Configuring LDAP Settings

About LDAP Settings

Active Directory is the only directory service tested for LDAP operation with Neurons for ITSM.

You can configure and synchronize employee profiles from your LDAP Active Directory server to the Neurons for ITSM Employee business object. The Data Import Wizard imports users from selected nodes in the directory server and supports attribute mapping. It also maps profiles to linked business objects such as managers and organizational units. You can run the wizard manually or schedule synchronizations.

The LDAP server stores user passwords and retrieves them directly, and not from Neurons for ITSM.

Before Setting Up LDAP

If you see the error message Internal IP is not accessible during LDAP import for Test Connection, the server IP address may fall within a restricted range for security reasons. This check prevents unauthorized access to Ivanti servers from untrusted networks. Set the global constant EnableInternalIPForLDAP to True then try the import again.

We recommend using HTTPS or IMAPS to connect. If you connect through a VPN, contact your Ivanti Software service representative. Before setting up any LDAP synchronization actions, first set up an LDAP/LDAPS authentication provider. See Working with ADFS/SAML.

Requirements

Ensure that the Neurons for ITSM data center can connect to your LDAP server.

Use a standard LDAP browser tool outside your network to confirm that LDAP/LDAPS works with the standard ports (389 for LDAP, 636 for LDAPS).

Open the appropriate ports (389 for LDAP or port 636 for LDAPS).

Configure certificates in your LDAP server.

Request an IP address from Ivanti if you need to open LDAP only for firewall configuration.

Have LDAP login credentials ready to test import and authentication.

Contact Ivanti Support if you encounter connection issues.