Before installing the Identity Connect Agent, confirm your environment meets the following requirements. If you also plan to install the Password Sync Agent, review the additional requirements in Configure Password Sync Agent as well. Some of them (like account privileges) are easier to set up correctly the first time than to fix later.
Machine requirements
- Supported platforms: 64-bit Windows Server 2008 or later / Windows 10 or later.
- WebView2 Runtime: This package is automatically installed during the agent's installation process if it isn't already present. (If this step fails, see Troubleshooting - WebView2 installation failed.)
- Network placement: The agent must be installed on a machine within the same network as your LDAP server, preferably a Domain Controller if you also plan to install the Password Sync Agent later.
Account requirements
- LDAP user credentials with read access to your directory are required for the base Identity Connect setup.
- If you plan to use Password Sync Agent, this account will need to be upgraded to Domain Admin-level privileges. See Configure Password Sync Agent.
Network and firewall requirements
Ensure the required outbound network access, firewall rules, domains, and ports are allowed before installing the Identity Connect Agent. The agent only initiates outbound connections and no inbound internet-facing firewall rules are required.
Binary download policy
For agent auto-update, ensure your network allows downloading our secure .zip file. The download will fail if your network policies block binary file formats (.zip, .exe, .rar, .7z) at the network level.
Endpoints to whitelist
To ensure uninterrupted updates, whitelist the following endpoints:
one.zoho.com/downloads/onpremises_sync/OnPremisesSyncUpdate.zip
one.zoho.com/downloads/onpremises_sync/ZDPasswordSyncAgentUpdate.zip
Example: For an organization on the EU data center,
one.zoho.eu/downloads/onpremises_sync/OnPremisesSyncUpdate.zip
one.zoho.eu/downloads/onpremises_sync/ZDPasswordSyncAgentUpdate.zip