Question
How do I enable Active Directory authentication in FTK*, Lab, or Enterprise**, and create a "Trusted User"?
*FTK allows trusted users, but only for local machine accounts rather than domain accounts.
**Enterprise 6.5 and newer. For previous versions, use the article Configure AD Enterprise for LDAP Authentication (6.3 and older).
Introduction
FTK allows users to create "Trusted User" accounts, which then utilize users' Windows or domain credentials to automatically log in to FTK, Lab and Enterprise.
Procedure
- Log into Lab as an Application Administrator
- Go to Tools > Set LDAP Authentication
- Check the box "Enable LDAP Authentication"
- In the "Base LDAP URL with DN" field, enter your LDAP server and base DN as per the format shown in the example.
- Click "OK"
- Go to Database > Administer Users > Add User
- Click "Trusted User"
- Enter the domain username of the desired user
- Click "OK" again
- Grant the user the desired Role and finish adding them
Notes
- If a Domain User does not enable LDAP authentication before logging out or closing AD Lab, they may get locked out of AD Lab.
- FTK also allows trusted users, but only for local machine accounts rather then domain accounts.
- This will not work if there is an existing Lab non-LDAP user account with the desired Domain username.
- You must be logged in to Windows using the desired LDAP user to run Lab.