Active Directory connection
When the gateway is connected to Active Directory, access is determined by directory group membership. Disabling an employee’s account removes their access without any further action.
Connect to the directory
Section titled “Connect to the directory”-
Choose an access group
Create an Active Directory group or choose an existing group for people who need VPN access. Members of nested groups are included.
-
Choose an operator group
Members of this group can sign in to the console with their domain accounts.
-
Configure the connection in the console
On a domain-joined Windows Server, the gateway uses the computer account. No password is needed. On Linux, a read-only service account and a secure directory connection (LDAPS or StartTLS) are required.
-
Test the connection
Run the connection test in the console and check that the group member count looks right.
Who gets access
Section titled “Who gets access”- Group membership does not automatically create a profile. A profile is created when a group member’s computer requests it through Group Policy, or when you generate it in the console.
- The gateway syncs with the directory every few minutes. You can also start a sync from the console.
When an employee leaves
Section titled “When an employee leaves”Disable the account in Active Directory or remove it from the access group, as you do today. At the next sync, all of the employee’s devices will be revoked, and they will no longer be able to connect.
To remove access immediately, revoke the device in the console. Manual revocation takes effect immediately.
Safeguards against accidental revocation
Section titled “Safeguards against accidental revocation”- If the directory is unavailable, no one’s access is revoked. The console displays an alert, and syncing resumes when the directory is available again.
- If the directory returns an empty group, no one’s access is revoked, and the console displays an alert.
- If a sync would revoke an unusually large proportion of devices, no devices are revoked until an operator approves the revocation in the console.
