Overview
Microsoft Entra ID does not offer an LDAP interface of its own. To use your Entra identities with External Users on the LocknCharge Cloud (lockncharge.io), you publish them through Microsoft Entra Domain Services (Entra DS), with Secure LDAP (LDAPS) turned on and reachable over the internet, then point External Users at it.
This guide covers the Entra DS side end to end and gives the exact External Users values to use. It is a companion to Configure External Users, which explains every field in more detail. Microsoft's own walkthrough, with screenshots, is Tutorial: Configure LDAPS for Microsoft Entra Domain Services.
The examples below use a managed domain called aaddscontoso.com. Replace it with your own everywhere it appears.
Before you begin
- An Entra DS managed domain that is already deployed and healthy.
-
A custom DNS domain name on that managed domain, such as
aaddscontoso.com. The LocknCharge Cloud connects by hostname, and you will need to publish a DNS record for it. You cannot add records to a*.onmicrosoft.comname, and a managed domain's name cannot be changed after it is created. - The right access: the Application Administrator and Groups Administrator roles in Entra, rights to edit the managed domain's network security group in Azure, and access to your public DNS zone.
- A service account to bind with, such as FUYL LDAP. It only needs to read the directory. Entra DS can only check a password it holds a hash for: a cloud-only account must change its password after Entra DS was enabled, and hybrid accounts need password hash sync from your on-premises AD.
- Somewhere to hold each user's PIN and/or RFID. Entra DS is read-only for synced users, so these values must be set in Entra ID (or in on-premises AD for hybrid users) and synced down. See Attribute Mappings.
Get a certificate for Secure LDAP
Entra DS needs a certificate, with its private key, to encrypt LDAPS traffic. A certificate from a public certificate authority (CA) is simplest, because the LocknCharge Cloud already trusts it. A self-signed certificate also works, but you must give the LocknCharge Cloud a copy to trust (see CA Certificate below), and update that copy each time you renew.
Whichever you use, the certificate must meet these requirements or enabling Secure LDAP will fail:
-
Subject name is a wildcard for your managed domain, such as
*.aaddscontoso.com. A wildcard is required because Entra DS domain controllers have random names that change over time. - Key usage includes Digital Signature and Key Encipherment.
- Purpose is TLS server authentication.
- Signature is SHA-256 or stronger. The LocknCharge Cloud rejects weaker signatures.
- Lifetime is at least 3 to 6 months from now. LDAPS stops working when it expires.
To create a self-signed certificate, run the following in PowerShell as Administrator on a Windows computer:
$dnsName = "aaddscontoso.com"
$lifetime = Get-Date
New-SelfSignedCertificate -Subject *.$dnsName `
-NotAfter $lifetime.AddDays(365) -KeyUsage DigitalSignature, KeyEncipherment `
-Type SSLServerAuthentication -DnsName *.$dnsName, $dnsName
The certificate is created in the computer's Local Computer > Personal > Certificates store.
Export the certificate
Export the certificate from the Certificates (Local Computer) console (run mmc, then add the Certificates snap-in for the Computer account). If you used a public CA, export the certificate you were issued in the same way.
For Entra DS (.PFX, with the private key)
- Start the export Under Personal > Certificates, right-click the certificate and select All Tasks > Export...
- Include the private key Choose Yes, export the private key. Without it, Entra DS will refuse the certificate.
- Choose PKCS #12 Select Personal Information Exchange - PKCS #12 (.PFX) and tick Include all certificates in the certification path if possible.
- Set a password Choose Password, set the encryption to TripleDES-SHA1, and note the password. Entra DS only accepts .PFX files encrypted this way.
-
Save the file Save it somewhere safe, such as
aaddscontoso-ldaps.pfx. Anyone with this file and password can decrypt your LDAPS traffic.
If you export with PowerShell instead, pass -CryptoAlgorithmOption TripleDES_SHA1 to Export-PfxCertificate.
For the LocknCharge Cloud (.CER, self-signed only)
Skip this if your certificate came from a public CA.
- Export again Right-click the same certificate and select All Tasks > Export...
- Leave out the private key Choose No, do not export the private key.
- Choose Base-64 Select Base-64 encoded X.509 (.CER), then save the file. This is the PEM-format certificate you will paste into External Users.
Enable Secure LDAP on the managed domain
- Open your managed domain In the Microsoft Entra admin center, search for Microsoft Entra Domain Services and select your managed domain.
- Open Secure LDAP Select Secure LDAP from the left-hand menu.
- Turn on Secure LDAP Toggle Secure LDAP to Enable.
- Allow access over the internet Toggle Allow secure LDAP access over the internet to Enable. The LocknCharge Cloud connects from the internet, so this is required. The next section restricts it to our addresses.
- Upload the certificate Select the .PFX file from the previous section and enter its password in Password to decrypt .PFX file.
- Save Select Save. Enabling takes a few minutes, and the managed domain cannot be changed until it finishes.
If enabling fails, the most common causes are a subject name that does not match the managed domain, a .PFX not encrypted with TripleDES-SHA1, or a certificate that has expired or expires soon.
