Setup and Sync from Active Directory/LDAP server
System requirements
Zoho Directory Sync Tool READ and REPLICATING DIRECTORY CHANGES permissions for the domains that need to be synced
- .NET Framework - 4.6 or later
- Browser - Internet Explorer 9 or later
- Operating System - Windows 7 or later
- Password Sync Agent Administrative privilege in Active Directory for the domains that need to be synced.
- .NET Framework 2.0 or 3.5 installed in all domain controllers, along with the HTTP Activation and Non-HTTP Activation features.
Message queuing service enabled and running before installing the Password Sync Agent. The domain controllers must have had a full installation, rather than a server core installation.
- Sign in to Zoho Directory 
, then click Admin Panel in the left menu.
- Go to Active Directory, then click Download.
- Install the downloaded file in the Domain Controller (DC), or a system connected to the DC.
- Open the tool, go to Zoho Sign-in, then sign in with your Zoho Directory admin credentials.
- Go to LDAP Configuration, then sign in with your LDAP domain's administrator credentials. Sign in to all the required domains.
- Choose the required OUs and objects to sync with Zoho.
Note: You can check the users and groups that are eligible for sync by clicking View Count in Select OUs.
- To further filter the objects to sync, go to Exclusion Rules, then click Add Rule. Select the type of objects to filter out, select the field name and exclusion criteria, then enter the values. Click Add.
- Go to Attributes, then map the LDAP fields with the Admin Panel's fields. The list of attributes available to choose from are:
- Email ID
- Secondary Email
- SAM Account Name
- First Name
- Last Name
- Display Name
- Employee ID
- Job Title
- Department
- Work Location
- Date of Joining
- Reporting To
- Mobile
- Phone
- Website
- Fax
- Post Office Box
- Street Address
- City
- State
- Country
- Postal Code
- If you have users without a domain-based custom email address, consider using the Replace Domain option under the Email Address attribute. Learn more about replacing the domain.
- Go to Sync Settings, then set the following:
- Default Password: This one-time password will be used for all newly-created Zoho user accounts. Users will be prompted to set a new password during their first sign-in.
- User Settings: This setting dictates how the Sync Tool will handle user accounts deleted in the AD server.
- Create LDAP Group: This setting creates a Zoho Directory collaboration group named after your Portal Name, for all users synced from AD through this tool.
- Create Groups for OUs: This setting creates a Zoho Directory collaboration group named after the OU, for each OU that is being synced.
- Go to Directory Sync and review the list of all users and groups that are yet to be created, updated, or disabled. Click Sync.
Note: You can see the status of all users and groups after the sync.