---
title: Active Directory Integration
slug: portal-sub/active-directory-integration
docTags: 
createdAt: 2026-03-04T12:03:15.468Z
---

# Overview & Requirements

Profile provides two integration options with Active Directory (AD), both for AD user management and authentication, as well as Single Sign On (separately). This technical document is intended for audiences familiar with Active Directories and Systems Administration.

AD integration allows:

- Management of access to the product in AD by creating and deactivating accounts in AD
- Two modes for storing passwords: having them synchronized with AD or stored in AD only
- Externalization of authentication as, in the second mode, user validation is performed only by AD
- Logging in as an application user using your preserved solution account and password

## Requirements

- Profile v8.4 and higher
- Windows Server 2003 and higher

# Active Directory Integration

## Integration Process Overview

1. Application Users are managed by AD.
2. Profile server login window expects AD credentials, i.e., AD username and AD password.
3. Profile sends entered username and password to IHServer.
4. IHServer validates entered credentials with AD.

As a result, IHServer has an active connection with the AD server:

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/PPo95Ie0fC-T9mFIUXBXb_anc4zkxrlyy8e8c1o9i2v95ulmxj38gr8g.png" size="75" isUploading="false" initialPath="assets/Anc4zkxRLyy8e8c1O9i2v95UlmxJ38gR8g.png" githubPath="en/General Settings and Configuration/Single Sign-On/Active Directory Integration/assets/Anc4zkxRLyy8e8c1O9i2v95UlmxJ38gR8g.png" position="flex-start" showCaption="false"}

## AD Integration Setup

### Overview

-  On the Profile side, set up the Domain Account used to access AD in Integration Preferences.
-  On the AD side, set up Local Group Policy for the domain, such as the Password policy and the Lockout policy.
-  On the AD side, create AD users in the domain.
-  On the Profile side, allow Domain Authorization to a user.
-  On the Profile side, log in using Domain Authorization. Upon successful AD login, the Application User is automatically created if it does not exist, and the appropriate integration preference is on.

### Integration Preferences

A dedicated CN (Common Name) or OU (Organizational Unit) is recommended.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/LzyJZlt-IBWR7xcS0vu8c_zu2h3pqnaer0qunootsp77yxj55a1vvblw.png" size="56" isUploading="false" initialPath="assets/Zu2H3PqNAER0QunooTsP77YxJ55A1Vvblw.png" githubPath="en/General Settings and Configuration/Single Sign-On/Active Directory Integration/assets/Zu2H3PqNAER0QunooTsP77YxJ55A1Vvblw.png" position="flex-start" showCaption="false"}

1. Go to **Organization/Preferences/Technical/Integration/Environment&#xA0;**&#x74;ab.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/jqw7cCrppXkxPOvX2tkaC_00o9-1ixxx8lm0rlnyhzgy8-ttbhf-sjg.png" size="88" isUploading="false" initialPath="assets/00o9-_1iXxx8lm0RLnYHZgy8-ttbHf-Sjg.png" githubPath="en/General Settings and Configuration/Single Sign-On/Active Directory Integration/assets/00o9-_1iXxx8lm0RLnYHZgy8-ttbHf-Sjg.png" position="flex-start" showCaption="false" indent="2"}

2. In the **Login with&#xA0;**&#x64;ropdown field, select **Windows Domain Authorization**. This enables the following relevant checkboxes and fields.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/IoKZOJkFAUij6tWePPHLA_s4axz8yx5y3twmjp2xxvvkohmp-mpqnzg.png" size="85" isUploading="false" initialPath="assets/S4aXz8yx5Y3TWM_jP2xxvVkOHMp-mpqnZg.png" githubPath="en/General Settings and Configuration/Single Sign-On/Active Directory Integration/assets/S4aXz8yx5Y3TWM_jP2xxvVkOHMp-mpqnZg.png" position="flex-start" showCaption="false" indent="2"}

