> For the complete documentation index, see [llms.txt](https://docs.pascom.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pascom.net/en/integrations/connector/user-active-directory.md).

# Users from Microsoft Active Directory

User Synchronisation and Authentication with Microsoft Active Directory

<figure><img src="https://2713225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVIw0BpSv358R2Pr2HflD%2Fuploads%2Fgit-blob-56d9849bfa54da2e6b31eda92eb28fc5a0f980ca%2Fconnector_microsoft_ad.png?alt=media" alt="microsoft active directory" width="50%"><figcaption></figcaption></figure>

## Microsoft Active Directory

In order to be able to read data from Active Directory, you require a user with the appropriate permissions. You could use the Active Directory Administrator for this purpose. However, as the PASCOM cloud phone system needs to save the access credentials for the automated future imports and the the administrator as significantly more than the required permissions, it is advisable to create a user account for the PASCOM PBX:

If you use *mobydick* as the username, this will be automatically detected by the LDAP filter during the import process and will not be automatically added as a PASCOM cloud phone system user.

Assign a password for the PASCOM user and select *password never expires*. The PASCOM PBX can then authenticate itself by the Active Directory with every execution of the connector sync. If you wish to change this password, you must change the password in both Active Directory and within the PASCOM connector profile:

## "Users from AD" Connector Profile

Create a new connector profile by using the following steps in the PASCOM cloud phone system Web UI: Click on the menu option **Settings** > **Connector** and then click **Add**.

Select the *AD User Sync* template and enter the following data:

| Field                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Name**                      | Connector Profile Name                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **AD Domain**                 | Active Directory Domain Name                                                                                                                                                                                                                                                                                                                                                                                                            |
| **AD Server**                 | Server IP or Host DNS Name                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Username** and **Password** | Credentials of the previously added PASCOM User for authentication                                                                                                                                                                                                                                                                                                                                                                      |
| **Configure authentication**  | <p><strong>NO</strong>: Users will only be imported. Authentication will be performed by the PASCOM cloud phone system.<br><strong>YES</strong>: Users will be imported and the can be authenticated against the AD. In this case, the authentification will be setup and you can modify this according to your needs under <strong>Appliance</strong> > <strong>Services</strong> under the tab <strong>Authentification</strong>.</p> |
| **Create PASCOM softphone**   | **YES**: Creates a PASCOM softphone for every imported user. **NO**: No PASCOM softphones will be added for imported users.                                                                                                                                                                                                                                                                                                             |
| **Create mobile phone**       | **YES**: Creates a mobile phone device for every imported user. **NO**: No mobile devices will be added for imported users.                                                                                                                                                                                                                                                                                                             |

After saving, the template can be modified according to requirements under the tab **Basic Data**.

**Use multiple LDAP URIs from your authentication servers**.

Click **Appliance** > **Services** from the menu and go to the **Authentication** tab. Here you can specify multiple LDAP(S) URIs, which are separated by a space. If one LDAP server fails, we simply use the second server entered.

<figure><img src="https://2713225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVIw0BpSv358R2Pr2HflD%2Fuploads%2Fgit-blob-5e3dc07adad0058300e227da60e17fdbd16da427%2Fmultiple-ldap-uris.png?alt=media" alt="Use multiple LDAP URIs" width="80%"><figcaption></figcaption></figure>

### Pre Filter

Per default, the template will import all users from the AD except for the user *mobydick*. Using the **Pre Filter** tab you can restrict the import to groups of users e.g. *pascom-user*. Simply enter the following code:

```
# only import users with membership
if (!array_key_exists("memberOf", $row)) return false;

$groups = $row["memberOf"];
# turn a single group membership (string) into a list of memberships (array)
if (!is_array($groups)){
  $groups = array($row["memberOf"]);
}

# always search in a list of memberships
return preg_grep('/pascom-user/i', $groups);
```

### User Fields in AD

| Active Directory                         | PASCOM       | Description                                                                                                                                                                                      |
| ---------------------------------------- | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Account > sAMAccountName                 | username     | The login name is used for all logins and can only contain lowercase letters. Required field.                                                                                                    |
| General > displayName                    | displayname  | The display name is displayed on telephone displays and within the PASCOM desktop and mobile apps. Required field.                                                                               |
| General > givenName                      | givenname    | First name of the user used for the PASCOM telephone book entry.                                                                                                                                 |
| General > sn                             | surname      | Last name of the user used for the PASCOM telephone book entry.                                                                                                                                  |
| General > telephoneNumber                | phone        | The user's internal extension number. If this is not managed in AD, PASCOM will automatically assign the next available extension from the number pool.                                          |
| General > mail                           | email        | User's e-mail address. Used for sending voicemails and faxes.                                                                                                                                    |
| Organisation > company                   | organisation | Company to be entered in the user's PASCOM telephone book entry.                                                                                                                                 |
| Phone numbers > homePhone                | homephone    | User's private / home telephone number for the PASCOM telephone book entry.                                                                                                                      |
| Phone numbers > mobile                   | mobile       | The user's mobile phone number to be added to the PASCOM telephone book entry and with which a mobile phone device should be automatically created.                                              |
| Phone numbers > facsimileTelephoneNumber | Fax          | Internal fax number assigned to the user. Automatically also adds a virtual PASCOM fax machine assigned to the user. A pre-requirement here is that the PASCOM fax server is already configured. |

These fields are just template suggestions. You can add and remove fields or even modify the complete structure to match your requirements.

### Test and Activate the Import Process

After you have finalised your configuration, you can test the connector profile to determine which data sets will be imported using the **Save and Simulate** button. Once you are satisfied with the results, it is possible to either perform a one off import using the **Action** > **Import Now** option or automate the import to be performed at regular intervals by clicking the **Automate** button.

### Authentication Tests

If you have configured the template using the *Configure authentication* *YES* option, it is now possible to test the user authentication process using the following menu options **Appliance** > **Services** under the **Authentification** tab and finally using the **Test Authentication** button.

#### Optional Modifications

Do you want to make changes to source variables or the Connector structure? Then follow the links below to the appropriate instructions:

[Variable Assignment](/en/integrations/connector/variables-assignment.md)

[Variables structure](/en/integrations/connector/variables-structure.md)

#### Assign a Softphone, Mobile Phone or IP Telephone

From within the Active Directory, it is possible to directly assign a user with a Softphone or IP telephone.

**Assign IP Telephones via MAC Address:**

Under the **Variables** tab add the following lines by clicking **Add**:

| Variable | Source                    |
| -------- | ------------------------- |
| mac      | `return $row['ipPhone'];` |

This line instructs the Connector to save the content of the Active Directory field "ipPhone" to the variable "mac". "mac" corresponds to the MAC Address of the IP phone which should be assigned to the user. This variable now be assigned to the PASCOM field IP Telephone within the **Structure**.

To do this, expand the following lines so:

```
,"ipphone": [{
  "010dev_bez": "{{username}}_sipdevice",
  "071ipp_mac": "{{{mac}}}"
}],
```

**Softphone Assignment:**

If you want to assign users with a PASCOM softphone, it is not necessary to add an additional variable.

Under **Variables** it is sufficient to set the entry **createSoftphone** to "return true;".

**Mobile Phone Assignment:**

If you want to assign users with a mobile phone, it is not necessary to add an additional variable. The mobile phone number will be automatically read from the field "Phone numbers" > "mobile".

Under **Variables** it is sufficient to set the entry **createMobile** to "return true;".


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.pascom.net/en/integrations/connector/user-active-directory.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
