Manage Active Directory Accounts¶
12Port can manage Active Directory user accounts through the LDAP User asset type. This includes automated and on-demand password set, verify, and unlock tasks.
Active Directory account management requires a specific asset configuration. The default Windows Host asset type does not natively support Active Directory account management tasks. Instead, the account to be managed must use the LDAP User asset type and a separate LDAP Administrator asset must be configured, as a Shadow, to perform the management operation.
LDAP User assets can be created through an import, manually, or through the 12Port API. The same asset configuration is required regardless of how the asset is created.
Active Directory Account Management Components¶
Active Directory account management uses two interlinked asset types. The LDAP User asset represents the account being managed. The LDAP Administrator asset provides the connection and credentials required to perform management operations against the Active Directory domain.
LDAP User¶
The LDAP User asset represents an Active Directory user account stored in the 12Port vault.
For this configuration, the LDAP User asset requires:
- User: The Active Directory account name in UPN format (e.g. bwilliams@contoso.com).
- Password: The current password for the Active Directory account.
The LDAP User asset type includes the tasks required to manage Active Directory passwords. These tasks use a Shadow Account to connect to Active Directory and perform the requested operation.
The LDAP User asset should be used for the account being managed.
LDAP Administrator¶
The LDAP Administrator asset provides the connection to the Active Directory domain and the credentials used to perform account management operations.
The asset requires:
- User: An Active Directory account with permission to manage passwords for other accounts.
- Password: The password for the administrator account.
- URL: The LDAPS endpoint used to connect to the Active Directory domain.
The URL must use the ldaps:// protocol and include the appropriate port like :636. LDAP write operations like password set cannot be performed over non-secure ldap:// connections or through the Global Catalog. For example, the connection should resemble this:
The account configured on the LDAP Administrator asset must have permission to set passwords for the accounts being managed. A Domain Administrator account is one example of an account that may have the required permissions.
Note
The LDAP Administrator configuration is independent of any existing LDAP Integration configuration. LDAP Administrator assets do not use or inherit settings from any LDAP Integrations.
Shadow Account Configuration¶
The LDAP User asset uses the LDAP Administrator asset as a Shadow account when an account management task runs.
The process works as follows:
- A task is executed on the LDAP User asset.
- 12Port identifies the LDAP Administrator asset assigned to the LDAP User as a Shadow.
- The task uses the LDAP Administrator credentials and URL to connect to Active Directory.
- The task executes the appropriate Active Directory script.
- After the operation completes successfully, the LDAP User asset is updated with the new password.
For example, the Active Directory LDAP Set Password by Shadow task uses the LDAP Administrator asset to connect to the configured Active Directory domain and set the password for the LDAP User account.
Configuring Active Directory Account Management¶
Before creating LDAP User assets, make sure the required asset types are available.
Unhide Required Asset Types¶
If LDAP User or LDAP Administrator is not available when creating an asset:
- Go to Management > Asset Types.
- Find LDAP User and LDAP Administrator.
- Select the asset type and choose Unhide.
Both asset types must be available before configuring the account management assets.
Create the LDAP Administrator Asset¶
Create an LDAP Administrator asset in the folder where the Active Directory accounts will be managed.
- Open the target folder.
- Create a new asset using the LDAP Administrator asset type.
- Enter the User for an Active Directory account with permission to manage other AD accounts. For example, if you are planning on setting new passwords, then this LDAP Administrator user must have permission in Active Directory to perform such an action.
- Enter the Password for the account.
- Enter the URL for the Active Directory LDAPS endpoint.
For example:
6. Click the Verify Trust button and import the LDAPS certificate to establish trust.
7. Save the asset.
The LDAP Administrator asset can be reused as the Shadow Account for multiple LDAP User assets when the same Active Directory connection and administrative credentials are appropriate.
Creating LDAP User Assets¶
LDAP User assets can be created through an import, manually through the 12Port interface, or through the API.
Regardless of the creation method, each LDAP User asset must contain the Active Directory User and Password values. The LDAP Administrator asset must also be assigned as the Shadow Account.
Import LDAP User Accounts¶
When importing Active Directory accounts, configure the import to create assets using the LDAP User asset type.
- Configure the import for the target folder.
- Set Asset Type to LDAP User.
- Set Reference Asset to the LDAP Administrator asset created for the Active Directory domain.
- Configure the remaining import parameters as required.
- Run the import.
After the import completes:
- Open the target folder.
- Open one of the imported LDAP User assets.
- Verify that the User field is populated as expected.
- Verify that the LDAP Administrator asset is assigned with Member Asset Role: Shadow.
The Reference Asset setting associates the imported LDAP User assets with the LDAP Administrator asset used for account management.
Create LDAP User Assets Manually¶
LDAP User assets can also be created individually without using an import.
- Create a new asset using the LDAP User asset type.
- Enter the Active Directory account in the User field.
- Enter the current account password in the Password field.
- Assign the LDAP Administrator asset as a Shadow asset.
- Save the asset.
The resulting asset uses the same account management tasks as an LDAP User asset created through an import.
Create LDAP User Assets Using the API¶
LDAP User assets can also be created programmatically through the 12Port API.
When creating the asset through the API, use the LDAP User asset type and provide the required User and Password values. The LDAP Administrator asset must also be assigned as the asset's Shadow Account.
The API-created asset follows the same task and Shadow Account configuration as an asset created through the user interface or an import.
Verifying the Configuration¶
Before executing an account management task, verify the following:
- The account being managed uses the LDAP User asset type.
- The LDAP User contains valid User and Password values.
- An LDAP Administrator asset is available.
- The LDAP Administrator contains a valid User and Password.
- The LDAP Administrator URL uses
ldaps://and the correct port. - The LDAP Administrator account has permission to set passwords for the target accounts.
- The LDAP Administrator is assigned to the LDAP User with Member Asset Role: Shadow.
- The required Active Directory task is available on the LDAP User asset.
If the LDAP User does not have a Shadow Account, the account management task cannot use the required Active Directory connection and credentials and therefore, it will fail.
Executing Password Reset Tasks¶
After the LDAP User and LDAP Administrator assets are configured, password management tasks can be executed from the LDAP User asset.
For an on-demand password reset:
- Open the LDAP User asset.
- Select Execute.
- Select Active Directory LDAP Set Password by Shadow.
- Submit the task for execution.
- Open Reports > Jobs to review the result.
The task uses the LDAP Administrator asset assigned as the Shadow Account to connect to Active Directory and set the password.
The LDAP User asset is updated with the new password after the task completes successfully.
The same task can also be configured for scheduled execution by using the task configuration on the LDAP User asset.
Auditing and Jobs Reports¶
Active Directory account management tasks are recorded in the Jobs Report.
To review the result of a password reset:
- Open the LDAP User asset.
- Navigate to Reports > Jobs.
- Locate the password management job.
- Review the job status and result.
The Jobs Report can also be accessed globally through Reports > Jobs to review task executions across the environment.