Hello there!

Need Help? We are right here!

miniOrange Support
miniOrange Email Support
success

Thanks for your Enquiry.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:

×

Import Machines from AD


This feature allows administrators to fetch computers and their associated users/accounts from Active Directory (AD) via LDAP. The imported machines can then be onboarded into PAM for centralized access and privilege management.

  • Import Machines
    Enables scanning of machines from the Active Directory and fetching system details into PAM.
  • Auto Onboard Machines
    When enabled, RDP machines discovered during import are automatically added to the PAM database without requiring manual onboarding.
  • Scheduled Imports
    Administrators can configure one-time or periodic schedules for fetching machines from AD.
    • Once: The import will run at the scheduled time only once.
    • Periodic: The import will repeat automatically at defined intervals (daily, weekly, etc.), ensuring PAM stays up to date with newly added machines in AD.

Steps to Configure LDAP and Import Machines

1. Add AD Configuration and Set Up Import Machines

  • Log in as Admin and open your PAM dashboard, and navigate to LDAP Configuration:
  • From the left-hand menu, click Authentication.
  • Under Authentication, select LDAP.
  • Click + Add Configuration.
  • Import Machines from AD - navigate to Authentication LDAP and add configuration

  • Fill the required details on the Configuration tab:
  • Field Description
    Name A unique name used to identify this LDAP/Active Directory configuration in PAM.
    LDAP Server URL The protocol and hostname or IP address of the LDAP server.
    Bind Account Username The LDAP service account username used to authenticate and perform directory searches.
    Bind Account Password The password for the bind account to securely connect to the LDAP server.
    Search Base The base Distinguished Name (DN) from which LDAP objects such as users, groups, and machines are searched.
  • Go to the Import Machines tab.
  • Enable Import Machines to allow machine discovery.
  • Optionally enable Auto Onboard Machines to automatically onboard discovered RDP machines into the PAM database.
  • Search Base (Optional)
    Specify the directory path (OU/DN) where machines should be scanned in Active Directory.
  • Search Filter Type
    Select the required Search Filter Type:
    • Windows Machines – discovers only Windows-based systems.
    • Linux Machines – discovers only Linux-based systems.
    • Write Your Custom Filter – allows defining a custom LDAP filter.
  • Import Machines from AD - import machines tab settings

  • Configure scheduling (Optional):
    • Toggle Add schedule.
    • Select OccurrenceOnce (one-time import) or Periodic (recurring import).
    • Define the Start From date and time.
  • Click Save to complete the configuration.
  • Import Machines from AD - save import machines configuration

2. Perform Import and View Results

  • Open the Action menu for your LDAP configuration and select Import Machines to manually trigger a scan of AD.
  • Import Machines from AD - action menu import machines

  • Once the scan is complete, you will receive a notification and an email (if SMTP configured) with the import status.
  • Import Machines from AD - dashboard notification after machine scan

3. View Imported Machines and System Users

  • From Action, select Show Machine Scan Results to view the list of imported machines.
  • Import Machines from AD - show machine scan results

  • Clicking Onboard allows you to import the machines.
  • Import Machines from AD - onboard imported machines

  • Use View System Users to see the system users associated with each machine.
  • Import Machines from AD - view system users

Note: Bulk onboarding for Machine/System Users can be done by selecting multiple values and clicking on the Apply button from the top right.


  • To onboard a system user, click View System Users, then select Onboard next to the desired system user.