Configuration Guide - Lepide Active Directory Self Service (LADSS)


1. Installing Lepide Active Directory Self Service

To start the installation, download the setup file of Lepide Active Directory Self Service from https://www.lepide.com/active-directory-self-service/download.html and save it on the disk. Make sure that the host computer meets the entire system requirements as discussed in Section System Requirements of this guide and has sufficient memory available.

  • After you have downloaded the installer file, execute the following steps to install the software:

A screenshot of a computer

Description automatically generated
Setup Wizard
  • Double-click the Lepide Active Directory Self Service installer file. Click on Run & then Yes, to run the File & The following LADSS Setup wizard will start:

A screenshot of a computer screen

Description automatically generated
Setup Wizard License Agreement
  • Click Next to continue. The following dialog box is displayed:

  • Accept the license agreement and click Next

  • The user needs to enter the Web Server Port Number that can vary from 1 to 65535. Here, 7777 is the default port number

A screenshot of a computer

Description automatically generated
Setup Wizard Port Information

  • After specifying the Port Number, click Next to continue

  • Here, the user can change the destination location for installing Lepide Active Directory Self Service software. Click Next to proceed

A screenshot of a computer program

Description automatically generated
Setup Wizard Destination Location
A screenshot of a computer

Description automatically generated
Setup Wizard Start Menu Folder

  • Click Browse if you want to change the location of the shortcuts folder in the Start Menu and then click Next

A screenshot of a computer

Description automatically generated
Setup Wizard Additional Tasks
A screenshot of a computer program

Description automatically generated
Setup Wizard Ready to Install

  • Select the additional task if required and click Next. Setup is now ready to start the installation process

A screenshot of a computer program

Description automatically generated
Setup Wizard Installing
  • Click Install to start the installation process

A screenshot of a computer

Description automatically generated
Setup Wizard Install Finished
  • When the installation process is complete, the following message box will appear on the installation wizard:

  • Click the Finish button to complete the installation process and to run the application

2. Launching the Solution

image-20260416-121835.png
System Tray Menu

Once the Solution is installed, it will be added to the system tray. Right-click on the icon and it displays four options to choose from:

  • Show Admin Login: This option lets you directly go to the Admin Login section in case you have closed the browser tab where LADSS was running previously

  • Start Server: Choosing this option will start the application server

  • Stop Server: Choosing this option will stop the application server

  • Exit Tray: Choosing this option will remove the application from the system tray

3. Admin Login

Getting started with Lepide Active Directory Self Service is a straightforward process. As soon as you launch the Solution, you will be prompted to login. Use admin as the default username and password for first time use.


A screenshot of a computer

Description automatically generated
Admin Login

4. Add Domain

When you log into the Solution, you need to add the domain for which the self-service actions are to be configured.


Manage Domain

To add a domain, follow the steps below:

  • Type the domain name in the Domain text field

  • Type the name of the primary domain controller in the Domain Controller text field. You can also provide the IP Address instead of the system name

  • Type the domain administrator name in the Username text field of the user who has the privilege to reset a password and unlock an account in the particular domain

  • Provide the domain admin password in the Password field

  • Click the Save button

  • The new domain details will be verified and if correct, the domain will be successfully added. Now, Lepide Active Directory Self Service is ready to be configured as required for self-service activities

The User can also restore the environment and added domain (if added earlier), after choosing a valid backup file created earlier and then selecting Restore Database Option

4.1 User Account Privileges

The user account provided here should be a member of the following groups: Administrators, Domain Admins, Enterprise Admins, Schema Admins, Group Policy Creator and Owner.

Follow the steps below to provide the rights mentioned above:

  • Go to Administrative Tools

  • Open Active Directory Users and Computers

  • Select User Properties

  • Click Member Of

  • Click Add Group

  • Select the following Groups: Administrators, Domain Admins, Enterprise Admins, Schema Admins, Group Policy Creator and Owner

  • Click Apply and then click OK

A screenshot of a computer

Description automatically generated
Administrator Properties

4.2 Manage Domain

A screenshot of a computer

Description automatically generated
Manage Domain

Multiple domains can be added and managed with Lepide Active Directory Self Service. Go to the manage domain section and enter the details for the domain that is to be added. Existing domain details can also be edited, and a particular domain can be set as the default domain.

