This feature allows our service to sync with the users stored in an Active Directory instance. As users are added and removed from AD, they will be invited and deleted from your Allthenticate tenant. Additionally, certificates can be provisioned for each user with a AD Certificate Services instance in a domain. These certificates can be used to log in to domain joined Windows computers.
Before You Start
<aside>
ℹ️
This guide is intended to be completed with an Allthenticate engineer during an implementation session; it is not a self-service guide. Before the call, confirm that the prerequisites below are available and that the administrators who hold these permissions can join.
</aside>
What the customer should have ready
- Administrative access to the Windows domain controller: Domain Admins, or delegated rights to read the target OU and to create the service accounts listed under Identities and Accounts
- Access to the AD CS Enterprise CA, including the Certification Authority and Certificate Templates consoles (CA administrator; Enterprise Admins is required to install the Certificate Enrollment Web Service role if it is not installed yet)
- Access to the IIS server that hosts, or will host, the Certificate Enrollment Web Service (CES)
- An Allthenticate admin portal account with super-admin rights for your organisation
- A host for the Domain Controller Bridge: a Linux host with Docker (recommended) or a domain-joined Windows machine, with the network access listed under Requirements and Network Access
- A test OU containing at least one test user whose E-mail attribute is filled in, a domain-joined Windows test computer you have local administrator rights on, and a phone with the Allthenticator app
- The service accounts described under Identities and Accounts, or the ability to create them during the call
Who does what
Steps throughout this guide are tagged:
- Customer: performed by your administrators, usually before the call
- Allthenticate: performed by the Allthenticate engineer
- Together: performed on the call with both present
How it works

Then, at login:
