Skip to main content

Import users from private AD

Import users from your private Active Directory to use them in oneclick™.
Proceed as follows:

Preparations in your Active Directory​

To import your existing AD users into oneclick™, an Active Directory must be set up on your Windows Server.

Email address as required field

For all users to be imported (including the administrator), a publicly reachable e-mail address must be entered in the E-mail field. This e-mail address is used to create the user in oneclick™.
An email in the "User logon name (UPN)" field is not considered by oneclick™.

Add email address for users​

  1. Open Active Directory Users and Computers.
  2. Navigate to your Organizational Unit (e.g. Users).
  3. Double-click a User.
  4. Open the General tab.
  5. Enter a publicly reachable email address in the E-mail field.
  6. Click OK.
    Sue Perman Properties dialog with the E-mail field filled in and the OK button highlighted

Create a security group for import​

Create a new group in your Active Directory that contains only the users to be imported into oneclick™.

System groups

Do not use Active Directory system groups. These are not considered in oneclick™.


  1. Open the desired Organizational Unit (e.g. Users) on the left.
  2. Right-click in the right area.
  3. Select New → Group.
  4. Enter the desired name in the Group name field (e.g. oc-users).
  5. Click OK.
    New Object - Group dialog with the Group name field filled in and the OK button highlighted

Add users to the group​

  1. Double-click the newly created group.
    Active Directory Users and Computers list with the newly created oc-user group selected
  2. Open the Members tab.
  3. Click Add.
    oc-user Properties dialog on the Members tab with the Add button highlighted
  4. Enter the desired users and click Check Names.
  5. Click OK.
    Select Users, Contacts, Computers dialog with a user name entered and the Check Names button highlighted

Assign "Domain Users" group​

Assign the AD group "Domain Users" and, if required, additional permission groups to the new AD group.

  1. Open the group and switch to the Member Of tab.
  2. Click Add.
    oc-user Properties dialog on the Member Of tab with the Add button highlighted
  3. Enter Domain Users and click Check Names.
  4. Click OK.
    Select Groups dialog with Domain Users entered and the Check Names and OK buttons highlighted
  5. Click Apply and then OK.
    oc-user Properties dialog on the Member Of tab showing the added Domain Users group with the Apply and OK buttons highlighted

Connect Active Directory to oneclick™​

  1. Check in advance how many user licenses are required and request them in the licenses section.
    Alternatively, select a demo license in the final step of the import and assign the appropriate license later.
  2. Optionally create groups in oneclick™ to which the users from the Active Directory should be assigned.
    By default, you can select the oneclick™ group "Administrator".
  3. Open the Resources menu and go to Connections, then click the Plus icon.
    Connections list with the Plus icon highlighted
  4. Select Directory Service and then Private Directory Service.
    New connection wizard with Directory Service and Private Directory Service selected as connection type
  5. Select an on-premises resource or a cloud resource where your Active Directory is located in oneclick™, then click Next.
    Make sure to use the correct port:
    • LDAP: 389
    • LDAPS: 636
      New connection Destination step with a destination selected and the Next button highlighted
  6. Enter a Name and select the protocol LDAP or LDAPS.
    New connection Settings step with the Name field and LDAP protocol dropdown highlighted
  7. Enter the User. Use a service user.
    A standard domain user without special permissions (role "Domain User") is sufficient.
    For security reasons, do not use an administrator account.
    Use either:
  8. Enter the Password of the service user.
  9. Verify the Base DN and optionally the Base DN for users.
    Enter the values according to your Active Directory structure, e.g.: OU=UsersOu,DC=company,DC=local (without spaces).
  10. Under User matching, specify how oneclick™ identifies existing users.
    Under Identify existing users, select one of the following options:
    • By the object id of the directory service: oneclick™ matches users based on the object ID. This is the default setting. The match remains in place even if the e-mail address changes in the directory service.
    • By e-mail address only: oneclick™ matches users exclusively based on the e-mail address. For each unknown e-mail address, oneclick™ creates a separate user. This option is suitable, for example, if two directory services contain the same people and you want to manage them as separate users in oneclick™.
  11. Click Next.
    New connection Settings step with the User, Password, and Base DN fields and the Identify existing users dropdown highlighted, and the Next button highlighted
  12. In the next step, optionally enter specific directory service groups or leave the field empty and click Load directory service groups.
  13. Assign the directory service groups to the corresponding oneclick™ groups.
    Click a Directory service group and select the appropriate oneclick™ group.
  14. Click Next.
    New connection Groups step with the Load directory service groups button and a group assignment dropdown highlighted, and the Next button highlighted
  15. Check the group assignment and the displayed user data. The users are displayed in separate sections depending on their status. Each section shows the number of users it contains in the heading. Sections without users are not displayed.
    • Users that cannot be imported: oneclick™ does not import these users. In the Reason column, you can see why the import is not possible, for example because no e-mail address is stored in the directory service or because the user already exists in another division.
    • New users: These users do not yet exist in oneclick™. oneclick™ imports them from the directory service and creates them when you save.
    • Existing users: These users already exist in oneclick™. Their data is replaced with the information stored in the directory service. In the Matched user account column, you can see the assigned oneclick™ user account and the basis for the match, for example the object ID or e-mail address. A Plus icon before a group assignment indicates a new group assignment. When you save, oneclick™ also adds the user to the assigned oneclick™ group.
Differences in user data

If the e-mail address in the directory service differs from the e-mail address of the existing user account, oneclick™ also displays the previously stored address. If saving changes the e-mail address of the existing user account, oneclick™ displays a highlighted warning. Check this warning before you continue.

  1. Click Next. New connection Users step showing the group assignments and user sections with the Next button highlighted
  2. Select a user license with sufficient capacity.
  3. Click Save.
    New connection License step with a user license selected and the Save button highlighted

Your Active Directory is now connected and the users are available in oneclick™.

Log in to oneclick™​

Your users are created in oneclick™ using the email address stored in Active Directory.
Users log in with this email address and their AD password.

Depending on the configuration, login with a oneclick™ password may also be possible.
For more information, see the article Login with AD credentials.

Changes in Active Directory​

If you change data in your AD and want those changes to take effect in oneclick™, you must synchronize your connected AD.
See the article Synchronize connected Active Directory.