Lawliet LAWLIET
Book a demo

Directory sign-in (Active Directory / LDAP)

People can sign in to the console with their Active Directory account. The Lawliet server does not join the domain: it only needs to reach one or more domain controllers on LDAPS (636) or StartTLS (389), and to trust the certificate they present.

Local accounts keep working beside directory sign-in. While it is on, at least one active local super administrator must exist: Lawliet refuses to turn it on without one, and refuses to deactivate, demote or delete the last one. That account is your way back in if the directory is unreachable or its groups change.

How a sign-in works

  1. The user picks Sign in with directory account on the sign-in page and enters DOMAIN\user or their account name. With a service account configured, any UPN works too.
  2. With a service account, Lawliet first looks the name up and finds the one account it names. A name that matches no account is never bound.
  3. Lawliet checks its per-account failed-bind cap (see Lockout safety).
  4. Lawliet binds as the user, over TLS, with the user's own password. The certificate is verified against the uploaded CA and against the host name or IP address of the domain controller. Referrals are never followed, so a password is never sent to a host the directory points to.
  5. Lawliet reads back exactly the account that bound. Disabled, locked, expired and password-expired accounts are refused.
  6. The user's groups, nested ones included, are matched against the group-to-role rules. If no rule matches, the user has no access.
  7. Two-factor authentication is always required for directory accounts. The first sign-in enrols an authenticator app; after that every sign-in asks for the code. Directory users cannot turn two-factor off; an administrator can reset it.

The person signing in sees one generic message for a wrong password, an unknown account, and a disabled, locked or expired account. The audit trail records the precise reason.

Account names

Typed asWithout a service accountWith a service account
DOMAIN\jsmithYesYes
jsmithYesYes
[email protected] (the directory's own DNS domain)Yes, read as the account nameYes
A UPN whose prefix differs from the account name, or with another suffixRefused with a message to sign in as DOMAIN\usernameYes

The reason is lockout safety: without a service account Lawliet cannot look anything up before binding, so it binds every name as DOMAIN\name and counts failures against the account name the domain controller checks. Different spellings of one account never get separate allowances.

Configure it

Settings > Authentication > Directory sign-in. You need the Manage users permission, and with dual control on, a change waits for a second signature.

FieldWhat to enter
Domain controllersOne per line, for example dc1.corp.example.com:636. Tried in order; the next is used only when one is unreachable, never to retry a refused password.
TransportLDAPS (636) or StartTLS (389). Plain LDAP is not offered.
Failed sign-ins per account1 to 4 (default 3), and at least 2 below the domain's lockout threshold.
Session lifetime1 to 24 hours (default 8). After it, a full sign-in with the second factor is needed.
DNS domain, NetBIOS name, base DNFor example corp.example.com, CORP, DC=corp,DC=example,DC=com. Accounts of any other domain are refused.
CA certificate (PEM)The CA that issued the domain controllers' LDAPS certificates. An internal enterprise CA must be uploaded.
Service account (optional, recommended)A read-only plain domain user. It resolves names before binding, reads the domain's lockout policy, and re-checks users at every session refresh. Its password is encrypted at rest and never returned.
Group to roleSee Groups to roles.

Test connection reaches every listed server over TLS and verifies the certificate, reads the base DN and, with a service account, the lockout policy, and says whether the cap leaves the required margin. It never binds a user account.

On a domain controller, PowerShell gives the values: (Get-ADDomain).DNSRoot, (Get-ADDomain).NetBIOSName, (Get-ADDomain).DistinguishedName, and Get-ADDefaultDomainPasswordPolicy for the lockout threshold and window.

Groups to roles

Each rule pairs an AD group with a Lawliet role. Name the group by sAMAccountName (Lawliet Admins), distinguished name or SID; a CN alone is never matched, because CNs repeat across OUs. Nested membership counts. The first matching rule wins, so put the most privileged rule first. The role is recomputed at every sign-in.

Map dedicated groups, such as Lawliet Admins and Lawliet Analysts, rather than Domain Admins, so that domain administration and Lawliet administration stay separate decisions.

Lockout safety

Lawliet's own binds never take an account closer than 2 attempts to the domain's lockout threshold, under the Default Domain Policy.

Failures from the user's workstation, mail client or other systems count against the same threshold; Lawliet's margin of 2 is the room it leaves for them. Fine-grained password policies (PSOs) are not visible to an ordinary account, so if PSOs apply to console users, set the cap at least 2 below the lowest PSO threshold.

Sessions and revocation

Every attempt is in the audit trail with the account, the domain controller and the precise reason, such as invalid_credentials, account_locked, no_role_mapping or bind_cap_reached.

Troubleshooting

SymptomCause and fix
Test connection: certificate not trusted or issued for another nameUpload the CA that issued the DC certificate, and use a host name or IP address listed in the certificate's subject alternative names.
Test connection: TLS failedLDAPS is not enabled on the DC, or StartTLS was chosen on a port that speaks LDAPS.
Test connection: not reachableFirewall or routing between the Lawliet server and the DC on 636 or 389.
Referral, or base DN does not existThe base DN is not in this domain. Use this domain's DN.
Save refused: set the failed sign-in cap lowerThe domain's lockout threshold is low. Lower the cap, or raise the threshold.
Every user gets "Invalid username or password"Check the audit reason: foreign_domain means the NetBIOS name is wrong; identity_not_found means the base DN does not contain the users.
"Too many failed sign-in attempts ... 60 minutes" after one mistakeThe domain policy has not been read yet. Configure a service account, or wait for the first successful sign-in.
Users are told to wait N minutesThe failed-bind cap was reached. Wait the time shown, or check the password in the directory first.
"Not in a group that has access"The user's groups match no rule. Check the rule's spelling (sAMAccountName, DN or SID).
An administrator removed from the group is told to use the break-glass accountThe last-administrator guard. Sign in with the local super administrator and make another user super administrator.

Passwords travel only inside TLS 1.2 or later, with certificate and name verification that cannot be switched off. The LDAP library ships in the backend image, so directory sign-in works on air-gapped installations.