To specify an Active Directory, Microsoft Entra ID or LDAP server as an additional authentication device, you must register the information ofthe server used for authentication. Conduct a connection test as necessary. |
1 | Select the check box for [Use Active Directory] and select [Set Manually] for [Set Domain List:]. |
2 | Click [Active Directory Management...] [OK]. |
3 | Click [Add Domain...]. |
4 | Enter the necessary information. [Domain Name:] Enter the domain name of the Active Directory that is the login destination (Example: company.domain.com). [NetBIOS Name] Enter the NetBIOS domain name (Example: company). [Primary Host Name:] / [Secondary Host Name] Enter the host name of the Active Directory server or the IPv4 address. When using a secondary server, specify the name in [Secondary Host Name]. Example: Using a host name: ad-server1 Using an IPv4 address: 192.168.18.138 [User Name:] / [Password:] Enter the user name and password to use for accessing and searching the Active Directory server. [Starting Point for Search:] Specify the location to access and search in the Active Directory Server. [Login Name:] / [Displayed As] / [E-Mail Address] Specify the data fields (attribute names) for the login name, display name, and e-mail address of each user account on the Active Directory server (Example: sAMAccountName, cn, mail). |
5 | Click [Test Connection] to confirm that connection is possible, and then click [Add]. To edit server information Click [Edit] for the server information that you want to edit, make the necessary changes, and click [Update]. |
1 | Select the check box for [Use LDAP server] and click [LDAP Server Management...] [OK]. |
2 | Click [Add Server...]. |
3 | Enter the LDAP server information. [Server Name] Enter the name for the LDAP server. The name "localhost" cannot be used. The server name may not include spaces. [Primary Address] Enter the IP address or host name of the LDAP server (Example: ldap.example.com). The loopback address (127.0.0.1) cannot be used. [Port:] Enter the port number used for communicating with the LDAP server. Use the same setting that is configured on the server. If you do not enter a number, it is automatically set to "636" when the check box is selected for [Use TLS], or it is set to "389" when the check box is cleared. [Secondary Address:] / [Port:] When using a secondary server in your environment, enter the IP address and the port number. [Comments] Enter a description or note as necessary. [Use TLS] Select the check box when using TLS encryption for communications with the LDAP server. [Use authentication information] Clear the check box to allow anonymous access to the LDAP server, only if the LDAP server is set to allow anonymous access. When using the user name and password for authentication, select the check box and enter values for [User Name:] and [Password:]. If this check box is selected, when you want to change the settings in [Primary Address] or [Secondary Address:] of an LDAP server, entering the password specified in [Password:] in [Use authentication information] is required. [Starting Point for Search:] Specify the location (level) to search for user information when LDAP server authentication is performed. |
4 | Specify how to set the attribute names and domain name. [User Name (Keyboard Authentication):] Specify the LDAP data field (attribute name) for the user name on the LDAP server (Example: uid). [Login Name:] / [Display Name] / [E-Mail Address] Specify the LDAP data fields (attribute names) for the login name, display name, and e-mail address of each user account on the LDAP server (Example: uid, cn, mail). [Specify the domain name] / [Specify the attribute name for domain name acquisition] Select how to set the domain name of the login destination. To specify the domain name directly, select [Specify the domain name] and enter the domain name. To specify an LDAP data field (attribute name) from which to acquire the domain name on the LDAP server, select [Specify the attribute name for domain name acquisition] and enter the attribute name (Example: dc). |
5 | Click [Test Connection] to confirm that connection is possible, and then click [Add]. |
1 | Select the check box for [Use Microsoft Entra ID] and click [Domain Settings] [OK]. |
2 | Enter the necessary information. [Login Destination Name:] Enter the display name for the login destination. Default value:Microsoft Entra ID [Domain Name:] Enter the domain name of Microsoft Entra ID that is the login destination. [Application ID:] Enter the application ID (client). [Secret:] Enter the secret issued on Microsoft Entra ID. When you use [Key and Certificate], it is not necessary to enter here. [Key and Certificate] Click [Key and Certificate] when you use a key and a certificate. By clicking [Export Certificate], you can export the certificate that is registered to Microsoft Entra ID. [Microsoft Entra ID Authentication URL] / [Microsoft Entra ID API URL] Enter the URL. Depending on your cloud environment, it may be necessary to modify the URL. Click [Restore Initial Settings] to restore the URL of [Microsoft Entra ID Authentication URL] / [Microsoft Entra ID API URL] to the default value. Default value: [Microsoft Entra ID Authentication URL]: https://login.microsoftonline.com [Microsoft Entra ID API URL]: https://graph.microsoft.com [Login Name:] / [Display Name:] / [E-Mail Address:] Enter the data field (attribute) names to which a login name, display name, and e-mail address of each user account are registered on an Microsoft Entra ID server. Default value: WindowsLogonName, displayName, mail Example: userPrincipalName, displayName, mail [Domain Name:] Under most circumstances, you do not need to change the setting. Default value: AzureAD [Domain Name to Autocomplete:] Enter the domain name that is entered automatically. You do not have to enter the domain name after @ by yourself. |
3 | Click [Test Connection], confirm that the connection is established, and click [Update]. |
[Search Criteria] | Select the search criteria for [Character String]. |
[Character String] | Enter the character string that is registered to the attribute specified in [User Attribute to Browse:]. To set the privileges based on the group that user belongs to, enter the group name. |
[Role] | Select the privileges that apply to users who match the criteria. |
DNS SettingsThe following settings are required if the port number used for Kerberos on the Active Directory side is changed. Information for the Kerberos service of Active Directory must be registered as an SRV record as follows: Service: "_kerberos" Protocol: "_udp" Port number: The port number used by the Kerberos service of the Active Directory domain (zone) Host offering this service: Host name of the domain controller that is actually providing the Kerberos service of the Active Directory domain (zone) |