5. User Enrollment

This section allows you to enroll users with the software. You can send invites to users through email and ask them to enroll with the Solution or bulk enroll them using CSV files.

5.1 Invite Users to Enroll

You can notify domain users via email to enroll themselves to use features like Self Reset Password, Unlock Account, Update Active Directory Attributes, and Automatic Password Reset. You can schedule notifications to be sent at prescribed times to all unenrolled users, for existing policies.


A screenshot of a computer

Description automatically generated
Enrollment Notifications

5.1.1 Enroll Users through Notifications

You can send enrollment Notifications directly to all the OU Members that come under the selected policy. To use this feature follow the steps below:

  • Click the enrollment notification tab

  • Select Policy from the drop-down list displayed

  • Enter the Policy Title in the displayed Title text field

  • Enter the policy text to be displayed in the text field

  • Select Notification Interval at Logon if you want the notification to be delivered immediately after the user login

  • Select schedule on daily, weekly and monthly basis from the schedule drop down list

  • Select the time to display a notification

  • Click Save to finish

5.1.2 Schedule New Notification

You can create new notifications for sending notifications to users at scheduled times. Click the Add Notification tab to get started:

  • Provide a name for the schedule.

  • Provide a Description.

  • Select the policy which is to be applied to the users who enroll themselves.

  • Select the time interval when the notification is to be sent. Choose from daily, weekly or monthly options.

  • In the mail setting section, provide the sender's email address.

  • Provide a mail subject for the notification email.

  • Provide mail content that is to be delivered to users. The current URL (http://localhost:7777/LADSS/UserLoginAction.do?method=populate) is for demonstration purposes only and so will need to be edited.

  • Click Save to finish.

A screenshot of a computer

Description automatically generated
Enrollment Notification

5.2 Bulk Enrollment

This section allows you to enroll multiple users at once using a CSV file. You can also send notifications to users who have been newly enrolled. The notification mail generally contains Question and Answer details for the user to authenticate enrollment from their behalf.

To enroll users, follow the steps below:

  • Select the policy for which the preselected users are to be enrolled.

  • Click Browse and select the CSV file which contains user data.

  • Select the checkbox 'If already enrolled then skip enrollment' to avoid enrollment of already enrolled users.

  • Select the checkbox Automatically disenroll users deleted from AD to remove enrollment of those users who have been deleted from AD.

  • Select Send enrollment status notification to Users to let respective users know about their enrollment status. If selected:

    • Provide the admin mail address from whom the notification email will be sent

    • Provide a suitable email subject

    • Provide email content for the body section of the email

  • Click Enroll to successfully enroll users in bulk

A screenshot of a computer

Description automatically generated
Enrollment through CSV

5.2.1 Download CSV

Click Download CSV to download a blank CSV file with the correct format to enter data. Provide a username, a question and then an answer. For multiple questions, provide a question and then an answer and then the next question and next answer. Check the sample CSV image below:

A screenshot of a computer

Description automatically generated
Sample CSV File

6. Policy Configuration

Policies help to preconfigure self-service actions that can be performed by domain users. Once a domain is added, a default policy gets automatically created for that particular domain. By default, self-password reset, unlock account, and on behalf actions are included. More settings such as expiry notification schedule, self-update attributes and automatic account unlock actions can be configured. This default policy can be edited or new policies can be created as per requirements.

