1. Installing Lepide Active Directory Self Service
To start the installation, download the setup file of Lepide Active Directory Self Service from https://www.lepide.com/active-directory-self-service/download.html and save it on the disk. Make sure that the host computer meets the entire system requirements as discussed in Section System Requirements of this guide and has sufficient memory available.
After you have downloaded the installer file, execute the following steps to install the software:
Double-click the Lepide Active Directory Self Service installer file. Click on Run & then Yes, to run the File & The following LADSS Setup wizard will start:
Click Next to continue. The following dialog box is displayed:
Accept the license agreement and click Next
The user needs to enter the Web Server Port Number that can vary from 1 to 65535. Here, 7777 is the default port number
After specifying the Port Number, click Next to continue
Here, the user can change the destination location for installing Lepide Active Directory Self Service software. Click Next to proceed
Click Browse if you want to change the location of the shortcuts folder in the Start Menu and then click Next
Select the additional task if required and click Next. Setup is now ready to start the installation process
Click Install to start the installation process
When the installation process is complete, the following message box will appear on the installation wizard:
Click the Finish button to complete the installation process and to run the application
2. Launching the Solution
Once the Solution is installed, it will be added to the system tray. Right-click on the icon and it displays four options to choose from:
Show Admin Login: This option lets you directly go to the Admin Login section in case you have closed the browser tab where LADSS was running previously
Start Server: Choosing this option will start the application server
Stop Server: Choosing this option will stop the application server
Exit Tray: Choosing this option will remove the application from the system tray
3. Admin Login
Getting started with Lepide Active Directory Self Service is a straightforward process. As soon as you launch the Solution, you will be prompted to login. Use admin as the default username and password for first time use.
4. Add Domain
When you log into the Solution, you need to add the domain for which the self-service actions are to be configured.
To add a domain, follow the steps below:
Type the domain name in the Domain text field
Type the name of the primary domain controller in the Domain Controller text field. You can also provide the IP Address instead of the system name
Type the domain administrator name in the Username text field of the user who has the privilege to reset a password and unlock an account in the particular domain
Provide the domain admin password in the Password field
Click the Save button
The new domain details will be verified and if correct, the domain will be successfully added. Now, Lepide Active Directory Self Service is ready to be configured as required for self-service activities
The User can also restore the environment and added domain (if added earlier), after choosing a valid backup file created earlier and then selecting Restore Database Option
4.1 User Account Privileges
The user account provided here should be a member of the following groups: Administrators, Domain Admins, Enterprise Admins, Schema Admins, Group Policy Creator and Owner.
Follow the steps below to provide the rights mentioned above:
Go to Administrative Tools
Open Active Directory Users and Computers
Select User Properties
Click Member Of
Click Add Group
Select the following Groups: Administrators, Domain Admins, Enterprise Admins, Schema Admins, Group Policy Creator and Owner
Click Apply and then click OK
4.2 Manage Domain
Multiple domains can be added and managed with Lepide Active Directory Self Service. Go to the manage domain section and enter the details for the domain that is to be added. Existing domain details can also be edited, and a particular domain can be set as the default domain.
5. User Enrollment
This section allows you to enroll users with the software. You can send invites to users through email and ask them to enroll with the Solution or bulk enroll them using CSV files.
5.1 Invite Users to Enroll
You can notify domain users via email to enroll themselves to use features like Self Reset Password, Unlock Account, Update Active Directory Attributes, and Automatic Password Reset. You can schedule notifications to be sent at prescribed times to all unenrolled users, for existing policies.
5.1.1 Enroll Users through Notifications
You can send enrollment Notifications directly to all the OU Members that come under the selected policy. To use this feature follow the steps below:
Click the enrollment notification tab
Select Policy from the drop-down list displayed
Enter the Policy Title in the displayed Title text field
Enter the policy text to be displayed in the text field
Select Notification Interval at Logon if you want the notification to be delivered immediately after the user login
Select schedule on daily, weekly and monthly basis from the schedule drop down list
Select the time to display a notification
Click Save to finish
5.1.2 Schedule New Notification
You can create new notifications for sending notifications to users at scheduled times. Click the Add Notification tab to get started:
Provide a name for the schedule.
