Rejected LDAP/Active Directory Authentication - Replaced with SSO

James Gauci

Forum User
Joined
Jul 4, 2017
Messages
4
Reaction score
14
Hi All,

I am a prospective customer of 3CX for a team of 200 clients across a WAN, however one area that is essential for us is LDAP/Active directory authentication of users.

While I see that LDAP integration is available for the web meeting system, the contact component of 3CX has is own seperate credentials database.

Passwords can be revealed in clear text which I agree is a handy feature for some but a security concern in our environment.

Furthermore, it means we need to manage two seperate directory username/password systems which is time consuming.

Other competitive solutions have this functionality by default, however if this issue was resolved for us, we would jump onto 3CX tomorrow.
 
Upvote 139
I would LOVE to see the ability to link 3CX into AD to pull user pictures (Already populated for all email users, could match extensions based off the email attribute vs the extensions email)
 
+1
LDAP, AD , ADFS, SAML ... all are ok for me
but please implement only one of them in order to be able to offer an SSO to my users !
we are deploying the app on all computers just because webapp need a different password ; wrong story way...
BR
Stéphane
 
SSO for the web client would be awesome.
 
+1
 
V16 has AD import however there are no instructions written on how to use it. There should be an option to filter inactive users, filter by OUs and all...
 
+1
i need this
 
+1000

O365 integration is nice, but quite a lot of my customers are using ADFS to bridge Azure AD and on-prem AD. Local 3CX authentication is not the way to go as people cant even remember their own passwords. There has to be a way of syncing passwords or authenticating via ADFS, AD, LDAP, SAML or Radius for the 3CX Web Client. In this day, it is common practice to have this "feature" in all major software packages. Companies will drop 3CX from the list just because of the lack of central authentication support

And while I'm here, an API to query extensions, provision/remove users/extensions is a highly desirable feature for, not only large sites, but also for all sites where support staff is limited and operations is reliant more and more on automated processes. Most of the companies I work with have highly automated processes to provision users because of security concerns. The less people touching the data, the less of a chance that they could compromise the system security.

Please seriously consider these requests. They would go a long way to have more and more companies accepting 3CX into their fold.
 
They should never have taken this out of the previous version, it was really easy to add extensions to 3CX importing from Active Directory.
I propose that in the new implementation of Active Directory there is an option to list OU's from Active Directory that automatically add all the user accounts that reside in it. This way you have automatic user/extension creation in 3CX which makes management a lot easier. Off course there should also be an option to manually pull/import from Active Directory for other users.
 
One Problem ist the automatically creation of new extensions/user in 3CX, but the other problem is the administration of credentials to log-in in the web client. I hope a good solution is coming as soon as possible

+1
 
We are working on user sync with Office 365 and later Google gsuite. Also client authentication via Office365 and Google will be possible....
Do you know when we can expect SSO/SAML with Office 365? I know the integration is getting more features in U5 (according to the roadmap), is it one of them?
 

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur