LDAP (Lightweight Directory Access Protocol) enables Intelligent Sandbox to configure a dedicated LDAP server for user authentication. A separate server for user authentication facilitates a secured and centralized authentication system. It provides a robust and secure credential authentication and management system for various types of Intelligent Sandbox users.
To authenticate an account from an LDAP server, you must create an account on the Intelligent Sandbox appliance with the authentication type LDAP. The account name on the Intelligent Sandbox appliance must match the LDAP server account name.
Base Distinguished Name (BaseDN) — Create a specific BaseDN for Intelligent Sandbox users. BaseDN acts as a root node under which all the Intelligent Sandbox users are added.
Admin Credentials — To enable the LDAP option, you must provide the Admin User credentials in the Intelligent Sandbox web interface. If the Admin User has not been created, you must create the same in the LDAP server directory.
User creation — Create a user with the same username as on the LDAP server and select the authentication type as LDAP.
Note
During the LDAP logon, username must match the username created locally in the Intelligent Sandbox database. Username is case sensitive.
After upgrading to Intelligent Sandbox 5.2, consider the following LDAP scenarios:
When LDAP is enabled - Users with administrator roles, such as admin or atdadmin, will be upgraded to LDAP users, while other users will remain as local users.
When LDAP is disabled - All users will be upgraded to local users.
The authentication type for users created by administrators prior to the Intelligent Sandbox 5.2 upgrade can be changed to LDAP by using the Edit Users option on the TIS Users page. LDAP authentication is not supported for the user with the Integration Administrator role.
Log on to the Intelligent Sandbox web interface.
Click → → , then select Enable LDAP.
Configure the LDAP User Credentials options, then click Test Connection.
On the LDAP Test connection successful window, click OK.
Click Submit.
Note
To authenticate the cliadmin from an LDAP server, we can create the same user in the LDAP server. For cliadmin users, Fallback is enabled by default.