US English (US)
FR French
DE German
PL Polish
SE Swedish
FI Finnish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

English (US)
US English (US)
FR French
DE German
PL Polish
SE Swedish
FI Finnish
  • Log in
  • Home
  • Identity Governance and Administration (IGA)
  • IGA solution library
  • Instructions & guidelines
  • Customer instructions

Efecte Provisioning Engine - Customer instructions for Active Directory

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Service Management
    Matrix42 Professional Solution Matrix42 Core Solution Enterprise Service Management Matrix42 Intelligence
  • Identity Governance and Administration (IGA)
    IGA overview IGA solution library
  • Platform
    ESM ESS2 ESS Efecte Chat for Service Management Integrations Add-ons
  • Release Notes for M42 Professional, IGA, Conversational AI
    2026.1 2025.3 2025.2 2025.1 2024.2 2024.1 2023.4 2023.3 2023.2 2023.1 2022.4 2022.3 Release Information and Policies
  • Other Material
    Terms & Documentation Guidelines Accessibility Statements
  • Services
+ More
    • Service Management

    • Identity Governance and Administration (IGA)

    • Platform

    • Release Notes for M42 Professional, IGA, Conversational AI

    • Other Material

    • Services

Efecte Provisioning Engine - Customer instructions for Active Directory

Customer instructions for Active Directory


Efecte Provisioning Engine supports User Federation called as AD connector. AD connector is part of Efecte Connect, native connectors and it is used for reading (ITSM&IGA) and writing (IGA) data towards/from to customers Active Directory. It can be used for all Efecte solutions which are using Efecte Provisioning Engine. 


Customer actions

  1. VPN-tunnel between Efecte and Customers AD needs to be build
  2. Create Technical user account for Efecte authentication
  3. Create certificate for Efecte Solution 
  4. Grant Read permissions 
  5. Grant Write permissions if IGA project, these are described and documented in more detailed level in Customers Efecte AD integration description, provided by ongoing Efecte project. 


Customer deliverables
 

Information Example
Technical user name
Service account name which is used for reading data from customers AD. This is send to responsible Efecte consultant via secure mail.
SA_Efecte_Read
Password
Password for the service account. This is send to responsible Efecte consultant via secure mail
Minimum 10 characters

Port

Port to be used for connection to customer AD. Default is 636. 

636

IP-address or hostname

Host address or host name which will be used connecting to customers AD

10.1.11.1

OU's for user accounts

From which OU (can be several) user accounts are read from AD or which OU's are excluded.

OU=Users,OU=Example,DC=Efecte,DC=local

OU's for groups

From which OU (can be several) groups are read from AD or which OU's are excluded.

OU=Groups,OU=Example,DC=Efecte,DC=local

Certificate

EPE stores AD certificates in a file (truststore) with format PKCS 12.

AD certificate must use X.509 standard/structure and they must use PEM format (Base64 ASCII encoded file)

Note it's not recommended to use certificates loaded directly from AD server, instead it is preferred to use intermediate CA that is used to sign server certificates as they last longer that server certificates (only 1 year mostly).

 

Certificates needs to be set in place and delivered to responsible Efecte consultant.

 

AD connector description

More info about AD connector can be found from here.

 

Test environment compared to Production

It is good practice to create a dedicated service account for the test environment, with read-only access to the test directory or test OU. In production, broader rights to read everything that is needed.

 

 

engine provisioning

Was this article helpful?

Yes
No
Give feedback about this article

Table of Contents

Related Articles

  • Efecte Secure Access - Customer instructions for User Federation (AD)
  • Secure Access - Customer instructions for Entra ID configuration OpenID Connect (OIDC)
  • Customer Instructions for IGA Project
  • Efecte Secure Access - Customer instructions for Strong authentication

Copyright 2026 – Matrix42 Professional.

Matrix42 homepage


Knowledge Base Software powered by Helpjuice

0
0
Expand