Setting up Bitrix24 integration with LDAP/Active Directory
Imagine: in a company of 200 employees, the HR person adds a new employee to Active Directory, then separately creates an account in Bitrix24, manually adds them to the correct department and groups. When someone leaves—the same process in reverse. Six months later, there are 30 "dead" accounts in Bitrix24, and a new manager has been working for two weeks without CRM access—the request to create an account got lost. Every manual process wastes time and invites errors: forgot to create an account—the person can't work; forgot to disable—a departed employee still has access to CRM and documents. The LDAP integration we configure solves this: a single source of truth—Active Directory—and Bitrix24 synchronizes automatically. We have 8+ years of experience setting up LDAP integrations for on-premise Bitrix24 and guarantee stable operation.
Requirements and limitations
LDAP integration is only available for the on-premise version of Bitrix24. Cloud Bitrix24 does not support direct LDAP connections—for the cloud, use SSO solutions (SAML, OAuth). We strongly recommend using LDAPS (port 636) instead of unencrypted LDAP, as LDAPS reduces the risk of credential interception by a factor of about 100.
Required connection parameters:
| Parameter |
Value |
| LDAP server |
IP or FQDN of domain controller |
| Port |
389 (LDAP) or 636 (LDAPS) |
| Base DN |
DC=company,DC=local |
| Bind DN |
Service account with read access to directory |
| Protocol |
LDAP v3 |
| Encryption |
LDAPS (port 636) or STARTTLS |
Protocol comparison:
| Protocol |
Port |
Encryption |
Security |
| LDAP |
389 |
None |
Low |
| LDAPS |
636 |
SSL/TLS |
High |
The service account should not be a domain administrator. Read rights on objects in the required OUs are sufficient.
How synchronization with Active Directory works
In Bitrix24 admin panel: Settings → LDAP servers → Add. Connection parameters:
- Server—address of the domain controller. For fault tolerance, you can specify multiple servers separated by spaces.
- Base DN—root container for user search. If users are in multiple OUs, configure multiple LDAP connections or use a higher-level Base DN.
- User filter—LDAP filter for selection:
(&(objectClass=user)(objectCategory=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))—active users, excluding disabled accounts.
- Field mapping—correspondence of LDAP attributes to Bitrix24 fields:
sAMAccountName → login, mail → email, displayName → name, department → department, telephoneNumber → work phone.
All mappings are flexibly configured to your AD schema. We also prepare documentation for each field.
Synchronization of groups and departments
LDAP groups are mapped to Bitrix24 groups. A user added to the Sales group in AD automatically lands in the "Sales department" group in Bitrix24. Mapping is set in the LDAP server settings: group field memberOf, binding to Bitrix24 groups by name or ID.
Departments are synchronized by the department attribute or by OU structure. If AD has OU=Marketing,OU=Users,DC=company,DC=local, users from this container go to the "Marketing" department in Bitrix24.
Why automatic deactivation is important
The key task is to promptly block access for a departed employee. During synchronization, the LDAP connector checks the account status in AD:
- Account disabled (
ACCOUNTDISABLE flag in userAccountControl) → user is deactivated in Bitrix24.
- Account deleted from AD → user is deactivated in Bitrix24 at the next synchronization.
- Account moved to the departed OUs → if the OU is not in the Base DN, the user is also deactivated.
Synchronization runs on a schedule via the cron agent of the LDAP module. Recommended interval: every 15-30 minutes. For critical cases (immediate blocking upon termination), manual synchronization or direct deactivation in Bitrix24 can be used.
We provide full schedule configuration and error notifications for synchronization failures.
What's included in the turnkey setup?
- LDAP server connection with encryption (LDAPS/STARTTLS)
- Mapping AD attributes to Bitrix24 profile fields
- Filters for selecting required users and excluding service accounts
- Synchronization of AD groups with Bitrix24 groups and departments
- Automatic deactivation upon blocking/deletion in AD
- Configuration of cron synchronization schedule
- Documentation of settings and synchronization algorithm
- Administrator training (optional)
- Technical support for 2 weeks after launch
How we guarantee stability
We test the integration in a staging environment before moving to production. We provide a verification checklist: all accounts synchronized, deactivation works, groups map correctly. In case of failure, prompt recovery. Our engineers hold 1C-Bitrix certifications and have experience with large domain structures (up to 10,000 users).
We will assess your project and propose a setup timeline from 2 to 5 days depending on complexity. Contact us for a consultation.
How a corporate portal on Bitrix24 solves the problem of information chaos?
Employees spend up to 2 hours a day searching for files, emails, and solutions. Tasks get lost in dozens of chats, approvals get stuck for weeks. The manager learns about missed deadlines only at a meeting. A corporate portal on Bitrix24 ties every message, document, and task to a single context. You get a transparent picture of work: who is working on what, which stages, where bottlenecks are. Wikipedia: Information silo describes how unorganized data reduces productivity – a portal cuts that loss by 60–70%.
We will evaluate your project for free – contact us to get the architecture in 2 days. A medium‑sized company typically saves 2.5 million rubles annually after deployment (based on our projects).
What does the portal offer in daily work and why is it better than messengers?
In messengers, information is unstructured – discussions get buried within a week. On the portal, every message is tied to a task, project, or document. Employees spend up to 30% of their work time searching for data (McKinsey). The portal reduces this time by 2–3 times thanks to structured repositories and full‑text search.
Communications. Activity stream, messenger, and video calls are tied to specific tasks. Any discussion can be found six months later – in a messenger it would be buried within a week.
Tasks and projects. Kanban, Gantt, checklists, dependencies, time tracking. Each employee's efficiency is visible in reports – no need to wait for a meeting.
Document flow. Approval routes through the business process designer: leave request → manager → HR → accounting. Electronic signature, versioning, deadline control. Integration with electronic document management (SBIS, Diadoc) via REST API.
HR. Onboarding of new employees, leave/travel requests, organizational structure, absence schedule. An employee knows where to go from day one.
Knowledge base. Bitrix24 wiki engine: regulations, instructions. Knowledge does not leave with departing employees.
Implementation example. For a manufacturing company with 320 employees, we deployed a portal with integration of 1C:SALARY AND HR MANAGEMENT and Active Directory in 4 months. Travel request approval time decreased from 3 days to 4 hours. Savings on employee idle time amounted to 1.5 million rubles per year. Managers receive automatic reports on department efficiency. Customer response time decreased by 20%. Portal payback period is 7 months.
How does integration with 1C and Active Directory accelerate HR management?
Integration with 1C:Enterprise via the b24connector module or custom REST handler: a leave request is approved on the portal through a business process and automatically enters 1C:SALARY AND HR MANAGEMENT for vacation pay calculation. Active Directory (SSO via the ldap module) – the employee account is created once in AD and synchronized to the portal, email, VPN. Upon dismissal, it is blocked everywhere. Manual account creation is eliminated, errors are minimized.
Types of corporate portals and key integrations
| Type |
Purpose |
Key Feature |
| Intranet |
Internal communications and services |
News, phone directory (sync with AD), meeting room booking, IT requests via BP |
| HR portal |
HR management and development |
Profiles, KPI/OKR on custom HL blocks, training, electronic document flow |
| Knowledge portal |
Documentation and regulations |
Categorization, tags, ratings, subscriptions to updates |
| Extranet |
Work with partners and contractors |
Granular permissions via CGroup and extranet module, access without VPN |
| Holding portal |
Management of multi‑company structure |
Separate workspaces, consolidated reporting, cross‑cutting BPs |
Additional integrations that deliver real value:
- Email: Exchange via EWS API or IMAP, calendar synchronization, creating a task from an email.
- IP telephony: Asterisk, Mango Office, Zadarma via REST API – calls from the portal, contact card, call recording.
- Video conferencing: built‑in video calls or integration with Zoom/Teams via marketplace.
- EDI: SBIS, Diadoc via REST API – fully electronic document flow with counterparties.
Security and compliance with Federal Law 152‑FZ
The portal contains personal data, financial reports, strategic plans. We guarantee protection:
- role model via CGroup and section‑level permissions;
- two‑factor authentication (OTP, Yandex.Key, SMS);
- audit of all actions (b_event_log);
- TLS encryption for transmission and disk encryption;
- full compliance with Federal Law No. 152‑FZ "On Personal Data".
How is implementation carried out? Step‑by‑step plan
| Stage |
Duration |
What we do |
| 1. Audit |
2–3 weeks |
Interviews, process analysis, architecture, integration plan |
| 2. Setup and customization |
3–6 weeks |
Structure, roles, BPs, branding (CSS template) |
| 3. Integrations |
2–4 weeks |
1C, AD, email, telephony, EDI |
| 4. Data migration |
1–2 weeks |
Documents, directories, employees from current systems |
| 5. Training and pilot |
1–2 weeks |
Administrators, key users, pilot of 20–30 people |
| 6. Scaling |
2–4 weeks |
Connecting departments, fine‑tuning based on feedback |
- Audit — we record current processes, measure time losses.
- Design — choose portal type, plan integrations.
- Implementation — configure business processes, permissions, interface.
- Test — pilot group tests scenarios, we fix issues.
- Launch — connect all employees, train, hand over documentation.
What you receive after implementation
- Project documentation: architecture, integration scheme, business process diagrams.
- Configured portal with all integrations (1C, AD, telephony, EDI).
- Business process descriptions and instructions for administrators and users.
- 30 days of technical support after launch.
- Access to our knowledge base and migration scripts.
Post‑launch support: how to prevent the portal from becoming obsolete
After six months, many portals become abandoned. To avoid this, we offer packages with fixed SLA and a dedicated administrator. Performance monitoring, platform updates, user administration, development of new modules. Our team has over 10 years of experience and more than 50 implemented corporate portals on Bitrix24. We are a certified 1C‑Bitrix partner, guaranteeing quality and deadlines.
Mobile access. Native Bitrix24 app (iOS/Android) with push notifications, tasks, chats. Responsive web interface for extranet users (no app installation required). Offline access to documents and tasks, sync when connectivity is restored.
Order a turnkey corporate portal implementation
Schedule a free audit – we will evaluate your project, propose architecture, and give clear timelines. Get a comprehensive proposal and see that the portal pays for itself within the first six months. Contact us today.