Directory sign-in (Active Directory / LDAP)
People can sign in to the console with their Active Directory account. The Lawliet server does not join the domain: it only needs to reach one or more domain controllers on LDAPS (636) or StartTLS (389), and to trust the certificate they present.
Local accounts keep working beside directory sign-in. While it is on, at least one active local super administrator must exist: Lawliet refuses to turn it on without one, and refuses to deactivate, demote or delete the last one. That account is your way back in if the directory is unreachable or its groups change.
How a sign-in works
- The user picks Sign in with directory account on the sign-in page and enters
DOMAIN\useror their account name. With a service account configured, any UPN works too. - With a service account, Lawliet first looks the name up and finds the one account it names. A name that matches no account is never bound.
- Lawliet checks its per-account failed-bind cap (see Lockout safety).
- Lawliet binds as the user, over TLS, with the user's own password. The certificate is verified against the uploaded CA and against the host name or IP address of the domain controller. Referrals are never followed, so a password is never sent to a host the directory points to.
- Lawliet reads back exactly the account that bound. Disabled, locked, expired and password-expired accounts are refused.
- The user's groups, nested ones included, are matched against the group-to-role rules. If no rule matches, the user has no access.
- Two-factor authentication is always required for directory accounts. The first sign-in enrols an authenticator app; after that every sign-in asks for the code. Directory users cannot turn two-factor off; an administrator can reset it.
The person signing in sees one generic message for a wrong password, an unknown account, and a disabled, locked or expired account. The audit trail records the precise reason.
Account names
| Typed as | Without a service account | With a service account |
|---|---|---|
DOMAIN\jsmith | Yes | Yes |
jsmith | Yes | Yes |
[email protected] (the directory's own DNS domain) | Yes, read as the account name | Yes |
| A UPN whose prefix differs from the account name, or with another suffix | Refused with a message to sign in as DOMAIN\username | Yes |
The reason is lockout safety: without a service account Lawliet cannot look anything up before binding, so it binds every name as DOMAIN\name and counts failures against the account name the domain controller checks. Different spellings of one account never get separate allowances.
Configure it
Settings > Authentication > Directory sign-in. You need the Manage users permission, and with dual control on, a change waits for a second signature.
| Field | What to enter |
|---|---|
| Domain controllers | One per line, for example dc1.corp.example.com:636. Tried in order; the next is used only when one is unreachable, never to retry a refused password. |
| Transport | LDAPS (636) or StartTLS (389). Plain LDAP is not offered. |
| Failed sign-ins per account | 1 to 4 (default 3), and at least 2 below the domain's lockout threshold. |
| Session lifetime | 1 to 24 hours (default 8). After it, a full sign-in with the second factor is needed. |
| DNS domain, NetBIOS name, base DN | For example corp.example.com, CORP, DC=corp,DC=example,DC=com. Accounts of any other domain are refused. |
| CA certificate (PEM) | The CA that issued the domain controllers' LDAPS certificates. An internal enterprise CA must be uploaded. |
| Service account (optional, recommended) | A read-only plain domain user. It resolves names before binding, reads the domain's lockout policy, and re-checks users at every session refresh. Its password is encrypted at rest and never returned. |
| Group to role | See Groups to roles. |
Test connection reaches every listed server over TLS and verifies the certificate, reads the base DN and, with a service account, the lockout policy, and says whether the cap leaves the required margin. It never binds a user account.
On a domain controller, PowerShell gives the values: (Get-ADDomain).DNSRoot, (Get-ADDomain).NetBIOSName, (Get-ADDomain).DistinguishedName, and Get-ADDefaultDomainPasswordPolicy for the lockout threshold and window.
Groups to roles
Each rule pairs an AD group with a Lawliet role. Name the group by sAMAccountName (Lawliet Admins), distinguished name or SID; a CN alone is never matched, because CNs repeat across OUs. Nested membership counts. The first matching rule wins, so put the most privileged rule first. The role is recomputed at every sign-in.
Map dedicated groups, such as Lawliet Admins and Lawliet Analysts, rather than Domain Admins, so that domain administration and Lawliet administration stay separate decisions.
Lockout safety
Lawliet's own binds never take an account closer than 2 attempts to the domain's lockout threshold, under the Default Domain Policy.
- Lawliet records every bind before it sends it. Once an account has the cap's number of failures (default 3), Lawliet refuses without contacting the domain controller, even for the correct password. The person is told how long to wait.
- The cap is counted per account, however the name is spelt, and kept in the database across restarts.
- Failures are forgotten the way the domain forgets them: after a quiet period of one observation window, using the domain's window when it is longer than Lawliet's own 15 minutes.
- The domain's lockout policy is read before each sign-in with a service account, or at each successful sign-in without one. Until it is known, Lawliet allows 1 failed bind per account per hour.
- A domain whose threshold is 1 or 2 leaves no safe margin: directory sign-in then refuses without binding and says so.
Failures from the user's workstation, mail client or other systems count against the same threshold; Lawliet's margin of 2 is the room it leaves for them. Fine-grained password policies (PSOs) are not visible to an ordinary account, so if PSOs apply to console users, set the cap at least 2 below the lowest PSO threshold.
Sessions and revocation
- With a service account, every session refresh re-reads the user. A disabled, locked, expired or deleted account, or one no longer in a mapped group, loses all its sessions. If the directory cannot be reached, the refresh fails and nothing is revoked.
- Every directory session has an absolute lifetime (8 hours by default), enforced on every request.
- Turning directory sign-in off ends every directory session at once.
- A directory or SSO role change never demotes the last active super administrator, and never makes a change after which nobody could approve user management. The role is kept, the sign-in is refused with a pointer to the local break-glass account, and the audit entry says why.
- An administrator can still deactivate a directory user in Settings > Users; Lawliet then refuses that user even when the directory accepts the password.
Every attempt is in the audit trail with the account, the domain controller and the precise reason, such as invalid_credentials, account_locked, no_role_mapping or bind_cap_reached.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
| Test connection: certificate not trusted or issued for another name | Upload the CA that issued the DC certificate, and use a host name or IP address listed in the certificate's subject alternative names. |
| Test connection: TLS failed | LDAPS is not enabled on the DC, or StartTLS was chosen on a port that speaks LDAPS. |
| Test connection: not reachable | Firewall or routing between the Lawliet server and the DC on 636 or 389. |
| Referral, or base DN does not exist | The base DN is not in this domain. Use this domain's DN. |
| Save refused: set the failed sign-in cap lower | The domain's lockout threshold is low. Lower the cap, or raise the threshold. |
| Every user gets "Invalid username or password" | Check the audit reason: foreign_domain means the NetBIOS name is wrong; identity_not_found means the base DN does not contain the users. |
| "Too many failed sign-in attempts ... 60 minutes" after one mistake | The domain policy has not been read yet. Configure a service account, or wait for the first successful sign-in. |
| Users are told to wait N minutes | The failed-bind cap was reached. Wait the time shown, or check the password in the directory first. |
| "Not in a group that has access" | The user's groups match no rule. Check the rule's spelling (sAMAccountName, DN or SID). |
| An administrator removed from the group is told to use the break-glass account | The last-administrator guard. Sign in with the local super administrator and make another user super administrator. |
Passwords travel only inside TLS 1.2 or later, with certificate and name verification that cannot be switched off. The LDAP library ships in the backend image, so directory sign-in works on air-gapped installations.

