Docs / Obsidian Mail Server / People
Active Directory
Coming in the next release: Obsidian Mail Server 0.9.0 does not include Active Directory import and sync yet.
People > Active Directory imports users, groups and contacts from Active Directory and keeps them in sync. People then sign in to mail with their Windows password. Each organization on the server can connect to its own AD.
Connect
You need:
- A domain controller the server can reach, with LDAPS (port 636) or LDAP with StartTLS (port 389). Name several: when one does not answer, the next is tried. Plain unencrypted LDAP is never used.
- A service account: an ordinary domain user with a long password that never expires. Reading the directory needs no admin rights. Enter it as
user@domain,DOMAIN\useror its DN. Its password is stored encrypted on the server and never shown again.
Test the connection tests every domain controller on its own and shows each one's certificate. Domain controllers usually have certificates from the company's own CA, which this server does not know. Either:
- Trust these certificates: exactly the certificates shown (one per domain controller) are accepted. When a DC's certificate is renewed, test again and trust the new one.
- Trust this CA: paste the company CA certificate (on a domain-joined PC:
certlm.msc> Trusted Root Certification Authorities > the CA > Export, Base-64). Every DC certificate it issues is accepted, renewals included. Recommended.
Use the domain controllers' names (dc1.example.local) rather than addresses where the server can resolve them: with the CA trusted, a certificate must then also be for that name.
Choose what to import
- OUs: tick the OUs to search, with everything below them. With nothing ticked, the whole domain is searched.
- Groups (optional): only members of these security groups, including nested members, come over. Use it with or instead of OUs, for example a group "Mail users".
- What comes over: accounts with an email address (Exchange's mail-enabled objects; recommended), groups that have an email address with their members, contacts, and optionally disabled accounts (they come over disabled).
How AD objects become recipients:
| In AD | Here |
|---|---|
| User with an email address | User (mailbox) |
Exchange shared / room / equipment mailbox (msExchRecipientTypeDetails) | Shared mailbox / room / equipment |
| Group with an email address | Group; security groups become security groups |
| Contact | Contact |
proxyAddresses (SMTP: = primary, smtp: = more) | Email addresses; else mail |
userPrincipalName | The account can also sign in with it |
msExchHideFromAddressLists | Hidden from the address book |
Only addresses in this organization's accepted domains come over. The preview lists the other domains it found; a global administrator can add them under Domains.
Preview
Before anything changes, the preview lists every object and what will happen to it: Create, Link existing (an account that already exists here with the same address is taken over by AD, keeping its mailbox and mail), Update, Disable, or Skip with the reason (no email address, domain not accepted, address used by another organization, and so on).
Sign-in
- The password is checked against AD each time someone signs in (at most every few minutes per device), so AD's password, lockout and expiry rules apply, and a password changed in Windows works here right away.
- The last password AD accepted is kept on the server (encrypted). If no domain controller answers, that password still works, so mail keeps working during an AD outage. While AD answers, it decides: an old password never works.
- When a sync sees that the password was changed in AD, the kept copy is dropped.
- Password changes and resets for these accounts happen in AD (webmail and this admin center say so).
- NTLM sign-in for Outlook works for them after their first sign-in.
Keeping in sync
Every 15 minutes to once a day (30 minutes by default), and with Sync now:
- New objects are created; names, email addresses and group members follow AD.
- Accounts disabled in AD are disabled here. Objects that leave the chosen scope (deleted, moved to another OU, no longer mail-enabled) are disabled, never deleted; their mail stays.
- Accounts created here by hand are never touched. Members added to an AD group here by hand are kept.
- Safety stop: when AD returns nothing, or a sync would disable more than half of the linked accounts at once (a wrong OU, a broken filter), the schedule does not apply it. The page shows the reason; check the preview and press Apply anyway if it is right.
Disconnect stops syncing. Every account stays, with its last password, and is managed here from then on.
From the command line: sudo oms directory status|preview|sync <org>.