Provide a Description.
Select the policy which is to be applied to the users who enroll themselves.
Select the time interval when the notification is to be sent. Choose from daily, weekly or monthly options.
In the mail setting section, provide the sender's email address.
Provide a mail subject for the notification email.
Provide mail content that is to be delivered to users. The current URL (http://localhost:7777/LADSS/UserLoginAction.do?method=populate) is for demonstration purposes only and so will need to be edited.
Click Save to finish.
5.2 Bulk Enrollment
This section allows you to enroll multiple users at once using a CSV file. You can also send notifications to users who have been newly enrolled. The notification mail generally contains Question and Answer details for the user to authenticate enrollment from their behalf.
To enroll users, follow the steps below:
Select the policy for which the preselected users are to be enrolled.
Click Browse and select the CSV file which contains user data.
Select the checkbox 'If already enrolled then skip enrollment' to avoid enrollment of already enrolled users.
Select the checkbox Automatically disenroll users deleted from AD to remove enrollment of those users who have been deleted from AD.
Select Send enrollment status notification to Users to let respective users know about their enrollment status. If selected:
Provide the admin mail address from whom the notification email will be sent
Provide a suitable email subject
Provide email content for the body section of the email
Click Enroll to successfully enroll users in bulk
5.2.1 Download CSV
Click Download CSV to download a blank CSV file with the correct format to enter data. Provide a username, a question and then an answer. For multiple questions, provide a question and then an answer and then the next question and next answer. Check the sample CSV image below:
6. Policy Configuration
Policies help to preconfigure self-service actions that can be performed by domain users. Once a domain is added, a default policy gets automatically created for that particular domain. By default, self-password reset, unlock account, and on behalf actions are included. More settings such as expiry notification schedule, self-update attributes and automatic account unlock actions can be configured. This default policy can be edited or new policies can be created as per requirements.
In order to manage a policy, follow the steps below:
Provide a policy name
Choose the domain for which policy is to be configures from the Select Domain drop-down menu
Select required OU's
The next step is to set permissions for the policy
Check self-password reset option if you want domain users to reset their AD account password on their own
Check Self Unlock Account option if you want domain users to unlock their account on their own
Check Self Update Attributes option if you want domain users to self-update their AD attributes. You can choose which attributes can be edited
Check Reset Password on behalf of User option if you want domain users to reset password on behalf of their coworkers
Check Unlock Account on behalf of User option if you want domain users to unlock account on behalf of their coworkers
Check Set Password Expiry Notification option to preset password expiry reminder
Check Automatic User Account Unlock option to allow software to automatically unlock expired AD accounts after a specified time interval
Click Save to finish policy configuration.
7. Multifactor Authentication
Lepide Active Directory Self Service allows users to authenticate using multiple options and validate their account for unlock and reset activities. Users can validate through:
Security Question and Answer
One Time Password
Before performing any configuration, select the policy for which these authentication settings will be applicable. Select the appropriate policy from the list of configured policies provided in the Select Policy drop-down menu.
7.1 Security Question and Answer Configuration
You can manage the Predefined Questions from Manage Predefined Questions Drop down Tab displayed above Question and Answer Policies.
Question and Answer Settings
Enter the details as given in the table below to perform Q&A settings.
Number of Predefined Questions | Mention the number of predefined questions that you want the domain users to select while enrolling. (Less than 10 allowed) |
Number of User Defined Questions | Mention the number of user-defined questions that you want the domain users to create. (Less than 10 allowed) |
Number of Characters in User Defined Question | Mention the number of characters that a user defined question can contain. (Minimum 5 characters and maximum 225 characters allowed) |
Number of Characters in an Answer | Mention the number of characters that an answer can contain. (Minimum 5 characters and maximum 225 characters allowed) |
7.2 One Time Password Configuration
This section allows you to configure OTP settings for self-service actions.
