Configure LDAP Authentication
By integrating Lightweight Directory Access Protocol (LDAP) authentication into Spectrum, you can enable users to sign into Spectrum by using their domain credentials.
Note: To perform this task, you must be signed in as the ClientAdmin, SystemAdmin, or SuperAdmin user. For more information, see
To integrate LDAP into Spectrum, use the following procedure.
Note: If you are configuring a multi-site deployment A configuration of a Spectrum environment that includes Spectrum instances located at different sites within the same WAN. In a multi-site deployment, each Spectrum instance acts as either a headquarters or a facility. of Spectrum, you must sign in to each facility site to configure LDAP or Azure authentication. LDAP or Azure authentication information is not synced from headquarters to facilities.
- In System
- Click New LDAP Authentication for a new configuration, or click the existing configuration that you want to modify.
- Configure the LDAP Authentication panel. For more information, see User Interface: LDAP Authentication.
- If you do not want to use LDAP auto-provisioning, skip this step.
If you want use LDAP auto-provisioning, do the following in the Auto Provisioning panel.- To turn on auto-provisioning now, select the Enable Auto Provisioning check box. Otherwise, you can leave the check box clear, set up auto-provisioning now, and enable it later.
- For LDAP Vendor, select an option from the drop-down list. Once selected, the remaining fields are pre-filled with the default settings for the selected LDAP vendor, but you must modify the settings to match your LDAP configuration. For more information, see User Interface: LDAP Authentication.
- In the Spectrum Group to LDAP Group mapping table, click the
Add button to add a Spectrum group or groups to the mapping table. For more information, see User Interface: Group Mapping Table.
Tip: The group must already exist in Spectrum and have permissions configured within Spectrum. For more information, see Create or Modify a Group.
- Click the LDAP Group Lookup button. The LDAP Group Lookup dialog box is displayed.
- Enter information by which to search in the Group Search Base and Group Search Filter fields, and then click Search.
- Click and drag the desired group from the LDAP Group Search Results list to the LDAP Group column of the mapping table for the corresponding Spectrum Group.
Tip: An LDAP group can only be mapped to one Spectrum group, but a Spectrum group can be mapped to multiple LDAP groups.
- Repeat for all Spectrum to LDAP groups you want to map.
- Click Save
.
To set up SSO with LDAP, see Configure Single Sign-On (SSO) Using Security Assertion Markup Language (SAML).
To set a specific default domain for users signing in to Spectrum, see Set a Default LDAP Domain in the Loftware Spectrum Installation and Configuration Guide.