Administration
LDAP settings
Synchronization
6 min
synchronization is only available in the passwork advanced license passwork supports synchronization of security groups from external directories, such as active directory and openldap, with groups in passwork this enables centralized access management through the existing directory infrastructure the following types of domains are supported in passwork for access management windows domains (based on active directory); linux domains (openldap, freeipa, and others) the synchronization process consists of the following steps an ldap request is executed based on the data specified in the users tab passwork retrieves a list of users, each including a memberof array with group membership information another ldap request is executed based on the data specified in the groups tab passwork retrieves a list of ldap groups passwork generates a list of ldap groups that are mapped to passwork groups the mapped passwork groups are compared against the combined memberof arrays of all users if matches are found, passwork assigns the corresponding groups to the users if the automatically create new users from mapped ldap groups option is enabled, passwork checks whether each matched user is already registered if not, the user is registered automatically if the automatically deactivate users not included into any mapped ldap group option is enabled, passwork verifies whether each user still belongs to the mapped ldap groups users not belonging to those groups are automatically deactivated dn filters can be used to retrieve nested groups or users nested objects will be displayed; however, group restrictions and mappings do not apply to nested groups to map passwork groups to security groups, select a security group from the list and click the button located on the right side in the dialog that appears, select the desired groups and save the configuration for synchronization to function correctly, background tasks docid\ yfbv3nwxjyj7casf5uhii must be configured synchronization settings the synchronization settings allow the following automatically deactivate users who are not members of ldap groups mapped to groups in passwork automatically register new users from ldap groups define the default authentication method to be assigned to users from ldap set the interval for ldap synchronization synchronization log passwork stores synchronization logs as part of the background task execution history to view the synchronization log, click the go to all logs button at the bottom of the synchronization tab, or apply the ldap synchronization filter on the tasks tab in the background tasks section