LDAP Directory Synchronization
ecos Article Number: 550.200.001
*Only available with on-premise ecos webman software
LDAP (Lightweight Directory Access Protocol) is the open, widely supported standard for accessing user and group information from a directory service. Because it is a protocol rather than a single product, ecos can use LDAP to synchronize with almost any LDAP-compatible directory — including on-premise Microsoft Active Directory and OpenLDAP.
GENERAL INTEGRATION
ecos connects to your directory via LDAP (or LDAPS). Users and their group memberships are read into ecos webman, bringing across the details that identify each person — name, e-mail and department — so key and asset access is driven straight from your existing directory rather than a separate list.
How it works
Point ecos webman at your directory by entering the LDAP/LDAPS server address and the read-only service account used to connect.
Bring your directory groups (or organizational units) into ecos, where they are reflected as user groups, so your existing structure sets access without being rebuilt.
ecos synchronizes users and group changes on a schedule, keeping access aligned with the directory as records change.
When a user is disabled or removed in the directory, their access to your ecos products is withdrawn at the next synchronization.
Key Features
Directory-driven user sync
Users are read from any LDAP-compatible directory into ecos, including their name, e-mail, and department, so there is no second user list to keep up to date.
Groups and roles synced for RBAC
Directory groups and organizational units are reflected as user groups in ecos, so your existing structure drives role-based access with no duplicate data entry. What each group is permitted to do is defined once, inside ecos.
Works with your existing directory
Because LDAP is an open standard, the same approach connects to on-premises Active Directory, OpenLDAP, and other LDAP directories — no vendor lock-in.
Scheduled, hands-off updates
Synchronisation runs automatically at set intervals using a read-only account, so changes and departures are reflected in ecos without manual effort.
Sync ecos with any directory, the standard way.
Use LDAP to synchronize users and groups from your existing directory — including on-premise Active Directory — so key and asset access always reflects who belongs where.