Configure LDAP on Pathfinder

Overview

Pathfinder authenticates users through a connected BeyondTrust product instead of connecting directly to Active Directory or LDAP. The connected product — Privileged Remote Access or Remote Support — acts as the proxy site for directory authentication.

Prerequisites

Before you begin, make sure you have:

  • Administrator access to Pathfinder.
  • The directory domain and any required connection details.
  • A connected BeyondTrust product configured with an LDAP or Active Directory provider.
  • A non-directory (local or SSO) admin account. AD/LDAP-authenticated admins can't configure a directory proxy. The proxy must exist before their accounts can log in at all.
🚧

Important information

This procedure assumes you have already configured an LDAP or Active Directory provider in your BeyondTrust product. If you have not, complete the appropriate configuration procedure before continuing.

Although Password Safe appears as a product option, it is not currently available for use with directory authentication in Pathfinder.

Register the directory provider

  1. Log in to Pathfinder as an administrator.
  2. From the tenant dropdown, select Administration.
  3. Open the navigation menu and click Directory Authentication.
Navigation menu with Administration expanded and Directory Authentication selected.
  1. On the Directory Authentication page, you can add a new directory provider or edit an existing one.
Directory Authentication page showing existing providers with options to add, edit, or remove a provider.
  1. When adding a provider, configure:

    • Label
    • Provider type
    • Domain or server
    • Proxy site
    • Product
Add Directory Provider page with settings to configure an Active Directory or LDAP provider through a connected BeyondTrust product.
⚠️

Warning

Removing a provider prevents users who rely on that directory from signing in unless another authentication method is available.

Provision users

Users sign in with their Active Directory username and password using the organization-specific URL. For example:

https://login.beyondtrust.io/signin/signIn?orgId=your-org-id

Replace your-org-id with your organization's ID. Active Directory and LDAP user accounts are created automatically the first time users sign in. Invite users manually only if you want to configure their access before a user's first sign-in.

ℹ️

AD/LDAP is the only method these accounts can use; there is no fallback to local or SAML. If the LDAP server or proxy configuration breaks, affected users can't sign in until it's restored.

Local accounts can never convert to AD/LDAP accounts, since only directory-provisioned user names carry the Org ID suffix.


©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.