Recommended: under Security settings for the managed domain, enable TLS 1.2 only mode. The LocknCharge Cloud requires TLS 1.2 or higher, and this stops older clients from negotiating anything weaker. Make sure NTLM password synchronization is left enabled there, or the service account cannot bind.
Restrict LDAPS to the LocknCharge Cloud
Once Secure LDAP is available over the internet, your managed domain accepts connections on TCP port 636 from anywhere, which exposes it to password-guessing attacks. Add a network security group (NSG) rule so that only the LocknCharge Cloud can reach it.
- Open the network security group In the Azure portal, open the managed domain's resource group and select its network security group (for example aadds-nsg).
- Add an inbound rule Select Settings > Inbound security rules, then Add, and use the values in the table below.
- Save the rule Select Add. The default DenyAllInBound rule continues to block everyone else.
| Setting | Value |
|---|---|
| Source | IP Addresses |
| Source IP addresses / CIDR ranges | 35.84.160.102, 44.240.25.20 |
| Source port ranges | * |
| Destination | Any |
| Destination port ranges | 636 |
| Protocol | TCP |
| Action | Allow |
| Priority | 401 |
| Name | AllowLDAPS-LocknChargeCloud |
These are the same addresses listed under Firewall & Security in Configure External Users. If you want to test from your own network first, add your public IP address to the rule as well, and remove it afterwards.
Publish a DNS record
- Find the external IP address In the Microsoft Entra admin center, open your managed domain's Properties and copy the Secure LDAP external IP address.
-
Create an A record With your public DNS provider, create a host record such as
ldaps.aaddscontoso.compointing to that address. The hostname must sit directly under your managed domain name so it matches the wildcard certificate.
Configure External Users
In the LocknCharge Cloud, select Integrations in the left menu, then External Users, and enter:
| Field | Value for Entra DS |
|---|---|
| Provider Type | Active Directory |
| Identifier | Any unique name using letters, numbers, dashes or dots, such as entra-ds. |
| Connection Urls |
ldaps://ldaps.aaddscontoso.com (the record you created above, not the IP address). |
| Client Key | Leave blank. |
| Client Certificate | Leave blank. |
| CA Certificate | Public CA certificate: leave blank. Self-signed certificate: open the .CER file in a text editor and paste its entire contents, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines. |
| Base DN |
OU=AADDC Users,DC=aaddscontoso,DC=com. Entra DS puts every user and group synced from Entra ID in the AADDC Users OU. |
| Bind DN | The service account's full distinguished name, for example CN=FUYL LDAP,OU=AADDC Users,DC=aaddscontoso,DC=com. The CN is the account's display name in Entra ID. |
| Bind Password | The service account's password. |
| LDAP Filter | Optional, but recommended. To limit External Users to members of an Entra group called FUYL Users (including nested groups):(memberOf:1.2.840.113556.1.4.1941:=CN=FUYL Users,OU=AADDC Users,DC=aaddscontoso,DC=com)
|
Attribute Mappings
Expand Attribute Mappings and set:
| Field | Value for Entra DS |
|---|---|
| User's Name |
cn (the default) or displayName. Both carry the user's Entra display name. |
| PIN | The attribute you store PINs in, such as employeeID or one of extensionAttribute1 to extensionAttribute15. |
| RFID | The attribute you store RFID values in, using the same format set in your Account Settings (Hex by default). |
Set these values in Entra ID (or on-premises AD for hybrid users), not in Entra DS. Changes can take up to an hour to sync from Entra ID into the managed domain.
Select Test Connection. When all tests pass, save the configuration and set up a workflow that uses your external users.
Renewing the certificate
LDAPS stops working when the certificate expires. Before it does, create a replacement that meets the same requirements, then open Secure LDAP on the managed domain and select Change Certificate.
If you use a self-signed certificate, paste the new .CER into the External Users CA Certificate field at the same time. Until you do, the LocknCharge Cloud will not trust the new certificate and users will not be able to access their bays.
Troubleshooting
| Symptom | Check |
|---|---|
| Test Connection cannot connect or times out | The DNS record resolves to the Secure LDAP external IP address; Allow secure LDAP access over the internet is enabled; the NSG rule includes both LocknCharge Cloud addresses on TCP 636. |
| Certificate or TLS error | The Connection Url hostname sits directly under the managed domain name (matching *.aaddscontoso.com); for a self-signed certificate, the current .CER is in the CA Certificate field; the certificate is signed with SHA-256 or stronger and has not expired. |
| Bind fails with invalid credentials | The Bind DN is the full DN in OU=AADDC Users, spelled exactly; the service account has changed its password since Entra DS was enabled (cloud-only) or password hash sync is running (hybrid); NTLM password synchronization has not been disabled. |
| Connection succeeds but no users are found | The Base DN matches your managed domain name; the group named in the LDAP Filter exists in OU=AADDC Users and the users are members; the PIN and RFID attributes are populated in Entra ID and have had time to sync. |
If you are still stuck, contact support with the result of Test Connection and we will help you work through it.