Before you can synchronize with an LDAP server, you must create a connection to that server.
In the Library Manager, right-click Connections and select Add.
In the Add LDAP Connection dialog, for Name, enter a unique name for the connection.
For Type, select Microsoft Active Directory.
For Server, enter the name or IP address of the LDAP server.
TIP: For example, for Microsoft Entra ID, this may be in the form ldaps.yourcompanyname.onmicrosoft.com.
For Port, enter the server port.
For LDAP, the default value is 389.
For Microsoft Entra ID (Azure Active Directory), use 636.
In the Account section, you can select how and where the LDAP credentials are stored.
To connect to LDAP as the currently authenticated Windows user (and encrypt LDAP credentials with the current user's account), select the Connect with active account check box. When this option is selected, the current user isn't prompted for LDAP credentials when connecting to a directory.
If you don't select Connect with active account, select a Storage setting to define how and where the LDAP credentials are stored. The options are:
Database This is the legacy storage mechanism.
NOTE: We recommend not selecting this option for new connections. Instead, select one of the following:Connect with active account
Local Machine
Local User
Local Machine
Select this option to allow anyone who can sign in to the current device to get access. This option can be used—for example, if the on-going LDAP synchronization is to be performed by a service account.For User, enter the distinguished name (LDAP DN) for the account user.
For Password, enter the password for the account.
Local User (default)
Select this option to allow a specific Windows user to get access. When this option is selected, there'll be a prompt for the Windows credentials (specified in Step 7b) each time the user tries to access this LDAP connection.
For User, enter the distinguished name (LDAP DN) for the account user.
TIP: For Microsoft Entra ID (Azure Active Directory), this is the distinguished name of the user in Azure, for example your.name@yourcompany.onmicrosoft.com. Also refer to Creating a user with directory access.
For Password, enter the password for the account.
Select OK.
If you've selected Local Machine as the Storage option, the new LDAP connection is added.
If you've selected Local User as the Storage option:
In the IRM LDAP Credential Access dialog, enter the following account credentials for the Windows account that'll be used to encrypt the LDAP credentials, and which will be prompted for when accessing this connection:
User
Domain
Password
A new LDAP connection is added.