You can either enable sending OTP through both SMS and email or either one of them. If needed, the OTP notification text can be edited.
You can also use the SMS and email settings link to perform required settings (if this has not been done previously).
7.3 Authentication Mode
This option appears when both security questions and OTP have been enabled. You can choose whether users authenticate themselves with both Q&A and OTP or just with either one of them.
7.4 Disenrollment
Check this to dis-enroll all currently enrolled users with previous policies. If you have made some changes in the authentication modes or created new policies and you wish users to register as per the new settings, you can select this option to automatically dis-enroll them.
Users will receive a notification email informing them that they need to re-enroll with LADSS. You can select the mail sender and edit the email subject and content.
8. E-mail Server Settings
You need to configure the Mail server for sending Scheduled Reports from the Solution. You can edit the settings later if you want to use another Server as per your mail server. Multiple exchange servers can also be configured for using specific mail servers for different domains.
To perform mail server settings, click the E-mail Server Settings option under the Configuration tab.
To configure email server settings, follow the steps below:
Exchange Mail Server: Type the Exchange Mail Server Name or IP Address.
Port: Enter mail server port number.
Use SSL: Enable secure socket layer connection if applicable.
SMTP Authentication: Provide SMTP Username and SMTP Password in the given fields.
From Address: Provide sender's Email address in the given field. This email address will be used for sending all the scheduled reports.
Click Save to complete adding email server. It is recommended that you use the Send Test Email button to test the mail server configuration.
9. SMS Server Settings
To send OTP via SMS, you need a GSM modem and a SIM card for communication. Install the modem on the system where the software is installed. SMS data charges will apply as per your service provider.
Alternatively, you can configure SMS Server Settings through SMS Gateway via get & Post Method by providing the HTTP/(s) Url and Parameters along with a mobile Number as shown in the image below:
To configure SMS server settings through GSM Gateway, follow the steps below:
The SMS Provider is by default selected as GSM Modem
Enter the COM Port number as 3
Enter the Number of Attempts to be made for sending the OTP
Enter the Time-out value until which the software will attempt sending the SMS
Enter the Baud Rate value. It is the rate at which information is transferred into your communication channel
Enter a valid Recipient Mobile Number from which the SMS will be sent
Click Save to complete the SMS settings. It is recommended that you use the Send Test SMS button to test the SMS server configuration.
10. Connection Settings
Web Server settings can be updated to change the port number. By default, the preconfigured HTTP port number is 7777. The given port number is used to connect with the software from anywhere in the domain.
Configure HTTP Port: You can change and enter another port number as per your priorities
Set User Session Expiry duration: Select the time interval after which user session will automatically expire if no activity has been performed in the selected time
SSL Port [HTTP]: Select the Use SSL Port [HTTPS] check box if Secure Socket Layer (SSL) is used in your network. LADSS automatically uses a default certificate to populate the HTTPS port field
To import your own SSL trusted certificate, click on the SSL Certification Tool tab. Enter the required company details and generate a CSR file. Follow the onscreen process to successfully incorporate SSL security.
11. Password Synchronization
Password Synchronization enables the synchronization of third party applications and allows you to reset those particular passwords from the solution itself. Currently, password sync is supported for Office 365, IBM AS400 and Google Apps.
Follow the steps below to enable password synchronization:
Enter profile name of your choice
Provide a description
Select the policy on which the settings will be applicable
Now select the Application type
Application type details for IBM:
Enter IP Address of your IBM Server.
Enter Username of the server account.
Enter Password
Application type details for Google Apps:
Browse and select the P12 Key File. To generate a P12 key file, refer to this link:
https://www.lepide.com/guide/ladss-generate-P12-key.pdf
Enter the service account email address.
Enter Domain name
Enter Username
Application type details for Office 365:
Enter the domain name of your Office 365 account.
