Zimbra Collaboration 8 Active Directory authentication

zimbra8activedirectory01

When Active Directory is used to manage users' authentication within the network, Zimbra Collaboration should be configured to use this mode to keep the passwords in sync. The configuration can be done accessing the Admin Console via browser.

Zimbra Collaboration suite is an open source solution for email, address book, calendar and tasks that can be accessed from a variety of standards-based email clients and mobile devices.

 

Check Active Directory account

To properly configure the application, it's necessary to figure out AD users to create in the mail system accessing Active Directory User and Computer MMC snap-in.

zimbra8activedirectory02

Right click the user to test with Zimbra then select Properties option.

zimbra8activedirectory03

Note the User logon name.

zimbra8activedirectory04

 

Configure Zimbra authentication

To configure Zimbra authentication mode, access the Admin Console typing from the browser the address https://IP_Address:7071. Insert Username and Password then click Sign In button.

zimbra8activedirectory05

Select Configure item in the left side of the window.

zimbra8activedirectory06

Click Domains on the left side then right click the domain to configure and select Configure Authentication option.

zimbra8activedirectory07

Select External Active Directory option then click Next.

zimbra8activedirectory08

Type the AD domain name and insert the IP_address or FQDN of the Domain Controller specifying the LDAP Port. Click Next.

zimbra8activedirectory09

Leave default. Click Next.

zimbra8activedirectory10

Type the Username and Password of the Active Directory account to authenticate. Click Test button to verify the account.

zimbra8activedirectory11

If everything has been properly set, the account is authenticated successfully. Click Next.

zimbra8activedirectory12

Leave default then click Next.

zimbra8activedirectory13

The configuration is complete. Click Finish to save changes.

zimbra8activedirectory14

To synchronize Zimbra Collaboration with Active Directory, same account name must be created in the Zimbra system. From Admin Console, Select Manage item in the left side of the window.

zimbra8activedirectory15

Click Settings icon then select New to create a new account.

zimbra8activedirectory16

Type same Account name as set in the Active Directory and the used public domain.

zimbra8activedirectory17

As you can recognize, no password field is present in the New Account options. This because the password is taken directly from the Active Directory. Click Finish to create the account.

zimbra8activedirectory18

If you try changing the password of the created account, the Change Password option is grayed out.

zimbra8activedirectory19

Test authentication

Open the browser and access Zimbra webmail by typing the server IP_Address or the DNS public name (i.e. mail.nolabnoparty.com). When Zimbra authentication screen appears, type Username and Password of the account just created then click Sign In button.

zimbra8activedirectory20

If the authentication succeeds, Zimbra user’s webmail page opens. The used account has been authenticated directly from the Active Directory.

zimbra8activedirectory21

Zimbra is now properly configured to authenticate users against Active Directory. If a company needs to implement Zimbra Collaboration as messaging software, this task should be performed by IT professionals to achieve best results and ensure a proper support.

firma

2 Comments

  1. Eduardo 30/10/2014
  2. jdokurugu 18/06/2015