Source record · tier 2 current vendor documentation
Deployment Guide for Directory Connector
- Publisher
- Cisco Webex
- URL
- https://help.webex.com/en-us/article/zqvufbb/Deployment-Guide-for-Directory-Connector
- Published
- 2026-09-15
- Updated
- unknown
- Accessed
- 2026-09-24
- HTTP status
- 200
- License
- Cisco website terms of use; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- Directory Connector's default incremental synchronization interval is 30 minutes on versions 3.4 and earlier and 4 hours on versions 3.5 and later. in context
- Directory Connector needs a separate instance for each Active Directory domain, and each instance must run on a host in the domain it synchronizes. in context
- Users deleted through Directory Connector are kept in the Webex cloud identity service for 7 days before they are permanently deleted. in context
- Cisco recommends integrating the organization's IdP for SSO if new Directory Connector-synced Webex App accounts should be Active before users sign in for the first time. in context
- In Directory Connector attribute mapping the only required field is uid, which is typically mapped to mail or userPrincipalName in email format. in context
- Directory Connector is supported on Windows Server 2025, 2022, 2019 and 2016, and needs .NET Framework 4.5 for TLS 1.2 support. in context
- Directory Connector can upgrade itself automatically when 'Automatically upgrade to the new Cisco Directory Connector version' is checked under Configuration > General, and Cisco recommends enabling it. in context
- The Directory Connector dashboard shows current sync status, the two most recent sync results, cloud statistics and connector status, and the Windows event viewer is used to find sync issues. in context
- By default Directory Connector synchronizes all users that are not computers and all groups that are not critical system objects. in context
- Scheduled Directory Connector synchronization is turned off under Actions > Synchronization Mode > Disable Synchronization, and synchronized users remain in Webex but stop receiving AD updates. in context
- Directory Connector requires .NET Framework 3.5 and .NET Framework 4.5, the latter being required for TLS 1.2. in context
- A Directory Connector dry run compares on-premises objects with Webex cloud objects and shows what will be added, modified or deleted, and the administrator chooses whether to retain or delete mismatched cloud users. in context
- Directory synchronization is enabled and the connector installer downloaded from Control Hub under Users > Manage Users > Enable Directory Synchronization. in context
- The account used to sign in to Directory Connector must be a full administrator account in Control Hub. in context
- A Directory Connector full synchronization sends all filtered AD objects and must run before incremental synchronizations begin. in context
- Multiple Directory Connectors can be configured so a backup takes over if the main connector or its host goes down. in context
- The Directory Connector host needs at least 8 GB RAM and 50 GB storage; no minimum CPU is specified. in context
- The Directory Connector host needs outbound HTTPS (port 443) access to the internet. in context
- Directory Connector's default incremental sync interval is every 4 hours on version 3.5 and later, and every 30 minutes on earlier versions. in context
- Directory Connector object selection can be narrowed with LDAP filters for users and groups and by choosing the on-premises base DNs to synchronize. in context
- Directory Connector treats a Webex user with no matching AD object as a mismatch no matter how that user was added to Webex, and can delete such users after the first full sync if the administrator chose delete. in context
- A multi-domain Active Directory deployment needs one Directory Connector per Active Directory domain. in context
- Full and incremental sync schedules are set by day, hour and minute under Configuration > Connector Policy in Directory Connector. in context
- The Directory Connector service account (Local System or a domain account) must be able to connect to the domain controller and read Active Directory user objects. in context
- Users deleted by Directory Connector are kept in the Webex cloud identity service for 7 days before permanent deletion, and the guide documents recovering accidentally deleted users. in context
- An auto-assign licence template must be set up before it can apply to new users synchronized from Active Directory. in context
- Directory Connector maps the Active Directory userAccountControl attribute to ds-pwp-account-disabled so disabled AD accounts are reflected in Webex. in context
- In Directory Connector attribute mapping the only required Webex field is uid, and Cisco recommends mapping it from mail or userPrincipalName. in context
- Cisco Directory Connector is supported on Windows Server 2025, 2022, 2019 and 2016. in context
Cite this source record
APA
WarmTransfer. (2026, September 15). Deployment Guide for Directory Connector. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-help-zqvufbb-directory-connector-deployment
BibTeX
@misc{warmtransfer-cisco-help-zqvufbb-directory-connector-deployment,
title = {Deployment Guide for Directory Connector},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/cisco-help-zqvufbb-directory-connector-deployment},
note = {Cisco Webex, accessed 2026-09-24}
}