Active Directory
Audience:
Low-code Engineers,System/Security AdministratorsSkill Prerequisites:
Actions,Tokens,Connectors,Users
The Active Directory add-on lets users sign in to your app with their Microsoft Active Directory account. It adds an Active Directory (LDAP) connector type, which holds the domain and the account the site connects with, and the User Login (MS Active Directory) action. The action checks the username and password against Active Directory, creates or updates a matching site account, keeps site roles in step with directory groups, and signs the user in.
This add-on is the Active Directory add-on (PlantAnApp.ActiveDirectory). It's installed separately and needs the MSAD feature in your license. If it isn't licensed, the action fails with a "not licensed" error. If you don't see the action in the User Management group, or the Active Directory (LDAP) connector type, the add-on isn't installed.
Choosing an action
| Action | What it does | Use it to |
|---|---|---|
| User Login (MS Active Directory) | Checks the password against Active Directory, creates or updates a matching site account, maps groups to roles, and signs the user in. | Let employees sign in to an intranet app with their domain account. |
To sign in users with a site account, use User Login from the User Management add-on. For an OpenLDAP server, use the OpenLDAP add-on.
Setting it up
-
Create the connector. Add a connector of type Active Directory (LDAP). See Connectors, or create it with Add Connector.
Setting Description Domain The domain or domain controller to connect to, for example example.com.Principal Username An account the site uses to connect to Active Directory. If it's empty, the site connects with the identity its application pool runs as. Principal Password The password of that account. It's stored encrypted. -
Build the login form. Add
UsernameandPasswordfields and a button. Use HTTPS on the page, because the password is sent from the browser. -
Add the action. Add User Login (MS Active Directory) to the button. Pick the connector, set Path to the part of the directory whose users may sign in, for example
OU=Staff,DC=example,DC=com, and map the fields to Username and Password. Usernames are account names (SAMAccountName), such asjsmith, without the domain. -
Map profile values and roles, if you need them. User Attribute Mapping copies directory attributes to profile properties, and User Roles Mapping keeps site roles in step with directory groups.
-
Handle errors. Add On Error actions, for example a message or a redirect. End users only see a general login failure. The detailed reason is in the log and in the
[Exception]token.
The action isn't available in Automation (workflows and scheduled jobs), because signing in needs a browser to receive the login cookie. Test Connector doesn't support this connector type, so test the setup by signing in.
Site accounts and roles
- One account per directory user. The first sign-in creates a site account called
AD-followed by the user's security ID (SID). It's authorized and gets a random password, so the user can only sign in through the action. Renaming the user in Active Directory doesn't create a second account. - Profile values are copied on every sign-in. The first name, last name, email, display name and mapped attributes are updated each time, so changes in Active Directory flow to the site. Mapped profile properties must exist on the site.
- Groups map to roles. For each row in User Roles Mapping, the action adds the role if the user is in the group, and removes it if they aren't. Roles outside the mapping aren't touched. Only map powerful roles, such as
Administrators, to groups you control closely. - Existing site accounts aren't linked. A user who already has a site account with the same email gets a second, separate account.
Security
- The connection isn't encrypted by the action. It connects with a simple bind and doesn't turn on SSL, so passwords may travel over the network unencrypted. Protect the connection between the web server and the domain controller.
- Site account status isn't checked. Once Active Directory accepts the password, the user is signed in, even if the site account is unauthorized or locked. To block a user, disable them in Active Directory or move them out of Path.
- Email as username isn't supported. If the site uses the email as the username, sign-ins after the first one fail. Don't use the add-on on such sites.
For all settings and an example, see User Login (MS Active Directory). For all add-ons, see Add-ons.
Revised 10/02/2026