[IMPORTANT] Please note that this site will be disabled on October 31. In it's place, the new JumpCloud Help Center is live! Check it out here!

Support Center

Configuring Okta to use JumpCloud's LDAP-as-a-Service

Configuration settings tested on latest version as of 06/26/2018

Prerequisites:

See Using JumpCloud's LDAP-as-a-Service to obtain the JumpCloud specific settings required below.

When using Okta's Connector for LDAP, here are the basic settings to configure authentication with JumpCloud's hosted LDAP service:
 

Important Note:

If the error Could not find a value for the BaseSubstitutionProperty on the User result is received, perform the following steps to resolve:
  1. During initial configuration, remove the memberOf value for the Groups > User Attribute configuration and leave the field blank.
  2. After the configuration is successfully saved, this value may then be re-input as per the configuration listed below.
  3. If the verification test continues to fail after replacing the memberOf attribute within the configuration, then confirm that your LDAP Users have been associated with an LDAP-enabled group as the query performed by Okta requires the attribute to be present in the user object during the verification.
 

LDAP Agent Configuration

LDAP Server: ldap.jumpcloud.com:389

Root DN: ou=Users,o=YOUR_ORG_ID,dc=jumpcloud,dc=com

Bind DN: uid=LDAP_BINDING_USER,ou=Users,o=YOUR_ORG_ID,dc=jumpcloud,dc=com

Bind Password: LDAP_BINDING_USER_PASSWORD
(Optional) Use SSL connection: Enable for SSL (Note: LDAP Server will instead point to port 636 - ldap.jumpcloud.com:636)

LDAP Configuration Settings

Version


LDAP Version: OpenLDAP
 

Configuration

 

Objects

Unique Identifier Attribute: entrydn
DN Attribute: entrydn


Users

User Search Base: ou=Users,o=YOUR_ORG_ID,dc=jumpcloud,dc=com
User Object Class: inetorgperson
User Object Filter: (objectclass=inetorgperson)
Account Disabled Attribute: pwdlock
Account Disabled Value: true
Password Attribute: userpassword
 

Group

User Search Base: ou=Users,o=YOUR_ORG_ID,dc=jumpcloud,dc=com
Group Object Class: groupofnames
Group Object Filter: (objectclass=groupofnames)
Member Attribute: member
User Attribute: memberof
 

Role

Object Class: groupofnames
Membership Attribute: memberof
 

Last Updated: Nov 01, 2018 08:40AM MDT

Related Articles
desk-forwarding@jumpcloud.com
http://assets0.desk.com/
false
desk
Loading
seconds ago
a minute ago
minutes ago
an hour ago
hours ago
a day ago
days ago
about
false
Invalid characters found
/customer/en/portal/articles/autocomplete