Skip to content

Active Directory connection

When the gateway is connected to Active Directory, access is determined by directory group membership. Disabling an employee’s account removes their access without any further action.

  1. Choose an access group

    Create an Active Directory group or choose an existing group for people who need VPN access. Members of nested groups are included.

  2. Choose an operator group

    Members of this group can sign in to the console with their domain accounts.

  3. Configure the connection in the console

    On a domain-joined Windows Server, the gateway uses the computer account. No password is needed. On Linux, a read-only service account and a secure directory connection (LDAPS or StartTLS) are required.

  4. Test the connection

    Run the connection test in the console and check that the group member count looks right.

  • Group membership does not automatically create a profile. A profile is created when a group member’s computer requests it through Group Policy, or when you generate it in the console.
  • The gateway syncs with the directory every few minutes. You can also start a sync from the console.

Disable the account in Active Directory or remove it from the access group, as you do today. At the next sync, all of the employee’s devices will be revoked, and they will no longer be able to connect.

To remove access immediately, revoke the device in the console. Manual revocation takes effect immediately.

  • If the directory is unavailable, no one’s access is revoked. The console displays an alert, and syncing resumes when the directory is available again.
  • If the directory returns an empty group, no one’s access is revoked, and the console displays an alert.
  • If a sync would revoke an unusually large proportion of devices, no devices are revoked until an operator approves the revocation in the console.