> For the complete documentation index, see [llms.txt](https://docs.pascom.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pascom.net/en/integrations/connector/user-ldap.md).

# Users from LDAP Directory

Synchronise and Authenticate your Users against LDAP

## LDAP

The "Lightweight Directory Access Protocol" (LDAP) is a network protocol for processing of queries and alterations in a shared directory service. LDAP itself is not a directory, but rather the protocol, via which one can use a specific syntax to query information from a LDAP directory.

In order to be allowed to read data from LDAP, a user with the appropriate permissions is required. Enter this user a password and check the *password never expires* option. PASCOM cloud phone system authenticates itself against LDAP for each connector run. If you wish to change the password, you must change it in both LDAP and within the PASCOM Connector profile:

## "Users from LDAP" Connector Profile

Create a new connector profile by navigating to the following options within the PASCOM admin Web UI: **Settings** > **Connector** and click **Add**.

Select the template *Users from LDAP* and enter the following information:

| Field                          | Description                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Title**                      | Connector profile name                                                                                                                                                                                                                                                                                                                                                                       |
| **LDAP URI**                   | URL to the LDAP directory                                                                                                                                                                                                                                                                                                                                                                    |
| **Base DN**                    | BaseDN specifies the position within the LDAP directory which should be read                                                                                                                                                                                                                                                                                                                 |
| **Username**                   | User with LDAP directory access permissions (LDAP bindDN)                                                                                                                                                                                                                                                                                                                                    |
| **Password**                   | Password for LDAP Authentication                                                                                                                                                                                                                                                                                                                                                             |
| **Search Filter**              | Filter for more detailed LDAP directory searches                                                                                                                                                                                                                                                                                                                                             |
| **Enable User Authentication** | <p><strong>NO</strong>: Users will be imported and the authenticated against the PASCOM server.<br><strong>YES</strong>: Users will be imported and can be authenticated against LDAP. In this case, the authentication will be setup and you can modify it to your requirements under <strong>Appliance</strong> > <strong>Services</strong> im Reiter <strong>Authentication</strong>.</p> |
| **Username field**             | (optional) You can enter the field name from which the to be imported users' username should be read. *Default: samAccountName*                                                                                                                                                                                                                                                              |
| **Create PASCOM Softphone**    | **YES**: Automatically adds a PASCOM softphone for every imported user. **NO**: No PASCOM softphones will be added for imported users.                                                                                                                                                                                                                                                       |
| **Create mobile phone**        | **YES**: Creates a mobile phone device for every imported user. **NO**: No mobile devices will be added for imported users.                                                                                                                                                                                                                                                                  |

After saving, the template can be modified according to requirements under the tab **Basic Data**.

**Use multiple LDAP URIs from your authentication servers**.

Click **Appliance** > **Services** from the menu and go to the **Authentication** tab. Here you can specify multiple LDAP(S) URIs, which are separated by a space. If one LDAP server fails, we simply use the second server entered.

<figure><img src="https://2713225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVIw0BpSv358R2Pr2HflD%2Fuploads%2Fgit-blob-83a358394f4f484275a5e02a0a4b395078562d1b%2Fmultiple-ldap-uris.png?alt=media" alt="Use multiple LDAP URIs" width="80%"><figcaption></figcaption></figure>

### Pre Filter

Per default, the template will import all users from the LDAP directory. Using the **Pre Filter** tab you can restrict the import according to certain factors e.g. *displayName* is populated. Simply replace "*return true;*" with the following code:

```
return array_key_exists('displayName', $row);
```

### User Fields in LDAP

Via the **Variables** tab, in the **Source** column it is possible to define from which LDAP user fields the information can be read from. The **Variables** in the left column define which information sets can be imported into the PASCOM cloud phone system.

The preset fields are suggestions for the template. It is possible to add, modify and remove fields i.e. completely alter the import structure to match your requirements.

### Test and Activate the Import Process

After you have finalised your configuration, you can test the connector profile to determine which datasets will be imported using the **Save and Simulate** button. Once you are satisfied with the results, it is possible to either perform a one off import using the **Action** > **Import Now** option or automate the import to be performed at regular intervals by clicking the **Automate** button.

### Authentication Tests

If you have configured the template using the *Configure authentication* *YES* option, it is now possible to test the user authentication process using the following menu options **Appliance** > **Services** under the **Authentification** tab and finally using the **Test Authentication** button.

#### Optional Modifications

Do you want to make changes to source variables or the Connector structure? Then follow the links below to the appropriate instructions:

[Variable Assignment](/en/integrations/connector/variables-assignment.md)

[Variables structure](/en/integrations/connector/variables-structure.md)

#### Assign a Softphone, Mobile Phone or IP Telephone

From within LDAP, it is possible to directly assign a user with a Softphone or IP telephone.

**Assign IP Telephones via MAC Address:**

Within the User from LDAP import, all required Variables and Structure for adding an IP telephony are already available.

Make sure, that values in your LDAP directory user fields are populated in accordance to how they are found in the PASCOM Web UI under the **Variables** tab:

| Variable  | Source                      | Description                                     |
| --------- | --------------------------- | ----------------------------------------------- |
| phonemac  | `return $row['phonemac'];`  | IP Telephone MAC Address                        |
| phoneip   | `return $row['phoneip'];`   | IP Telephone IP Address                         |
| phoneuser | `return $row['phoneuser'];` | Username for authenticating on the IP telephone |
| phonepass | `return $row['phonepass'];` | Password for authenticating on the IP telephone |

Optionally, the IP telephone FollowMe settings can also be set:

| Variable   | Source                       | Description                        |
| ---------- | ---------------------------- | ---------------------------------- |
| inttimeout | `return $row['inttimeout'];` | Internal calls: timeout in seconds |
| intdelay   | `return $row['intdelay'];`   | Internal calls: delay in seconds   |
| exttimeout | `return $row['exttimeout'];` | External calls: timeout in seconds |
| extdelay   | `return $row['extdelay'];`   | Team calls: delay in seconds       |
| quetimeout | `return $row['quetimeout'];` | Team calls: timeout in seconds     |
| quedelay   | `return $row['quedelay'];`   | Team calls: delay in seconds       |

Through these lines, the connector will save the content of the LDAP user fields to the corresponding PASCOM variable.

**Softphone Assignment:**

If you want to assign users with a PASCOM softphone, it is not necessary to add an additional variable.

Under **Variables** it is sufficient to set the entry **createSoftphone** to "return true;".

**Mobile Phone Assignment:**

If you want to assign users with a mobile phone, it is not necessary to add an additional variable. The mobile phone number will be automatically read from the LDAP user field "mobile".

Under **Variables** it is sufficient to set the entry **createMobile** to "return true;".


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.pascom.net/en/integrations/connector/user-ldap.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
