Skip to content

Managing LDAP server connections

Prerequisite knowledge of general LDAP (Lightweight Directory Access Protocol) concepts and features is important for this section.

The examples in this section use LDAP conventions. If you use Active Directory, adjust the examples accordingly.

aPriori provides the capability to specify one or more LDAP server connections to import users into aPriori and authenticate them when they use aPriori. You can specify several number details that are applied automatically when users are imported, such as the following:

  • User settings and access conditions
  • Access Control groups to which users are assigned (optional)
  • Several user "Extra" fields that you can use to add LDAP server attributes

When your LDAP connections are defined, you can synchronize aPriori user accounts with the LDAP server(s) either manually (see aPriori user password requirements), or automatically through the separately-licensed aP Admin LDAP Synchronization (“LDAP Sync”) module (see the aP Admin Guide to LDAP Synchronization).

In summary, you can manage your users in three ways:

  • Manually: Use the aPriori System Administrator user interface.
  • LDAP Map: Run LDAP connections manually by using the Synchronize with LDAP button on the Users tab.
  • LDAP Synchronization: Use the separately licensed aPriori Cost Admin “LDAP Synchronization” module to schedule and run your LDAP connections automatically.

This section describes how to define LDAP connections, whether you synchronize them manually or through the LDAP Sync module.

LDAP Connections and Access Control Groups

Membership for all access control groups is managed independently of LDAP except for the following special (system defined) groups:

  • All Users
  • System Administrators
  • Digital Factory Administrators

The All-Users group is always modified by LDAP.

The Systems Administrators and Digital Factory Administrators groups may or may not be modified by LDAP, depending on how these groups are defined and how the Sync Admin Group Membership options are defined for the LDAP connection.

The special Super User sub-group of the System Administrators group is always managed manually.

For more information about Access Control groups, see Access Control basic concepts in the Access Control chapter.