the same login name exists on a generic LDAP authentication server, you must modify the login name before synchronizing all OU configurations.

Procedure

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Select an authentication server to synchronize OU configurations, and click Sync Now.

  1. Synchronize OU configurations by using one of the following methods:

Edit an OU configuration

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Click Edit from the Actions column of an OU configuration in the OU configuration list.

  1. In the dialog box that opens, edit the name and subdomain base DN.

  1. Click OK.

Delete an OU configuration

  1. From the left navigation pane, select Users > Auth Collaboration > Primary Auth > LDAP Auth.

  1. Click Delete from the Actions column of an OU configuration in the OU configuration list. Deleting an OU configuration will delete all users and user groups in the OU.

  1. In the dialog box that opens, click OK.