3. Enter the domain username in the **Username&#xA0;**&#x66;ield. See example in the above screenshot.
4. Enter the domain password in the **Password&#xA0;**&#x66;ield.
5. In the **Base DN field**, enter something similar to:

```javascript
LDAP://OU=<Directory where the user from step 3 is located in the AD>, DC=<domain1>, DC=<Domain2>, DC=<Domain3>
```

## Additional Settings

- If the **Create Application User on successful AD logon** checkbox is checked, then the Application Users are automatically created when logon is successfully authenticated by AD. In such a case, the Application User properties are automatically filled from the AD user attributes.

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/7nw6uX2s50oW6Qa0vBhvU_1ke60fookrva1dqg-xotonzf9rot6kcg.png" size="50" isUploading="false" initialPath="assets/1kE60F_oOkrVA1DQg-xoTON_ZF9ROt6kcg.png" githubPath="en/General Settings and Configuration/Single Sign-On/Active Directory Integration/assets/1kE60F_oOkrVA1DQg-xoTON_ZF9ROt6kcg.png" position="flex-start" showCaption="false" indent="2"}

- If the **Create/update AD user on creating/updating Application User** checkbox is checked, then after creating a user in Profile, the AD user is automatically created, and properties are copied from the Application User.
- If the **Do not store user passwords in the database&#xA0;**&#x63;heckbox is checked, then passwords are stored in AD only.
- The **Allow Bypass of Logon Challenge&#xA0;**&#x63;heckbox simplifies the process of AD integration:
  - Application Users are managed by Profile
  - Profile client should be started with /DOMAIN\_LOGON switch (e.g., Profile.exe -domain logonserver=smith.msq.intrahealth.local).
  - Profile sends current AD user SID to IH Server.
  - This setting enables a ‘soft’ security mode where the Profile client automatically signs in on startup without a logon challenge. There is no connection to AD Server in the process at all. The logon is authorized if the SID is found in the local database. There is no password check. It is a manual process to maintain Profile user to AD user mapping.

:::hint{type="info"}
**Note: This might be convenient for small practices, but it is not recommended for Enterprise setup.**

:::

![](https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/I8wVXmn847KJe6iaud8qp_wvwawjvt7ewkgoel4nlb3dl5c51av7mya.png)

## User Domain Authorization

1. Go to **Organization/People & Places**. 
2. Double-click on a user to edit their profile. 
3. Go to the **Special&#xA0;**&#x76;iew. 

![](https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/zMsgFcuWY_tHB5dTv4IFa_ga5b64s5tpwgjiztfehmvimizuyyyo63w.png)

4. Check the **Domain Account** checkbox. 
5. Enter the user domain account in the **Domain Account** field.  

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/6GR1yhNb6i9cPXgLgtmcX_z2goean5evons7vvrhctp8gfvd5ytgeyq.png" size="46" isUploading="false" initialPath="assets/Z2GoeaN5_evOns7vvrhCTP8gFvD5YTGeYQ.png" githubPath="en/General Settings and Configuration/Single Sign-On/Active Directory Integration/assets/Z2GoeaN5_evOns7vvrhCTP8gFvD5YTGeYQ.png" position="flex-start" showCaption="false"}

6. Press

::Image[]{src="https://api.qa.archbee.co/api/optimize/zICxj0dnLereb6UUrBA3-/cf5n9jI-qMkPNot-PWs7w_nza0axoucc9fkghdcxqqsestmwnlanejbw.png" size="11" isUploading="false" initialPath="assets/NzA0axoucC9FKGhdCxQqseStMwNlaNejBw.png" githubPath="en/General Settings and Configuration/Single Sign-On/Active Directory Integration/assets/NzA0axoucC9FKGhdCxQqseStMwNlaNejBw.png" position="flex-start" showCaption="false" indent="2"}

:::Paragraph{indent="1"}
 to save the information and close the User profile window.
:::
