Generic LDAP format

The table below describes how mail addresses, groups, and user information must be formatted in generic LDAP input.

Mail fields Syntax Description Format Other
Primary Mail %mail%

Directory string

Example: jsmith@acme.com

Text

Mandatory

Globally unique

Mail aliases/

proxy addresses

%rfc822mailbox%

Directory string

Example: joe@acme.com

smith@acme.co.uk

Text

Optional

Globally unique

Groups fields Syntax Description Format Other
Name %CN%

Directory string

Example: Name, CN, sAMAccountName,

Display Name

Text

Mandatory

Unique in account

GUID

%objectGUID%

Hex string

Example: 746B8515-C8FF-C940-

9D905F053CB22D25

Hex 16 bytes

Mandatory

Unique in account

Group Parents

%memberOf%

DN

Example: CN=AllStaff,

OU=London, DC=acme,

DC=com

Text

Optional

Unique in account

Group Members

%member%

DN

Example: CN=Sales

,OU=London,

DC=acme,DC=com

Text

Optional

Unique in account

User fields Syntax Description Format Other
Name %CN%

Directory string

Can be constructed dynamically to become the NTLM ID for the user object. A typical NTLM ID is domain\username, for example acme\JSmith.

Text

Mandatory

Unique in account

Primary Mail

%mail%

Directory string

Must be a valid SMTP email address.

Text

Mandatory

Globally unique

Mail aliases/ proxy addresses

%rfc822mailbox%

Directory string

Must be a valid SMTP email address.

Text

Optional

Globally unique

Primary Group

%primaryGroupId%

Integer

Not used

Text

Not used

Other Groups

%memberOf%

DN

Example: CN=AllStaff,

OU=London,

DC=acme,DC=com

Text

Optional

Unique in account

GUID

%objectGUID%

Hex string

Example: 746B8515-C8FF-C940-

9D905F053CB22D25

Hex 16 bytes

Mandatory

Unique in account