In order to manage a policy, follow the steps below:

  • Provide a policy name

  • Choose the domain for which policy is to be configures from the Select Domain drop-down menu

  • Select required OU's

  • The next step is to set permissions for the policy

    • Check self-password reset option if you want domain users to reset their AD account password on their own

    • Check Self Unlock Account option if you want domain users to unlock their account on their own

    • Check Self Update Attributes option if you want domain users to self-update their AD attributes. You can choose which attributes can be edited

    • Check Reset Password on behalf of User option if you want domain users to reset password on behalf of their coworkers

    • Check Unlock Account on behalf of User option if you want domain users to unlock account on behalf of their coworkers

    • Check Set Password Expiry Notification option to preset password expiry reminder

    • Check Automatic User Account Unlock option to allow software to automatically unlock expired AD accounts after a specified time interval

  • Click Save to finish policy configuration.

A screenshot of a computer

Description automatically generated
Policy Configuration

7. Multifactor Authentication

Lepide Active Directory Self Service allows users to authenticate using multiple options and validate their account for unlock and reset activities. Users can validate through:

  1. Security Question and Answer

  2. One Time Password

Before performing any configuration, select the policy for which these authentication settings will be applicable. Select the appropriate policy from the list of configured policies provided in the Select Policy drop-down menu.

7.1 Security Question and Answer Configuration

You can manage the Predefined Questions from Manage Predefined Questions Drop down Tab displayed above Question and Answer Policies.

A screenshot of a computer

Description automatically generated
A screenshot of a computer

Description automatically generated
Select Policy

Question and Answer Settings

Enter the details as given in the table below to perform Q&A settings.

Number of Predefined Questions

Mention the number of predefined questions that you want the domain users to select while enrolling. (Less than 10 allowed)

Number of User Defined Questions

Mention the number of user-defined questions that you want the domain users to create. (Less than 10 allowed)

Number of Characters in User Defined Question

Mention the number of characters that a user defined question can contain. (Minimum 5 characters and maximum 225 characters allowed)

Number of Characters in an Answer

Mention the number of characters that an answer can contain.

(Minimum 5 characters and maximum 225 characters allowed)

7.2 One Time Password Configuration

This section allows you to configure OTP settings for self-service actions.

You can either enable sending OTP through both SMS and email or either one of them. If needed, the OTP notification text can be edited.

You can also use the SMS and email settings link to perform required settings (if this has not been done previously).

A screenshot of a computer

Description automatically generated
Enable SMS Configuration

7.3 Authentication Mode

This option appears when both security questions and OTP have been enabled. You can choose whether users authenticate themselves with both Q&A and OTP or just with either one of them.

Select Authentication Mode

7.4 Disenrollment

A screenshot of a computer

Description automatically generated
Disenrollment

Check this to dis-enroll all currently enrolled users with previous policies. If you have made some changes in the authentication modes or created new policies and you wish users to register as per the new settings, you can select this option to automatically dis-enroll them.

Users will receive a notification email informing them that they need to re-enroll with LADSS. You can select the mail sender and edit the email subject and content.

8. E-mail Server Settings

You need to configure the Mail server for sending Scheduled Reports from the Solution. You can edit the settings later if you want to use another Server as per your mail server. Multiple exchange servers can also be configured for using specific mail servers for different domains.

A screenshot of a computer

Description automatically generated
Email Server Settings
  • To perform mail server settings, click the E-mail Server Settings option under the Configuration tab.

To configure email server settings, follow the steps below:

  • Exchange Mail Server: Type the Exchange Mail Server Name or IP Address.

  • Port: Enter mail server port number.

  • Use SSL: Enable secure socket layer connection if applicable.

  • SMTP Authentication: Provide SMTP Username and SMTP Password in the given fields.

  • From Address: Provide sender's Email address in the given field. This email address will be used for sending all the scheduled reports.

  • Click Save to complete adding email server. It is recommended that you use the Send Test Email button to test the mail server configuration.

9. SMS Server Settings

To send OTP via SMS, you need a GSM modem and a SIM card for communication. Install the modem on the system where the software is installed. SMS data charges will apply as per your service provider.

