| Authentication | Users | Password |
|---|---|---|
| ✔ | ✔ | ✔ |
The Active Directory module is based on LDAP module, with the following features:
The configuration is the same as the LDAP module, except that the common uid attribute is replaced by sAMAccountName. The userPrincipalName is also a unique attribute. Generaly <sAMAccountName>@<ad-domain>.
AD password policy does not follow the LDAP RFC, but Microsoft has implemented its own policy. LemonLDAP::NG implements partially the policy:
Attention
Note: since AD 2012, each user can have a specific password expiration policy. Then, the “maximum password age” can have different values. This is currently unsupported in LemonLDAP::NG because every policy must be computed with their precedence to know which maximum password age to apply.
Some configuration is required in General parameters » Authentication parameters » LDAP parameters » Password:
To configure warning before password expiration, you must set two variables in Active Directory parameters in Manager: