- Organization admin
- Organization owner
Zoho
Directory Identity Connect (ZDIC) is an on-premises agent that connects your
organization’s on-premises LDAP-based directories to Zoho Directory. It automates synchronization of users, groups, and directory attributes from your
on-premises directories to Zoho Directory, reducing the need for manual
user management.
The ZDIC runs within
your network and communicates securely with Zoho Directory. It keeps directory data up to date based on the sync rules you define, such as
organizational units, attributes, and filters.
The ZDIC runs continuously on your Windows machine to
maintain synchronization as long as network connectivity is available. A
configuration interface (tray app) is also installed for administartors to
manage configurations.
When the ZDIC is enabled, your on-premises LDAP-based directory remains the primary
source of truth for user discovery and lifecycle, and Zoho Directory
reflects changes based on directory state and sync rules.
This
guide walks you through installing ZDIC and configuring directory sync.
Download and install the Identity Connect Agent on a machine that meets the following requirements
- LDAP user credentials with read access to your directory
- The
agent must be installed on a machine within the same network as your
LDAP server.
Download the Agent
- Sign in to Zoho Directory. Click ADMIN PANEL from the left menu.
- Go to the DIRECTORY STORES tab. Click Add Directory.
- Find LDAP Services and click Add.
- On the Download Agent screen:
- Review the prerequisites.
- Select your LDAP service from the dropdown.
- Once you select your LDAP service, the system displays an installation key. Copu the Installation Key.
- Click Download and wait for the download to complete.
Install the Agent
- Execute the downloaded file ZohoDirectory_IdentityConnect.msi to start installation.
- Paste
the Installation Key. Upon successful validation, you'll be taken
automatically to the setup wizard where you can complete the rest of the
installation steps.
- On the Welcome screen, choose your language.
- Read the software license agreement carefully, then accept the terms. Click Continue. Clicking the URL will not auto-redirect you to the page in some legacy systems. In this case, click 🔗 to copy the URL, then paste it in your browser to read the license agreement.

- Open the provided Login URL from a browser.

- Sign in to your Zoho Directory admin account if you haven't already.
- Enter the Verification Code shown in the installer.
- Upon successfully signing in, a confirmation screen with your Zoho account email and display name will appear. Click Continue.

Once the agent is installed, complete the sync setup in Zoho Directory.
Possible error cases that appear at this step:
Error | Fix |
The verification code is time-bound and will become invalid after the expiration time (5 minutes). | Click Retry to generate a new code, which you can use to sign in and proceed to configuring your LDAP settings. |
Sometimes, the agent may not be able to contact the Zoho server due to network issue. | Click Retry. If the error persists, contact support. |
- This is a crucial step where the agent is allowed to connect with the on-premises directory store to fetch data of users and groups for sync.
- Enter your directory info: Domain Name, LDAP servers, Connection Port, Base distinguishes name, User's distinguishes name, Password. Make sure they're all valid.


- Enable SSL for a secure connection:
- SSL is recommended, as it safeguards sensitive directory data during transmission.
- To use SSL:
- Your LDAP server must have a valid SSL certificate issued to its domain.
- Use the fully qualified domain name (FQDN) in your LDAP server name field (e.g., ldap-server-1.zylker.com).
Using only the hostname will cause SSL failure.
Click Next to review the LDAP configurations.
If you face the error 'LDAP server goes unreachable,' click Retry to attempt the connection again. Make sure that there's no connectivity issue between the agent machine and LDAP server.
Complete Installation
- Click Install to finish setting up the agent. Upon successful installation, the agent will be running.
Note: Ensure
the agent machine maintains continuous network connectivity according
to your organization's power-saving or login-based policies. - Click
to perform the following actions:
- Change ownership - Switch the Zoho Directory admin account linked to the agent in case
the original admin leaves your organization or loses LDAP access.

- Change LDAP settings - Modify your LDAP server details here. After making changes, click Update to save them.
- Go back to the Zoho Directory Admin Panel to complete the remaining setup.
Select Organizational Units (OUs)
- From the Admin Panel, navigate to your required directory using the dropdown provided in the download agent screen.
- Choose which OUs you want to sync to Zoho Directory.
- Select object types to include:
- Users
- Groups
- Custom LDAP Query - Enter a valid LDAP query and click Save to sync based on specific LDAP attributes.
- Review the chosen OUs:
- Edit or remove any existing OU preferences.
- To add more OUs, click Add OUs.
- When you're done, click Add and Continue.
Map Zoho Directory fields with your LDAP fields
- This is important for making sure user data is correctly transferred.
- Toggle between User Mapping and Group Mapping.
- Fields will be auto-suggested, but you can map them manually.
- Use the tabs to filter by All Fields, Mapped, or Unmapped fields. For example, you can map the Zoho Directory "Last name" field to your LDAP "Surname" attribute.
- For custom attributes:
- Click Edit next to one of the default attributes displayed.
- Select Custom LDAP attribute.
- Enter a name for the attribute and save it.
Define Sync Criteria
- On
the SET SYNC CRITERIA screen, specify which users or groups should be
included in the sync. To configure criteria for groups, switch to the Groups tab.
- Select import type: Based on criteria or All users
- If using criteria, define the Field, Relationship, and Value. Click Save and Next.
Enable the toggle to securely synchronize user passwords from on-premises LDAP-based directories to Zoho Directory.
Zoho Directory supports only the following hashing algorithms for security: SHA-512, BCrypt, and SHA-256. Ensure the user passwords are hashed using one of these.
Password updates will be reflected only during scheduled sync or manual import
If a directory-synced user is deleted from Zoho Directory, password changes for that user in on-prem directories will not sync unless the user is re-provisioned in Zoho Directory.
User Sync Settings
Configure automated rules for user account handling based on changes in on-premises LDAP-based directories.
Setting | What it is for | Options |
Mail Notifications | Choose whether you want to send notifications to synced users. | Notify via mail - Sends emails to newly synced users and resend invite links to pending users. Don't notify - No email notifications are sent to users. |
Password Notifications | Decide how new users get their initial passwords | Send email OTP to user - The new user will receive an email directly to their registered email address containing an OTP.
Send email OTP to admin - Admin will receive the OTP or setup info, which they should then forward to the user manually.
Don't
notify anyone - No automatic notifications are sent. An admin should manually
notify the user and provide them with their login credentials through some other medium on their own.  The Password Notifications section is displayed only when the Notify via mail option is selected in Mail Notifications section. |
| Choose how to reflect a user's on-premises account status changes in Zoho Directory. | Change in Zoho Directory - If disabled in on-premises, directory account also gets disabled (and re-enabled if restored).
Do nothing - Ignore on-premises status changes.  If Do nothing is selected, the system will no longer manage user status.
The When User Leaves Selected OU setting will be disabled and
unavailable, as it requires Status Sync to be enabled. Learn more about
this interactive behaviour illustrated after the table. |
When User Leaves Selected OU | Define what should happen in Zoho Directory when a user is moved out of a selected/synced on-premises directory OU. | Disable in Zoho Directory - The user's Zoho account is auto-disabled.
Do nothing - The user's Zoho account remains active, but will no longer be included in the future sync operations. |
Important note: There's a crucial interaction between Setting 3 and Setting 4. The When User Leaves Selected OU setting depends on Status Sync. The former is only available if the latter is set to Change in Zoho Directory. If you choose to Do nothing with status changes, the system cannot manage user status based on OU
membership. Therefore, Setting 4 will be disabled altogether.
Status Sync | When User Move Out of Selected OU | Action performed on Dexter (in on-premises LDAP directory) | Result (in ZD) |
Reflect in ZD | Disable in ZD | Dexter is removed from OU but still active in on-premises LDAP directory | Dexter's Zoho account is disabled (OU rule applies) |
| (field gets disabled with Do nothing selected) | Dexter is removed from OU | Dexter's
Zoho account remains active but is no longer synced (because Status