Alternatively, you can configure SMS Server Settings through SMS Gateway via get & Post Method by providing the HTTP/(s) Url and Parameters along with a mobile Number as shown in the image below:

A screenshot of a computer

Description automatically generated
SMS Server Settings

To configure SMS server settings through GSM Gateway, follow the steps below:

  • The SMS Provider is by default selected as GSM Modem

  • Enter the COM Port number as 3

  • Enter the Number of Attempts to be made for sending the OTP

  • Enter the Time-out value until which the software will attempt sending the SMS

  • Enter the Baud Rate value. It is the rate at which information is transferred into your communication channel

  • Enter a valid Recipient Mobile Number from which the SMS will be sent

  • Click Save to complete the SMS settings. It is recommended that you use the Send Test SMS button to test the SMS server configuration.


A screenshot of a computer

Description automatically generated
SMS Server Settings

10. Connection Settings

Web Server settings can be updated to change the port number. By default, the preconfigured HTTP port number is 7777. The given port number is used to connect with the software from anywhere in the domain.

  • Configure HTTP Port: You can change and enter another port number as per your priorities

  • Set User Session Expiry duration: Select the time interval after which user session will automatically expire if no activity has been performed in the selected time

  • SSL Port [HTTP]: Select the Use SSL Port [HTTPS] check box if Secure Socket Layer (SSL) is used in your network. LADSS automatically uses a default certificate to populate the HTTPS port field

  • To import your own SSL trusted certificate, click on the SSL Certification Tool tab. Enter the required company details and generate a CSR file. Follow the onscreen process to successfully incorporate SSL security.

A screenshot of a computer

Description automatically generated
Connection Settings

11. Password Synchronization

Password Synchronization enables the synchronization of third party applications and allows you to reset those particular passwords from the solution itself. Currently, password sync is supported for Office 365, IBM AS400 and Google Apps.

Follow the steps below to enable password synchronization:

  • Enter profile name of your choice

  • Provide a description

  • Select the policy on which the settings will be applicable

  • Now select the Application type

A screenshot of a computer

Description automatically generated
Password Synchronization

Application type details for IBM:

  • Enter IP Address of your IBM Server.

  • Enter Username of the server account.

  • Enter Password

A screenshot of a computer

Description automatically generated
Application Type Details

Application type details for Google Apps:

  • Browse and select the P12 Key File. To generate a P12 key file, refer to this link:

  • https://www.lepide.com/guide/ladss-generate-P12-key.pdf

  • Enter the service account email address.

  • Enter Domain name

  • Enter Username

A screenshot of a computer

Description automatically generated
Application Type Details for Google Apps

Application type details for Office 365:

  • Enter the domain name of your Office 365 account.

  • Enter a valid username

  • Enter password

A screenshot of a computer

Description automatically generated
Application Type Details for Office 365

You can test the connection in every case after entering the respective details.

Account Link methods

  • Link AD users automatically: Use this method to link all users within the selected policy automatically.

  • Link as per user's request: Use this method to link accounts when a particular user requests for synchronization.

  • Click Save to finish the password sync settings.

A screenshot of a computer

Description automatically generated
Account Link Methods

12. Backup/Restore Database

The Backup/Restore Database settings section comprises of three sub-sections:

  • Create New Backup

  • Set Schedule Time

  • Restore Backup

12.1 Create New Backup

In this section you can create a backup of the application's existing database. Running a database backup will create a database export file and store it in your system.

To create a backup you need to click on the Backup button.

Lepide Active Directory Self Service stores the backup in a zipped file format in its system files where the solution was installed. For example: C:\Program Files\Lepide Active Directory Self Service\tomcat\bin\backup

A screenshot of a computer

Description automatically generated
Create Backup

12.2 Set Backup Schedule

To schedule running a database backup you need to execute the following steps:

  • Select the Daily, Weekly or Monthly option.

  • Select the backup process start time from the dropdown.

  • Click on the Set button to complete the process.

You can enable or disable the automatic backup schedule option by using the given checkbox.

A screenshot of a computer screen

Description automatically generated
Set Schedule Time

12.3 Restore Backup

This section explains how to use an existing backup to restore the application's database.

