Active Directory management & automation

Allow Using Templates for User Creation

You can make the process of creating user accounts in the Adaxes Active Directory Web Interface faster and more efficient by using templates.

By creating a user template, you can make a copy of it when you need to create an account for a new user. Properties of the user template and its group membership will be copied to the new user account. This eliminates the need to type in the same property values and specify group membership each time you create a new user in Active Directory.

Creating a User Template

Creating a user template involves creating a new user account. It is recommended to create a template account for each category of users in your organization. For example, you could create a template for regular users and another one for Help Desk users.

When naming a template, it is recommended to place an underscore or a hyphen at the beginning of the user's Full Name so it will be at the top of the list. Example: _SalesPerson, _Subcontractor.

In this tutorial you will learn how to define a Create User action for the Web Interface Home page that will use a template for creating users.

On the computer, where the Web Interface is installed, start the Web Interface Customization tool.


In the Interface type drop-down list, select the Web Interface that you want to configure.



Activate the General tab, select the Actions pane option, and click Configure Home Page Actions.


In the Home Page Actions dialog, you will see all the actions available on the Actions pane.



To add a new action to the Actions pane, click the Add button located at the bottom of the Home Page Actions dialog.

To add an action to a group of actions, select the group prior to clicking the Add button.

On the first step of the Add Home Page Action wizard, select Copy User and click Next.


At the second step of the wizard, provide a name and a brief description for the new action. Click Next.



On the Object Selection step, you can configure options for choosing the user account that will be used as the template. The default settings allow users to choose any user account to be used as the template.

If you want the account of the user who initiated the action to be always used as the template, select the Always copy the account of the currently logged on user option.



If you want a specific user account to be always used as the template, enable the Always copy a specific AD object option, and enter the distinguished name (DN) of the template account in the Object DN field.

How to get the DN of an object

To get the DN of an Active Directory object:
  • Launch the Adaxes Administration Console.
  • Right-click the object you need.
  • In the context menu, open the submenu of the Copy item.
  • Click Copy DN. The DN of the selected Active Directory object will be copied to the clipboard.
If you want the template account to be determined depending on the user initiating the action, you can insert value references (e.g. %department% or %company%) as a part of the object DN. When the action is executed, the value references will be substituted with corresponding property values of the account of the user who initiates the action. For example, if you specify the following DN:

CN=_%company%Template,OU=Templates,DC=company,DC=com,

and the Company property of the user who initiates the action is set to Acme, the DN will be set to

CN=_AcmeTemplate,OU=Templates,DC=company,DC=com.

To insert a value reference, click the button at the right side of the Object DN edit box.

To allow users to select the account to be used as the template, enable the Allow users to select the object to copy option.



If you store all user templates in a separate Organizational Unit, enable the Allow selecting only AD objects located under a specific OU or container option and enter the distinguished name (DN) of the OU in the Container DN field.

How to get the DN of an object

To get the DN of an Active Directory object:
  • Launch the Adaxes Administration Console.
  • Right-click the object you need.
  • In the context menu, open the submenu of the Copy item.
  • Click Copy DN. The DN of the selected Active Directory object will be copied to the clipboard.
If you want the OU containing user templates to be determined depending on the user initiating the action, you can insert value references (e.g. %department% or %company%) as a part of the object DN. When the action is executed, the value references will be substituted with corresponding property values of the account of the user who initiates the action. For example, if you specify the following DN:

OU=%department%,OU=Templates,DC=company,DC=com,

and the Department property of the user who initiates the action is set to IT, the DN will be set to

OU=IT,OU=Templates,DC=company,DC=com.

To insert a value reference, click the button at the right side of the Object DN edit box.

If users must be able to see only the accounts that match a specific search criteria when selecting the template, enable the Allow selecting only AD objects that match the specific LDAP filter option and enter a search filter in the LDAP filter field.

For example, if all user templates contain the word 'Template' in their names, you can use the following filter: (name=*Template*). If you follow the convention that names of all user templates begin with an an underscore, you can use the following LDAP filter: (name=_*)

How to construct an LDAP filter

To construct an LDAP filter, you can use the Find dialog in the Adaxes Administration Console:
  • Launch the Adaxes Administration Console.
  • Connect to your Adaxes service and click Find on the toolbar.
  • Activate the LDAP Search tab.
  • In the Enter LDAP filter field, click the embedded button to build a filter using the LDAP Filter Builder.
If you want the search filter to depend on the user initiating the action, you can insert value references (e.g. %department% or %company%) as a part of the LDAP filter. When the action is executed, the value references will be replaced with corresponding property values of the account of the user who initiated the action. For example, if you specify the following filter:

(manager=%distinguishedName%)

the %distinguishedName% value reference will be replaced with the DN of the user who initiated the action. In this case, only user templates for which the user is set as the manager will be available.

To insert a value reference, click the button at the right side of the Object DN edit box.
It is recommended to clear the Do not display available objects automatically check box if at least one of the two options described above is enabled.


When finished, click Next.

On the Target OU/Container Selection step, configure the options for selecting the OU or container where new users will be created. Click Next.
For details on how to customize the options, see Configure Home page actions.

On the Form Customization step, you can customize the form used to create users.
Customization of the form for the action doesn't affect other user creation forms used in the Web Interface.
To customize the form that will be used to create new users:
  • Select the Use customized form option.
  • Click Customize Form.
  • Modify the form to fit your needs and click OK.
For details on how to customize forms, see Customize Forms for User Creation and Editing (starting from Step 6).
Click Finish and then click Apply.
There is no need to restart IIS to apply the changes, as the changes are applied automatically.
? Waiting

Progress status: Checking...