Sync setting is ignoring status changes, and OU-based handling is off) |
Reflecting hard deletion of users from on-premises LDAP-based directory to Zoho Directory:
When
Zoho Directory Identity Connect is enabled, your on-premises LDAP-based directory acts as
the primary source for user discovery. If a user is deleted or disabled in on-premises LDAP-based directories, the corresponding action in Zoho Directory depends on
the configured Status Sync setting.
When
Status
Sync is set to
Change in Zoho Directory, users disabled or deleted in on-premises LDAP directories are disabled in Zoho Directory.
If your organization requires users to
be
completely deleted from Zoho Directory instead of just disabled, contact
Zoho Directory Support to enable this configuration for your account. Enabling deletion
propagation will permanently remove users in Zoho Directory when they're
disabled/deleted in on-premises LDAP-based directories.
For step-by-step instructions on deleting users and handling ownership transfers, see
How to Delete a User
Note on admin deletion: Each
Identity Connect configuration is associated with a Zoho Directory
admin. To ensure uninterrupted sync, the system will not allow the
deletion or disablement of an owner-admin.
You must first use the Change Ownership option
in the tray app to transfer dependencies to another admin; only then
can the original account be removed. You must reassign ownership to
another admin. If you attempt deletion directly, the system will block
the action and place them in a "delete-pending" state until all
dependencies are cleared.
Deleting a directory-synced user from Zoho Directory: Deleting a user in Zoho Directory does not remove the user from the on-premises LDAP-based directories.
Warning on data loss:
If "Delete in ZD" is enabled, removing a user from on-premises LDAP directories will permanently erase their Zoho mail, files, and service data. This
data cannot be recovered even if the user is re-synced later from the LDAP directories.The following scenarios illustrate common outcomes based on typical configurations.
Actual results depend on sync criteria and status settings.
Scenario | Action in ZD | Action in on-premises LDAP directory | Manual Sync Result | Scheduled Sync Result |
Manual re-creation | User deleted | User exists & meets criteria | User appears in "Users to Create" | User is automatically re-created |
Complete removal | User deleted | User deleted | No action | No re-provisioning (user remains deleted) |
Mixed Zoho & on-prem LDAP directory actions (or) Conflicting actions | User deleted | User deleted User disabled/moved out of synced OU | Depends on Status Sync setting | Depends on Status Sync setting |
Schedule Sync
- Set frequency (Daily/Hourly/Weekly/Monthly) and time of sync. Click Save and Next.
Changes
in LDAP directories are reflected based on the
configured sync schedule and may not appear immediately in Zoho Directory.
Review and Finalize Sync
- Review and select users from the imported list to add to Zoho Directory. This screen helps you with the following filters:
- New Users - Users found in your directory but not yet in Zoho Directory.
- Users to Update - Existing ZD users whose info will be updated from your directory in the next sync.
- Marked for Activate/Disable - Users who will be activated or disabled based on their status in your
directory. Review this category carefully before syncing to avoid unintended changes to user access.
- Ignored - Users who do not meet the configured sync criteria
- Click Add and Continue.
- Review the summary and click Finish to complete the setup.
At this point, you're
done with the Identity Connect setup. The system will now automatically
sync your on-premises LDAP-based directories' users and groups to Zoho Directory based on the rules you
have defined.
You can also view the detailed status of the Identity Connect Agent:
LDAP server(s): The LDAP servers the agent is configured to sync with.
Agent version: The current version of the agent.
Device name: The name of the machine where the agent is installed.
Status: Connected / Disconnected.
Last sync: The timestamp of the last successful sync.
1. Click the

icon to perform the following actions:
- Change ownership - Change the Zoho Directory admin account linked to the agent when the current admin is no longer with your organization. If the current Zoho admin is the directory store owner, you must first transfer the store ownership to another admin before updating the linked admin account.
- Change LDAP settings - Modify your LDAP server details here. After making changes, click Update to save them.
Troubleshooting the "Disconnected" Status
If the agent status shows Disconnected,
- Verify that the machine has active internet connectivity.
- Ensure the system date and time on the machine are correct.