Active Directory settings
Active Directory settings
Once the connector is installed (see Set up Active Directory sync), these settings decide how it builds and places accounts in your Active Directory — which domain, where each type of user goes, how names are formatted, what scripts and drives they get, and their default password. Save changes here and the connector uses them on its next run.
The settings are grouped into sections down the left of the page: General, Staff, Students, Groups and Scripts.
Before you start
- You must be a school admin with sync settings permission, with the school selected in the switcher.
- Have your AD structure to hand: your domain name, the OU (organisational unit) paths where staff and students should live, and any logon-script or home-drive conventions you use.
- If you're not sure of a setting, turn on Test mode (below) so the connector reports what it would do without writing anything.
Wildcards (placeholders)
Several fields accept wildcards — short tokens the sync replaces per user when it runs. Each field that supports them shows an Available wildcards button listing exactly which ones apply there.
- Display-name fields use name wildcards such as
%PF(preferred forename),%PS(preferred surname), first-character variants like%PFFC, and — staff only —%TITLE(e.g. Mr, Mrs, Dr). Learners have no title, so%TITLEis offered on staff names only. - OU / path / group / script fields use structural wildcards such as
%UN(AD username),%RG(registration group),%YG(mapped year group),%TS(teaching / non-teaching),%IY(mapped intake year),%SC(staff code),%ORG(school name) and%DAY/%TIMESTAMP(dates). The mapped values (%YG,%IY) come from the mappings you set in AD advanced settings.
Steps
Step 1 — Open Active Directory settings {#step-1}
Open Active Directory settings for the school. The General section is shown first.
Step 2 — General: domain, names and global options {#step-2}
In General, set the domain and school-wide behaviour:
- Domain name — your AD domain, e.g.
school.local. - NetBIOS / domain (without DC) — the short domain name, e.g.
SCHOOL. - UPN suffix — the domain part of user principal names, e.g.
school.org. Enter it without a leading@— the connector adds the@when it builds[email protected]. If a stray@is entered, it's stripped automatically before export so the UPN is never doubled (user@@school.org). - Test mode — when on, the export appends
_tstto every username, email address and OU path it produces, so anything the connector creates from that run is unmistakably test data rather than mixed in with your real accounts — easy to find and clean up if something isn't right. Ideal for a first run or after big changes: check the preview and export (the_tstsuffix is visible there), then turn test mode off to go live with real names. - Remove special characters from names — strips characters AD dislikes from generated names.
- Sync passwords to AD — turn this on to push password sets/resets to AD. This is also what enables the AD password updates log.
- Move existing staff / students to OU on change — when a user's circumstances change (e.g. year group), move their existing AD account into the newly-correct OU rather than leaving it in place.
- Exclude protected staff / students — leave protected accounts out of the AD sync.
- Staff display name format and Student display name format — the templates that build each account's display name, using the name wildcards above (e.g.
%TITLE %PF %PSfor staff,%PF %PSfor students).
Step 3 — Staff: placement, passwords, scripts and drives {#step-3}
In Staff, control staff accounts:
- Process staff accounts — master switch for whether staff are synced to AD at all.
- Password behaviour: Change password at next logon, Password never expires, User cannot change password, and a Default staff password (a masked field — leave it blank to keep the stored value).
- Staff OU path — where staff accounts are created, e.g.
OU=Staff,DC=school,DC=local. Supports path wildcards. - OU if teaching / OU if non-teaching — optionally place teaching and non-teaching staff in different OUs.
- Leavers OU path — where staff who have left are moved to.
- Profile path, Connect path, Logon script, Home server name, Home local path and Home drive (e.g.
H:) — the roaming-profile, script and home-directory settings applied to staff accounts. All support path wildcards.
Step 4 — Students: placement, passwords and intake {#step-4}
In Students, the same kind of controls for student accounts:
- Process student accounts — master switch for students.
- The same password behaviour toggles and a masked Default student password.
- Student OU path and Leavers OU path, plus Profile path, Connect path, Logon script, Home server name, Home local path and Home drive.
- Year 7 intake year and Year 7 leaving year — the reference years used when working out year-group placement.
Step 5 — Groups and Scripts {#step-5}
- Groups — the AD groups new accounts are added to, entered one group per line: separate lists for Staff groups, Teaching staff groups, Non-teaching staff groups and Student groups. These support path wildcards too.
- Scripts — additional scripts to run for Staff, Teaching staff, Non-teaching staff and Students.
Step 6 — Save {#step-6}
Select Save settings. The connector picks up the new configuration on its next run. If you have a MAT and want the same structure across schools, many of these fields can be pushed trust-wide — see Apply sync settings across the trust.
A note on masked passwords
The Default staff password and Default student password fields are masked. Once a value is saved they show as dots, and leaving them blank when you next edit keeps the stored password unchanged. Only type into them when you actually want to set a new default.