To specify an Active Directory/LDAP Server/Microsoft Entra ID as an additional authentication device, you must register the information of the server used for authentication. Conduct a connection test as necessary. |
1 | Select the check box for [Use Active Directory] and select [Set Manually] for [Set Domain List:]. |
2 | Click [Active Directory Management...] [OK]. |
3 | Click [Add Domain...]. |
4 | Enter the necessary information. [Domain Name:] Enter the domain name of the Active Directory that is the login destination (Example: company.domain.com). [NetBIOS Name] Enter the NetBIOS domain name (Example: company). [Primary Host Name or IP Address:] / [Secondary Host Name or IP Address:] Enter the host name of the Active Directory server or the IPv4 address. When using a secondary server, specify the name in [Secondary Host Name or IP Address:]. Example: Using a host name: ad-server1 Using an IPv4 address: 192.168.18.138 [User Name:] / [Password:] Enter the user name and password to use for accessing and searching the Active Directory server. [Starting Point for Search:] Specify the location (level) to access and search for user information during Active Directory Server authentication. [Login Name:] / [Displayed As] / [E-Mail Address] Specify the data fields (attribute names) for the login name, display name, and e-mail address of each user account on the Active Directory server (Example: sAMAccountName, cn, mail). |
5 | Click [Connection Test] to confirm that connection is possible, and then click [Add]. To edit server information Click [Edit] for the server information that you want to edit, make the necessary changes, and click [Update]. |
1 | Select the check box for [Use LDAP server] and click [LDAP Server Management...] [OK]. |
2 | Click [Add Server...]. |
3 | Enter the LDAP server information. [Server Name] Enter the name for the LDAP server. The name "localhost" cannot be used. The server name may not include spaces. [Primary Address] Enter the IP address or host name of the LDAP server (Example: ldap.example.com). The loopback address (127.0.0.1) cannot be used. [Port:] Enter the port number used for communicating with the LDAP server. Use the same setting that is configured on the server. If you do not enter a number, it is automatically set to "636" when the check box is selected for [Use TLS], or it is set to "389" when the check box is cleared. [Secondary Address:] / [Port:] When using a secondary server in your environment, enter the IP address and the port number. [Comments] Enter a description or note as necessary. [Use TLS] Select the check box when using TLS encryption for communications with the LDAP server. [Use authentication information] Clear the check box to allow anonymous access to the LDAP server, only if the LDAP server is set to allow anonymous access. When using the user name and password for authentication, select the check box and enter values for [User Name:] and [Password:]. If this check box is selected, when you want to change the settings in <Primary Address> or <Secondary Address> of an LDAP server, entering the password specified in <Password:> in <Use authentication information> is required. [Starting Point for Search:] Specify the location (level) to search for user information when LDAP server authentication is performed. |
4 | Specify how to set the attribute names and domain name. [User Name (Keyboard Authentication):] Specify the LDAP data field (attribute name) for the user name on the LDAP server (Example: uid). [Login Name:] / [Display Name] / [E-Mail Address] Specify the LDAP data fields (attribute names) for the login name, display name, and e-mail address of each user account on the LDAP server (Example: uid, cn, mail). [Specify the domain name] / [Specify the attribute name for domain name acquisition] Select how to set the domain name of the login destination. To specify the domain name directly, select [Specify the domain name] and enter the domain name. To specify an LDAP data field (attribute name) from which to acquire the domain name on the LDAP server, select [Specify the attribute name for domain name acquisition] and enter the attribute name (Example: dc). |
5 | Click [Connection Test] to confirm that connection is possible, and then click [Add]. |
1 | Select the [Use Microsoft Entra ID] checkbox. | ||
2 | Click [Domain Settings]. The [Microsoft Entra ID Domain Settings] screen is displayed. | ||
3 | Specify the Microsoft Entra ID information. [Login Destination Name] Enter the name to be displayed at the login destination. * You cannot use control characters or spaces. [Domain Name] Enter the domain name of the Microsoft Entra ID that is the login destination. [Application ID] Enter the application (client) ID. [Secret] Enter the secret generated by Microsoft Entra ID. You do not need to enter this when [Key and Certificate] is used. [Key and Certificate] Press [Key and Certificate] when you use a key and certificate. You can press [Export Certificate] to export the certificate to be registered to Microsoft Entra ID. [Microsoft Entra ID Authentication URL] and[Microsoft Entra ID API URL] Enter the URLs. Depending on your cloud environment, you may need to change the settings. | ||
4 | Specify the attributes. [Login Name] From the pulldown menu, select the attribute for the login name of each user account on the server. *To specify an attribute not displayed in the pulldown menu, you can enter it directly. [WindowsLogonName]: displayName is obtained from Microsoft Entra ID. displayName is changed as follows to create the login name:
[displayName]: displayName obtained from Microsoft Entra ID becomes the login name. [userPrincipalName]: userPrincipalName obtained from Microsoft Entra ID becomes the login name. [userPrincipalName-Prefix]: The portion before "@" in userPrincipalName obtained from Microsoft Entra ID becomes the login name. Example: When userPrincipalName is "user.002@mail.test," the login name becomes "user.002." [Display Name] and [E-Mail Address] Enter the attributes for the display name and e-mail address of each user account on the server. | ||
5 | Specify the domain name of the login destination in [Domain Name] under [Domain Name to Set for Login Account]. | ||
6 | Specify the settings in [Autocomplete for Entering User Name When Using Keyboard Authentication] under [Domain Name to Autocomplete]. Enter the name of the domain for which to perform autocomplete. Normally, set the same name as entered in [Domain Name]. | ||
7 | Click [Connection Test] to test the connection. | ||
8 | Click [Update]. The screen returns to the [Edit Server Settings] screen. |
[Search Criteria] | Select the search criteria for [Character String]. |
[Character String] | Enter the character string that is registered to the attribute specified in [User Attribute to Browse:]. To set the privileges based on the group that user belongs to, enter the group name. |
[Role] | Select the privileges that apply to users who match the criteria. |
1 | In the navigation menu, click [App registrations] > [New registration]. |
2 | Enter the name of the application. You can enter any name. Input example: Canon <printer name> Login |
3 | Select the type of account, and click [Register]. The application (client) ID is generated. Make a note of the generated ID. |
1 | In the navigation menu, click [Certificates & secrets]. |
2 | Click [New client secret]. |
3 | In the [Add a client secret] dialog box, enter the description and expiry date, and click [Add]. A secret ID and value are created. Make a note of the created secret value. You do not need the secret ID. * The secret value is only displayed once. If you are unable to make a note of the value, create a new client secret. |
1 | In the navigation menu, click [Certificates & secrets]. |
2 | Click [Upload certificate]. |
3 | Select the file, and click [Add]. After the certificate is uploaded, make a note of the Thumbprint value. |