Creatio administration
This documentation is valid for Creatio version 7.14.0. We recommend using the newest version of Creatio documentation.

Import users and roles from LDAP

If you use the Active Directory service, you can import the users from your directories to bpm’online via LDAP synchronization. This will let you copy users and roles from your corporate Active Directory to bpm’online.

Before you start adding users via LDAP synchronization:

  • Prepare your directory for integration: make sure that the users are assigned to the AD user groups that will be synchronized with bpm’online.

Note

Active Directory (AD) users that do not belong to any AD user group will not be imported. bpm’online only imports the organizational structure represented by the AD user groups.

  • Set up LDAP integration. Read more >>> After you click [Save] on the LDAP integration setup page, bpm’online will notify you about the “Run LDAP import” business process running in the background. As a result, the Active Directory user groups will be copied to bpm’online database.

When your bpm’online is integrated with LDAP, you can synchronize with your AD and add the AD users to bpm’online.

Adding users via LDAP synchronization

LDAP synchronization enables importing AD users of specific AD user groups to bpm’online specific organizational roles by linking the bpm’online roles to the AD user groups.

To add users to a bpm’online organizational role:

1.Click btn_system_designer00007.png -> [Organizational roles].

2.Select the role, where you want to add LDAP users from the corresponding AD user group via LDAP synchronization. You can also create a new role for the AD user group in your bpm’online organizational structure. To do this:

a.Select a parent role (e.g. “All employees” for adding regular users or “All portal users” for adding portal users) -> [New] -> [Organization].

b.Specify the name for your new role. The name can be the same as in your Active Directory user group or it can be different.

3.On the [Users] tab, select the [Synchronize with LDAP] checkbox.

4.In the [LDAP element] field, select the corresponding user group from the list to connect the LDAP element with the bpm’online organizational role -> [Save].

5.Click btn_com_roles_actions_menu.png -> [Synchronize with LDAP]. bpm’online will notify you that the LDAP synchronization is complete.

Note

If LDAP synchronization resulted in an error, you can check the details by checking the instances of the [Run LDAP synchronization] business process in the [Process log] section.

6.Update the [Organizational roles] page.

As a result, the [Users] detail of the corresponding role will display the LDAP users of the corresponding user group in your Active Directory. The new organizational role will display on the [Organizational roles] detail of the user’s page. You can verify this by opening the corresponding user record and check its [Roles] tab (Fig. 1).

Fig. 1 Adding users via LDAP synchronization from the role page

gif_section_users_adding_users_via_LDAP.gif 

LDAP integration and user authentication in bpm’online

Setting up LDAP integration

Linking LDAP elements to bpm’online users and roles

Running LDAP synchronization

Did you find this information useful?

How can we improve it?