Configure Domain Controllers

PMM allows your users to be distributed across multiple domains. In order for the system to authenticate users, Secure Email Gateway must be joined to a domain controller associated with your users' mail domains.

A domain controller is responsible for authenticating your users and providing the Gateway with user information. If a user is accessing the PMM Portal from an unrecognized domain, their login will be unsuccessful unless the domain controller has been correctly configured.

You can configure a number of domain controllers for authenticating PMM users on behalf of the Gateway.

 

Secure Email Gateway can only be a member of one domain at any one time. Joining a new domain will remove the Gateway from its previous association with a domain controller.

The Gateway is only required to join a domain if Client Integrated Authentication has been selected.

Add a domain controller

  1. Navigate to System > PMM Settings > Authentication Settings. The Authentication Settings page is displayed.

  2. In the Domain Controllers panel, click New. The Modify Domain Controller page is displayed.

Overview

NTLM Domain Controller

You must provide the name of the domain and, optionally, the domain controller that the Gateway will join. A valid administrator and password for the domain must be supplied.

User Name & Password

A user name and password can be supplied for domain controller connections. The credentials are used for LDAP lookups of user information.

Mail Domains

You can specify which mail domains are associated with the domain controller. The Gateway determines which domain the domain controller is to use when PMM users login with their email address.

  1. Apply the configuration.

Join a domain

  1. Navigate to System > PMM Settings > Authentication Settings. The Authentication Settings page is displayed.

  2. In the Domain Controllers panel, select the required domain controller and click Edit. The Modify Domain Controller page is displayed.

  3. In the task panel, click Join Domain. The Join domain dialog is displayed.

  4. Enter an administrator User Name (e.g. administrator) and a Password for the domain.

  5. Click Join.

  6. Apply the configuration. You must apply changes to each of the Gateways configured as a group.
 

If the portal is configured on a remote peer, the Gateway must be a member of the domain on that peer.

In the Domain Controllers panel, when the mouse hovers over an item under the Joined column, a tooltip is displayed indicating which peer is a member of the domain. This panel also indicates which domain the Gateway has joined.

Test user authentication

After you have applied your domain configuration, you can check that PMM users can be correctly authenticated.

  1. Navigate to System > PMM Settings > Authentication Settings. The Authentication Settings page is displayed.

  2. In the Domain Controllers panel, select the required domain controller and click Edit. The Modify Domain Controller page is displayed.

  3. In the task panel, click Test Authentication. The Test Authentication dialog is displayed.

  4. Enter User Name and Password.

      Note that this username can be Windows logon, user principal name or email address.
  5. Click Run Test.

Edit a domain controller

  1. Navigate to System > PMM Settings > Authentication Settings. The Authentication Settings page is displayed.

  2. In the Domain Controllers panel, select the domain controller you wish to modify and click Edit. The Modify Domain Controller page is displayed.

  3. Modify the Overview, NTLM Domain Controller, User Name & Password and Mail Domains panels as required. Click Save on each panel to save your changes.

  4. Apply the configuration.

Delete a domain controller

You can delete a domain controller that is no longer required from the Gateway .

  1. Navigate to System > PMM Settings > Authentication Settings. The Authentication Settings page is displayed.
  2. In the Domain Controllers panel, select the domain controller you wish to delete and click Delete.
  3. Click Delete in the Confirm Delete dialog to confirm the removal.

  4. Apply the configuration.

If no domain controllers are configured, you will not be able to apply the configuration. You must disable PMM.

 

If you change any configuration or policy settings, you must Apply Configuration for the new settings to take effect. You can do this either from the Changes Made panel, or System > ConfigurationApply Configuration. See Apply new configuration for more information.

If you use Peer Gateways (i.e. when multiple Gateways are peered), any configuration changes from a local Gateway can then be applied to all the peers at the same time. See Configure Peer Gateways for more information.

See also...