Rejected LDAP/Active Directory Authentication - Replaced with SSO

James Gauci

Forum User
Joined
Jul 4, 2017
Messages
4
Reaction score
14
Hi All,

I am a prospective customer of 3CX for a team of 200 clients across a WAN, however one area that is essential for us is LDAP/Active directory authentication of users.

While I see that LDAP integration is available for the web meeting system, the contact component of 3CX has is own seperate credentials database.

Passwords can be revealed in clear text which I agree is a handy feature for some but a security concern in our environment.

Furthermore, it means we need to manage two seperate directory username/password systems which is time consuming.

Other competitive solutions have this functionality by default, however if this issue was resolved for us, we would jump onto 3CX tomorrow.
 
Upvote 139
+1
LDAP, AD , ADFS, SAML ... all are ok for me
but please implement only one of them in order to be able to offer an SSO to my users !
we are deploying the app on all computers just because webapp need a different password ; wrong story way...
BR
Stéphane

+1 For us still.
 
+1

Pretty sure this isn't going to happen at this point... We've been asking for 2 years and some change? I'm not holding my breath, and not sure what to do about moving forward with new clientele on 3cx for this reason primarily.

As an MSP, efficient user management via SSO are imperative for obvious reasons. SSO for administration is just as important. As other have mentioned, the support for MFA combined with SSO is definitely imperative considering today's threat environment.

Here's for wishful thinking...
 
We lost a deal, thousands of users and no sync/SSO, it was not possible to sell it :(
+1
 
+1 Here's for wishful thinking... too
 
+1 i lost multiple leads because of the missing LDAP Integration.
compareable PBX solutions like Starface or pascom PBX have this integration. I love 3CX, but missing this simple Enterprise feature is really an issue.
 
The password handling in the 3cx is a NoGo. It is not possible that users have to remember an extra password for the 3cx-webgui that then never expires.
An authentication against a directory (LDAP, AD) is necessary to meet the basic security requirements. it should be possible to create an appropriate interface.

This means that I cannot place the system with my customer because the person responsible for security vetoed it.
 
  • Like
Reactions: Andreas Conrad
Guys this is a really basic security feature. Can anyone from 3CX please let us know if this will ever be implemented or not? If not then we'll definitely move to another solution as soon as we can.
 
+1
We need SAML and user provisioning with GSuite
 
Last edited:
+1
 
We are working on user sync with Office 365 and later Google gsuite. Also client authentication via Office365 and Google will be possible....

@Nick Galea very greatfull if you could give an update on this
 
@Nick Galea very greatfull if you could give an update on this
I would love to see an update here as well. I mean you can import the users from o365 which already the first step. But the password handling for 420 users is not fun at all + you would immediately be able to provide MFA due external logins.
 
I'm also wandering why ideas with <100 votes get into the next level (in Consideration) when such important Enterprise feature get no attention yet.
 
Very important for our customers with 32 SC or 100 extensions and up.
 
+1
 
When you login to your Windows desktop, 3CX phone for Windows has your extension and PIN saved in a configuration file so you don't need to "log in" each time you open the application. If this approach is acceptable, VoIPTools can do the same so that when you log in to Windows it also logs you into 3CX. It would require a small .exe be placed in Windows startup.
 

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur