LDAP / Active Directory¶
Connect BongoShield to your on-premises Active Directory or LDAP directory so employees sign in with the credentials they already use, and you can bulk-import users straight from the directory. You configure this yourself in Settings → LDAP / AD. You must be a BongoShield Owner or Admin.
This needs network reach to a Domain Controller
BongoShield binds to your directory over the network at sign-in, so the BongoShield server must be able to reach a Domain Controller. That's the case for on-premise / dedicated installs that sit next to your directory. A cloud/pooled deployment generally can't reach an internal DC — if that's you, use SSO (Entra ID/OIDC/SAML) instead, which is the cloud-native path to the same directory.
Local BongoShield accounts always keep working alongside LDAP — adding a directory never disables them, and the break-glass Owner account stays local so you're never locked out if the directory is down.
Add a directory¶
- Go to Settings → LDAP / AD and click Add domain.
-
Fill in the form:
Field What to enter Example Display name A friendly label shown in the login dropdown Head OfficeDomain The directory's domain corp.example.comDomain controller URL The DC address; use ldaps://for TLSldaps://dc01.corp.example.com:636Service account A read-only directory account BongoShield uses to look users up at sign-in. Just the account name works — BongoShield resolves the bind identity from the domain. You can also paste a full user@domainor bind DN.svc-bongoshieldService account password The service account's password (stored encrypted; leave blank on edit to keep the current one) — Use StartTLS Turn on if you use ldap://on the standard port and upgrade to TLS with StartTLS (leave off if you're already usingldaps://)— Active (show in login) Whether this domain appears in the login "Sign in with" dropdown on The search base DN is derived automatically from the domain. Works with Active Directory or OpenLDAP (
sAMAccountName/uidmatched automatically). -
Click Test connection (in the dialog footer). BongoShield binds with the service account and reports success or the exact error — fix any issue before saving.
- Click Add domain. You can also Test connection later from each saved domain's card (the flask icon).
New directory users always start with the user role — directory groups never grant BongoShield roles. Promote people on the Users page.
Bulk-import users (Pull users)¶
Once at least one domain is configured, you can import everyone from the directory in one click:
- On Settings → LDAP / AD, click Pull users.
- BongoShield runs a dry-run preview first: how many users are in LDAP, how many would be created, how many updated, and how that compares to your licence seats (used / limit).
- If the pull would exceed your licence, BongoShield warns you before creating anyone. You can import the first users alphabetically up to the seat limit, or cancel and narrow the directory scope (e.g. a tighter OU search base) and try again.
- Confirm to import. The result shows how many were created, updated, skipped (over licence), and any errors.
New hires added to the directory later are also provisioned when they first sign in (subject to seats). See Licensing & Seats for seat behaviour.
Plugin gating kill switch¶
Settings → LDAP / AD also holds the org-wide Plugin gating switch. Turn it off to temporarily stop the Outlook add-in, Roundcube plugin and browser extension from enforcing the daily security question — every plugin still runs but lets users through — and back on to resume, without reinstalling anything. Useful during maintenance windows. See Gate Options.
Troubleshooting¶
| Symptom | Likely cause | Fix |
|---|---|---|
| Test connection fails immediately | BongoShield can't reach the DC | Confirm the DC URL/port and that the BongoShield server has network reach to the Domain Controller (firewall, VPN). |
| Test fails with an authentication/bind error | Wrong service-account name or password | Re-enter the service account; on edit, the password field is blank by design — re-enter it if it changed. |
TLS / certificate error on ldaps:// |
The DC's TLS certificate isn't trusted | Use a certificate the server trusts, or use ldap:// with StartTLS enabled. |
| Users can bind but aren't found | Directory uses a non-standard attribute or the search base is too narrow | AD sAMAccountName / LDAP uid are matched automatically; narrow/adjust the OU scope on your directory side if needed. |
| The domain doesn't appear in the login dropdown | The domain is marked inactive | Edit the domain and turn on Active (show in login). |
| Pull users says it would exceed the licence | More mailboxes than seats | Import up to the seat limit, add seats, or narrow the OU search base and re-run. |
| Cloud deployment can't reach the DC at all | Pooled/cloud install can't see an internal AD | Use SSO (Entra ID) instead, or move to a dedicated on-prem install. |