Directory Services
swimlane turbine supports integration with microsoft active directory (ad) and ldap directory services by integrating with directory services, administrators can streamline user management and ensure consistent authentication across their organization feature availability multiple directory services configurations in one account are available only when the multi sso feature flag is enabled for the account (the same flag that enables multiple saml identity providers) to enable multi sso, contact swimlane support if you are a turbine platform (tp) customer, a super admin can enable the feature flag for the account if enabling fails because saml is missing an identity provider certificate, open the single sso saml settings dialog, paste the certificate into the certificate text area or use upload certificate , then apply and save account settings first see enable saml for sso docid\ irgxchuyjmsyplqdq3duh when multi sso is enabled, turbine supports multiple directory services configurations within a single account each configuration is managed independently and can be used to connect to a different directory source when multi sso is not enabled, the account uses a single directory services configuration directory services configurations are displayed on the directory services page, where administrators can create, edit, enable, disable, or delete configurations as needed use cases and benefits many turbine administrators leverage directory services to enable soc engineers and analysts to log in to turbine with previously established directory credentials automate user and group management, reducing administrative overhead for large teams increase security by centralizing authentication and maintaining compliance with corporate policies users are synced upon each login automatic synchronization occurs every night at midnight, server time these settings are at the account level and propagate to all the tenants associated with users through roles or groups directory services configurations the directory services page displays all configured directory service connections for the account the list contains the following information column description name the administrator defined name of the directory service configuration protocol the directory protocol used by the configuration status indicates whether the configuration is enabled or disabled use the more actions menu ( ⋮ ) beside a configuration to edit the configuration delete the configuration enable or disable the configuration to create an additional directory service connection, click + add create a directory services configuration before you begin, verify that your server settings are correct and ensure you have the necessary permissions to configure directory services to create a directory services configuration click your profile and then click the admin panel navigate to settings > account settings > directory services click + add enter a unique name for the directory services configuration configure the remaining settings as required click save the configuration can be enabled or disabled using the enabled toggle, or from the more actions menu ( ⋮ ) name the name field uniquely identifies a directory services configuration within the account this is especially useful when multiple directory service connections are configured, allowing administrators to distinguish between different directory sources examples corporate active directory partner ldap internal directory each directory services configuration should have a meaningful, unique name the name is displayed throughout the platform to help distinguish users and groups that originate from different directory sources server settings click > to expand server settings under server type , select either openldap or active directory input your server settings ensure that the username is an ldap distinguished name (for example, cn=manager,dc=example,dc=com ) server settings if you want to test the connection to the server at this point, enter placeholder text in all required fields, including those in other sections, and then click save once your initial settings are saved, you can click test connection user settings click > to expand user settings and review or update the values there the default values for openldap are often the most appropriate, but they may need to be altered to conform to your directory server’s configuration ensure that the member of field target is empty by default, and update if required based on your organization’s needs user settings field mapping these values rarely need to deviate from the defaults provided review and update as necessary to match your directory configuration group settings delete the default value for user membership field target and make sure it is empty the group location field must contain a distinguished name (dn) that provides the complete path to the container in which the targeted groups are defined use an appropriate directory services client to inspect the targeted group(s) and make note of how belonging users are affiliated to the group(s) is it done through the group’s property named member , the users' property named memberof , or through some other means? group settings groups this section lists manually entered groups to add a group, type the name in the field and then click add value keep in mind that you have to add each group individually, and that the values are case sensitive under groups to sync , click validate groups if this fails, troubleshoot by checking spelling and confirming that the group name is defined in the container specified in the group location value (a distinguished name) membership from this field, you can select from one of two values by user field or by group field if the users are affiliated with their groups via the member property in each group, choose by group syncing and verification click save again and then click sync now ensure that you receive confirmation of a successful sync (a green success message displays) then, from the left navigation menu, navigate to the turbine users page and verify that all the members of the targeted groups have been created as users when you use directory services with multi sso, review automatic mapping behavior before you run a directory synchronization when multi sso is enabled and the account has a single saml configuration and a single directory services configuration, the upgrade links existing directory users to that directory configuration and maps users to the saml configuration multiple sso or directory services configurations do not auto map — complete user mapping as needed see automatic migration of existing users https //docs swimlane com/enable saml for sso#automatic migration of existing users troubleshooting and best practices ensure that all required fields are filled correctly before testing the connection use a third party ldap client to verify the distinguished names (dn) for users and groups use meaningful group names and consistent field mappings to avoid confusion during setup if synchronization issues persist, check server logs for detailed error messages and reach out to swimlane support if necessary