Enter a valid username
Enter password
You can test the connection in every case after entering the respective details.
Account Link methods
Link AD users automatically: Use this method to link all users within the selected policy automatically.
Link as per user's request: Use this method to link accounts when a particular user requests for synchronization.
Click Save to finish the password sync settings.
12. Backup/Restore Database
The Backup/Restore Database settings section comprises of three sub-sections:
Create New Backup
Set Schedule Time
Restore Backup
12.1 Create New Backup
In this section you can create a backup of the application's existing database. Running a database backup will create a database export file and store it in your system.
To create a backup you need to click on the Backup button.
Lepide Active Directory Self Service stores the backup in a zipped file format in its system files where the solution was installed. For example: C:\Program Files\Lepide Active Directory Self Service\tomcat\bin\backup
12.2 Set Backup Schedule
To schedule running a database backup you need to execute the following steps:
Select the Daily, Weekly or Monthly option.
Select the backup process start time from the dropdown.
Click on the Set button to complete the process.
You can enable or disable the automatic backup schedule option by using the given checkbox.
12.3 Restore Backup
This section explains how to use an existing backup to restore the application's database.
Use the Browse button to select a backup file. Click the Restore button to restore the application's database using backup.
13. GUI Rebranding
You can customize the application's GUI by using your company’s logo and banner image. To rebrand the GUI of the application you need to execute the following steps:
Click on the Browse button in the Select Banner Image field and browse a Banner Image file as per your choice. Click on the Set button to upload the image.
Click on the Browse button in the Select Login Image field to browse a Login Image file as per your choice. Click on the Set button to upload the image.
14. Captcha Settings
You can enable captcha on the login pages and other self-service activity pages to ensure more authenticity and an added layer of security.
Select the first checkbox to enable captcha on the Admin Login page.
For enabling captcha on rest of the options, first select the respective domain.
Select the second checkbox to enable captcha on the User Login page.
Select the third checkbox to enable captcha on the Unlock Account operation page.
Select the fourth checkbox to enable captcha on the Reset Password operation page.
15. Uninstalling the Solution
To remove Lepide Active Directory Self Service, follow the instructions below:
Click Start, go to Control Panel/Settings. The Control Panel window appears.
Double click the Add or Remove Programs icon or the Program and Features option (Windows 8 and above). A list of the programs installed on your computer appears.
Select Lepide Active Directory Self Service and click the Uninstall button. A backup instruction message appears onscreen before un-installing the software.
Click the Yes button to take a backup at your preferred location and click Ok.
Click Yes to start the un-installation process.
The uninstallation process is in progress.
The solution confirms whether you wish to keep the current settings or delete them. Click Yes/No as required.
Lepide Active Directory Self Service will be successfully uninstalled from your computer system.
To remove the remaining elements, delete its program installation folder manually and then empty the Recycle Bin as well.
After following the steps above, Lepide Active Directory Self Service will be uninstalled successfully from your computer system.
16. License Activation
The free version of Lepide Active Directory Self Service offers a license for 50 Users only. When enrolling more than 50 Users, you will need to purchase additional licenses.
To purchase licenses, contact our sales team at sales@lepide.com.
If you are using the free version of the product, follow these steps to purchase a license and activate it following these steps:
Open the web interface of software and login with administrator credentials
The Dashboard is the default screen that opens up.
Go to the Support tab and click on License in the left pane.
Click on the Request License link on the right-top corner. License request file is saved by default on this location: C:\Documents and Settings\User\My Documents\Downloads by the name of adss(alphanumeric code).request.
Send this file to the Lepide Software sales team at sales@lepide.com.
Lepide will send you a license activation file as per the license purchased.
Save that file to the local disk.
Open software web-interface and Go to the Support, License page. And click on Browse button against the Select License File field.
Locate and add the license activation file to the path provided.
Click on the Apply button to activate the license. The following message appears.
Click on OK and the license details will be displayed on the screen: