Configuring AADS credentials to access the Device Adapter Corporate Directory

Last Updated : Jan 13, 2023 |
Prolog information
In Release 8.1.3 and earlier, Device Adapter used the Trusted Hosts feature to authenticate in AADS. From Device Adapter Release 8.1.4, you can alternatively use credentials for an existing LDAP user to access the AADS. This is beneficial in environments where it is impossible to use the Trusted Hosts feature to authenticate in the AADS.
Note:
The Trusted Hosts feature is the recommended method to authenticate in the AADS. Use the following procedure only in instances where you are unable to use the Trusted Hosts feature.
From Release 8.1.4, do the following steps to configure the Corporate Directory using AADS and without using the Trusted Hosts configuration.
  1. Do the following steps to configure a service AADS account in the Active Directory or in a different LDAP service used by the AADS:
    1. Create a service user within a target group on the LDAP server.
    2. Configure a password for the user. Disable the password change after the first login.
      ADDITIONAL INFORMATION:
      Note:
      Configure a password expiration policy for the user. Consider that Device Adapter cannot change the password automatically when the password expires and an expired password can affect access to the AADS.
    3. Assign an email address to the user.
    4. Add the user to a user group, which is configured as a user role on AADS.
    5. Ensure that the user is active.
    ADDITIONAL INFORMATION:
    Note:
    For more information about configuring user accounts, see the LDAP service documentation.
    The service AADS user requires permission to read data for other users in the group, but the service AADS user should refrain from getting permission from users with administrative privileges.
  2. Log on to AADS using administrative credentials.
  3. On the AADS web console, navigate to Server ConnectionsLDAP ConfigurationEnterprise Directory, switch to a tab for a corresponding LDAP server.
  4. Click Force LDAP sync to synchronize accounts.
  5. Log on to System Manager using administrative credentials.
  6. On the System Manager web console, navigate to ElementsAvaya Breeze®Configuration.
  7. Click Attributes.
  8. To configure the AADS server address, AADS service username, and user password using the cluster attributes for a Avaya Breeze® or a Device Adapter cluster:
    • On a cluster level, click the Service Clusters tab, select the cluster, and select the service as DeviceAdapter.
    • On a global level, click the Service Global tab and select the service as DeviceAdapter.
  9. On the Attributes Configuration page, navigate to the Contacts group, and do the following:
    1. In the Enable Corporate Directory field, in Effective Value, click Yes to enable Corporate Directory support.
    2. In the Enable Personal Directory field, in Effective Value, click Yes to enable Personal Directory support.
    3. In the Avaya Aura Device Services (AADS) FQDN field, in Effective Value, type the FQDN that you want to use to access the AADS server.
    4. In the Avaya Aura Device Services (AADS) Port field, in Effective Value, type 8443 to access the AADS server.
    5. In the Avaya Aura Device Services (AADS) - Username field, in Effective Value, type the username, which permits alphabets, numbers, and the following symbols: "@", "-", "_", and ".". The username should match the UID of the service user.
      ADDITIONAL INFORMATION:
      Note:
      The actual UID depends on the UID Attribute ID configured on AADS. If UID Attribute ID is set to userPrincipalName, the username will be <user_name>@<domain_name> and if UID Attribute ID on AADS is set to sAMAccountName, the username will be <user_name>.
    6. In the Avaya Aura Device Services (AADS) - Password field, in Effective Value, type the password, which permits alphabets, numbers, and special characters. Set the AADS password similar to the one configured in LDAP.
    7. Click Commit.
  10. Ensure that the phones have Corporate Directory Allowed (CRPA) enabled in the Features field.