A blue rectangle with white text

Description automatically generated
Restore Backup

Use the Browse button to select a backup file. Click the Restore button to restore the application's database using backup.

13. GUI Rebranding

You can customize the application's GUI by using your company’s logo and banner image. To rebrand the GUI of the application you need to execute the following steps:

  • Click on the Browse button in the Select Banner Image field and browse a Banner Image file as per your choice. Click on the Set button to upload the image.

  • Click on the Browse button in the Select Login Image field to browse a Login Image file as per your choice. Click on the Set button to upload the image.

A screenshot of a computer

Description automatically generated
GUI Rebranding

14. Captcha Settings

You can enable captcha on the login pages and other self-service activity pages to ensure more authenticity and an added layer of security.

Select the first checkbox to enable captcha on the Admin Login page.

For enabling captcha on rest of the options, first select the respective domain.

  • Select the second checkbox to enable captcha on the User Login page.

  • Select the third checkbox to enable captcha on the Unlock Account operation page.

  • Select the fourth checkbox to enable captcha on the Reset Password operation page.

A screenshot of a computer

Description automatically generated
Captcha Settings

15. Uninstalling the Solution

To remove Lepide Active Directory Self Service, follow the instructions below:

  • Click Start, go to Control Panel/Settings. The Control Panel window appears.

  • Double click the Add or Remove Programs icon or the Program and Features option (Windows 8 and above). A list of the programs installed on your computer appears.

  • Select Lepide Active Directory Self Service and click the Uninstall button. A backup instruction message appears onscreen before un-installing the software.

A screenshot of a computer error

Description automatically generated
Uninstall
  • Click the Yes button to take a backup at your preferred location and click Ok.

A screenshot of a computer

Description automatically generated
Browse for Folder
A screenshot of a computer error

Description automatically generated
Confirm Uninstallation
  • Click Yes to start the un-installation process.

  • The uninstallation process is in progress.

A screenshot of a computer error

Description automatically generated
Uninstall Status

  • The solution confirms whether you wish to keep the current settings or delete them. Click Yes/No as required.

A screenshot of a computer error

Description automatically generated
Choose Whether to Keep the Current Settings
  • Lepide Active Directory Self Service will be successfully uninstalled from your computer system.

A screenshot of a computer

Description automatically generated
Uninstall Confirmation

  • To remove the remaining elements, delete its program installation folder manually and then empty the Recycle Bin as well.

  • After following the steps above, Lepide Active Directory Self Service will be uninstalled successfully from your computer system.

16. License Activation

The free version of Lepide Active Directory Self Service offers a license for 50 Users only. When enrolling more than 50 Users, you will need to purchase additional licenses.

To purchase licenses, contact our sales team at sales@lepide.com.

If you are using the free version of the product, follow these steps to purchase a license and activate it following these steps:

  • Open the web interface of software and login with administrator credentials

A screenshot of a computer

Description automatically generated
Login
  • The Dashboard is the default screen that opens up.

A screenshot of a computer

Description automatically generated
Dashboard

  • Go to the Support tab and click on License in the left pane.


A screenshot of a computer

Description automatically generated
License Details

  • Click on the Request License link on the right-top corner. License request file is saved by default on this location: C:\Documents and Settings\User\My Documents\Downloads by the name of adss(alphanumeric code).request.

  • Send this file to the Lepide Software sales team at sales@lepide.com.

  • Lepide will send you a license activation file as per the license purchased.

  • Save that file to the local disk.

A screenshot of a computer

Description automatically generated
Select License File

  • Open software web-interface and Go to the Support, License page. And click on Browse button against the Select License File field.

  • Locate and add the license activation file to the path provided.

A screenshot of a computer

Description automatically generated
: License Successfully Applied
  • Click on the Apply button to activate the license. The following message appears.

  • Click on OK and the license details will be displayed on the screen:

A close-up of a document

Description automatically generated
License Details