Configuring LDAP Sync requires the IRM server operator to have the appropriate access rights to the target directory service. The specific requirements depend on the type of directory being used. Refer to the following sections relevant to your environment.

For Microsoft Entra ID (Azure Active Directory)

The user who'll run the LDAP Sync to Microsoft Entra ID (Azure AD) simply needs to be a user in the Azure directory. For more information, go to Tutorial: Configure secure LDAP for a Microsoft Entra Domain Services managed domain.

For non-AD LDAP

After the synchronization attribute is added to a remote LDAP directory, the IRM server operator must have read/write access to the iManageSyncId attribute and class in the directory. If the synchronization attribute isn't used, there's no need for the IRM server operator to have write access to any part of the remote LDAP directory service.

Creating a user with restricted access rights is done by the administrator of the remote LDAP directory service, using the appropriate procedures for ADS directory services. The general procedure involves adding a new user (the IRM Server operator) to the trustee list and setting read/write permissions for the iManageSyncID attribute.

For specific instructions, the administrator of the LDAP directory service should refer to the documentation from the appropriate LDAP directory service provider.