Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / People

Active Directory

Coming in the next release: Obsidian Mail Server 0.9.0 does not include Active Directory import and sync yet.

People > Active Directory imports users, groups and contacts from Active Directory and keeps them in sync. People then sign in to mail with their Windows password. Each organization on the server can connect to its own AD.

Connect

You need:

  • A domain controller the server can reach, with LDAPS (port 636) or LDAP with StartTLS (port 389). Name several: when one does not answer, the next is tried. Plain unencrypted LDAP is never used.
  • A service account: an ordinary domain user with a long password that never expires. Reading the directory needs no admin rights. Enter it as user@domain, DOMAIN\user or its DN. Its password is stored encrypted on the server and never shown again.

Test the connection tests every domain controller on its own and shows each one's certificate. Domain controllers usually have certificates from the company's own CA, which this server does not know. Either:

  • Trust these certificates: exactly the certificates shown (one per domain controller) are accepted. When a DC's certificate is renewed, test again and trust the new one.
  • Trust this CA: paste the company CA certificate (on a domain-joined PC: certlm.msc > Trusted Root Certification Authorities > the CA > Export, Base-64). Every DC certificate it issues is accepted, renewals included. Recommended.

Use the domain controllers' names (dc1.example.local) rather than addresses where the server can resolve them: with the CA trusted, a certificate must then also be for that name.

Choose what to import

  • OUs: tick the OUs to search, with everything below them. With nothing ticked, the whole domain is searched.
  • Groups (optional): only members of these security groups, including nested members, come over. Use it with or instead of OUs, for example a group "Mail users".
  • What comes over: accounts with an email address (Exchange's mail-enabled objects; recommended), groups that have an email address with their members, contacts, and optionally disabled accounts (they come over disabled).

How AD objects become recipients:

In ADHere
User with an email addressUser (mailbox)
Exchange shared / room / equipment mailbox (msExchRecipientTypeDetails)Shared mailbox / room / equipment
Group with an email addressGroup; security groups become security groups
ContactContact
proxyAddresses (SMTP: = primary, smtp: = more)Email addresses; else mail
userPrincipalNameThe account can also sign in with it
msExchHideFromAddressListsHidden from the address book

Only addresses in this organization's accepted domains come over. The preview lists the other domains it found; a global administrator can add them under Domains.

Preview

Before anything changes, the preview lists every object and what will happen to it: Create, Link existing (an account that already exists here with the same address is taken over by AD, keeping its mailbox and mail), Update, Disable, or Skip with the reason (no email address, domain not accepted, address used by another organization, and so on).

Sign-in

  • The password is checked against AD each time someone signs in (at most every few minutes per device), so AD's password, lockout and expiry rules apply, and a password changed in Windows works here right away.
  • The last password AD accepted is kept on the server (encrypted). If no domain controller answers, that password still works, so mail keeps working during an AD outage. While AD answers, it decides: an old password never works.
  • When a sync sees that the password was changed in AD, the kept copy is dropped.
  • Password changes and resets for these accounts happen in AD (webmail and this admin center say so).
  • NTLM sign-in for Outlook works for them after their first sign-in.

Keeping in sync

Every 15 minutes to once a day (30 minutes by default), and with Sync now:

  • New objects are created; names, email addresses and group members follow AD.
  • Accounts disabled in AD are disabled here. Objects that leave the chosen scope (deleted, moved to another OU, no longer mail-enabled) are disabled, never deleted; their mail stays.
  • Accounts created here by hand are never touched. Members added to an AD group here by hand are kept.
  • Safety stop: when AD returns nothing, or a sync would disable more than half of the linked accounts at once (a wrong OU, a broken filter), the schedule does not apply it. The page shows the reason; check the preview and press Apply anyway if it is right.

Disconnect stops syncing. Every account stays, with its last password, and is managed here from then on.

From the command line: sudo oms directory status|preview|sync <org>.