Find Your Active Directory Search Base (2024)

When you configure your Firebox to authenticate users with your Active Directory server, you add a comma-delimited search base. The search base is the place the search starts in the Active Directory hierarchical structure for user account entries. This can help to make the authentication procedure faster.

Before you begin, you must have an operational Active Directory server that contains account information for all users for whom you want to configure authentication on the Firebox.

From your Active Directory server:

  1. Select Start > Administrative Tools > Active Directory Users and Computers.
  2. In the Active Directory Users and Computers tree, find and select your domain name.
  3. Expand the tree to find the path through your Active Directory hierarchy.

Domain name components have the format dc=domain name component, are appended to the end of the search base string, and are also comma-delimited.

For each level in your domain name, you must include a separate domain name component in your Active Directory search base. For example, if your domain name is prefix.example.com, the domain name component in your search base is:

dc=prefix,dc=example,dc=com

To make sure that the Active Directory search can find any user object in your domain, specify the root of the domain. For example, if your domain name is kunstlerandsons.com, and you want the Active Directory search to find any user object in the entire domain, the search base string to add is:

dc=kunstlerandsons,dc=com

To limit the search to begin in a container beneath the root of the domain, you must specify the fully-qualified name of the container in comma-delimited form. Start with the name of the base container and progress to the root of the domain. For example, assume your domain in the tree looks like this after you expand it:

Find Your Active Directory Search Base (1)

Also assume that you want the Active Directory search to begin in the Sales container that appears in the example. This enables the search to find any user object inside the Sales container, and inside any containers in the Sales container.

The search base string to add in the Firebox configuration is:

ou=sales,ou=accounts,dc=kunstlerandsons,dc=com

The search string is not case-sensitive. When you type your search string, you can use either uppercase or lowercase letters. Make sure that a comma separates each component in the search base, without spaces between the components.

This search does not find user objects inside the Development or Admins containers, or inside the Builtin, Computers, Domain Controllers, ForeignSecurityPrincipals, or Users containers.

DNof Searching User and Password of Searching User Fields

You must complete these fields only if you select an option for the Login Attribute that is differentfrom the default value, sAMAccountName. Most organizations that use Active Directory do notchange this.When you leave this field at the default sAMAccountName value, users supply their usual ActiveDirectory login names for their user names when they authenticate. This is the name you see in the User logon name text box on the Account tab when you edit the user account in Active DirectoryUsers and Computers.

If you use a different value for the Login Attribute, a user who tries to authenticate gives a different form of the user name. In this case, you must add Searching User credentials to your Firebox configuration.

Related Topics

Configure Active Directory Authentication

Change the Default Port for the Active Directory Server

© 2024 WatchGuard Technologies, Inc. All rights reserved. WatchGuard and the WatchGuard logo are registered trademarks or trademarks of WatchGuard Technologies in the United States and other countries. Various other trademarks are held by their respective owners.

Find Your Active Directory Search Base (2024)
Top Articles
Latest Posts
Article information

Author: Dean Jakubowski Ret

Last Updated:

Views: 6204

Rating: 5 / 5 (50 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Dean Jakubowski Ret

Birthday: 1996-05-10

Address: Apt. 425 4346 Santiago Islands, Shariside, AK 38830-1874

Phone: +96313309894162

Job: Legacy Sales Designer

Hobby: Baseball, Wood carving, Candle making, Jigsaw puzzles, Lacemaking, Parkour, Drawing

Introduction: My name is Dean Jakubowski Ret, I am a enthusiastic, friendly, homely, handsome, zealous, brainy, elegant person who loves writing and wants to share my knowledge and understanding with you.