Active Directory Integration
10 min
overview & requirements profile provides two integration options with active directory (ad), both for ad user management and authentication, as well as single sign on (separately) this technical document is intended for audiences familiar with active directories and systems administration ad integration allows management of access to the product in ad by creating and deactivating accounts in ad two modes for storing passwords having them synchronized with ad or stored in ad only externalization of authentication as, in the second mode, user validation is performed only by ad logging in as an application user using your preserved solution account and password requirements profile v8 4 and higher windows server 2003 and higher active directory integration integration process overview application users are managed by ad profile server login window expects ad credentials, i e , ad username and ad password profile sends entered username and password to ihserver ihserver validates entered credentials with ad as a result, ihserver has an active connection with the ad server ad integration setup overview on the profile side, set up the domain account used to access ad in integration preferences on the ad side, set up local group policy for the domain, such as the password policy and the lockout policy on the ad side, create ad users in the domain on the profile side, allow domain authorization to a user on the profile side, log in using domain authorization upon successful ad login, the application user is automatically created if it does not exist, and the appropriate integration preference is on integration preferences a dedicated cn (common name) or ou (organizational unit) is recommended go to organization/preferences/technical/integration/environment tab in the login with dropdown field, select windows domain authorization this enables the following relevant checkboxes and fields enter the domain username in the username field see example in the above screenshot enter the domain password in the password field in the base dn field , enter something similar to ldap //ou=\<directory where the user from step 3 is located in the ad>, dc=\<domain1>, dc=\<domain2>, dc=\<domain3> additional settings if the create application user on successful ad logon checkbox is checked, then the application users are automatically created when logon is successfully authenticated by ad in such a case, the application user properties are automatically filled from the ad user attributes if the create/update ad user on creating/updating application user checkbox is checked, then after creating a user in profile, the ad user is automatically created, and properties are copied from the application user if the do not store user passwords in the database checkbox is checked, then passwords are stored in ad only the allow bypass of logon challenge checkbox simplifies the process of ad integration application users are managed by profile profile client should be started with /domain logon switch (e g , profile exe domain logonserver=smith msq intrahealth local) profile sends current ad user sid to ih server this setting enables a ‘soft’ security mode where the profile client automatically signs in on startup without a logon challenge there is no connection to ad server in the process at all the logon is authorized if the sid is found in the local database there is no password check it is a manual process to maintain profile user to ad user mapping note this might be convenient for small practices, but it is not recommended for enterprise setup user domain authorization go to organization/people & places double click on a user to edit their profile go to the special view check the domain account checkbox enter the user domain account in the domain account field press to save the information and close the user profile window