← Workspace administrators learning pathGODESK PLATFORM / WORKSPACE ADMINISTRATORS

Directory sign-in with Active Directory or LDAP

Let staff sign in with their organisation account, give roles from directory groups, and remove access automatically when someone is disabled in the directory.

What directory sign-in does

Staff sign in to GoDesk with the username and password they use at work. GoDesk checks them with your directory and never stores the directory password.

Groups in the directory can decide each person's GoDesk role and team. Every half hour GoDesk checks the directory: anyone disabled or removed there is switched off in GoDesk and signed out.

Before you start

You need a directory GoDesk can reach. For Active Directory or another LDAP server in your office, open LDAPS (port 636) from the GoDesk servers, or connect through a VPN. On a self-hosted GoDesk it connects directly. Ask GoDesk support for the addresses to allow.

Ask your directory team for a service account that can read users and groups, the base DN where staff accounts live, and the attribute people sign in with, usually sAMAccountName.

If your organisation only uses Microsoft Entra ID in the cloud, directory sign-in is not the right option. Talk to GoDesk about single sign-on.

Connect your directory

Open Settings, then Directory sign-in. Enter the Host, and a Fallback host if you have a second domain controller.

Under Security choose LDAPS (port 636), the recommended option, or StartTLS. Keep the certificate check on, and add your CA certificate if your directory uses its own.

Enter the Base DN, the Login attribute, and the Bind DN and Password of the service account. The password is stored encrypted and never shown again.

Use Who may sign in to limit sign-in to a group, for example people in a GoDesk group.

Groups and roles

Under Groups and roles, add a Directory group DN with the GoDesk role, and optionally a team, it should give. The first matching group wins.

Choose a Role when no group matches, or refuse sign-in for people outside the listed groups.

Tick Create GoDesk accounts on first sign-in if new staff should get an account automatically. Accounts are only created while you have free seats.

Test, then switch on

Select Test connection and enter a username to look up. GoDesk shows what it found: the name, email, groups and the role it would give. Fix any error it reports before switching on.

Once it is on, the sign-in page asks for an email or username. Existing staff sign in with their directory account and their GoDesk account is linked to it.

Keeping a way in

Super admins, and your last active local administrator, always keep their own GoDesk password, so you are never locked out if the directory is down.

People who sign in through the directory change or reset their password through your organisation's process, not in GoDesk.

If something does not work

If Test connection cannot reach the server, check the host, port and firewall or VPN. A certificate error usually means the CA certificate is missing. If people see that the sign-in service could not be reached, your local administrators can still sign in. If you are still stuck, email GoDesk support at help@godesk.co.ke with your workspace name and what you see on screen.

← Back to Workspace administrators learning path