# Set up Active Directory login

Connect Content Central to your Windows domain so people sign in with their AD passwords — the Configuration Manager setup, importing the users, and what stays true afterward.

Product: content-central · Versions: 7.x · Audience: system-administrator · Time: 30 minutes · Last verified: 2026-09-05

Canonical: https://help.ademero.com/content-central/administration/set-up-active-directory-login

**At the end of this guide, your domain is connected, your people are imported as AD-linked users, and they sign in to Content Central with the same password they use for Windows — validated by your domain controller, never stored by Content Central.**

Two halves: the **domain connection** (Configuration Manager, on the server) and the **user import** (web administration). Doing only the first half accomplishes nothing visible — AD users must be imported before anyone can sign in.

## Step 1: Connect the domain

1. On the Content Central server, open **Configuration Manager** and choose **Active Directory**.

2. Check **Enable Active Directory Authentication**.

3. Under **Domains**, click **Add** and replace the placeholder with your **Fully Qualified Domain Name** — the full form, like `corp.company.com`, not the short NetBIOS name.

4. Under **Active Directory Login**, enter a directory account's **User name** and **Password**, and click **Test Login**.

*[Screenshot: Configuration Manager's Active Directory screen with a domain added and Test Login showing Test Succeeded]*

5. **What you should see:** "Test Succeeded." Then click **Apply** — nothing takes effect until you do.

> **NOTE:** A failed test quotes the directory's own error — most often a wrong FQDN, or a domain controller the Content Central server can't reach. Fix connectivity before touching anything else.

## Step 2: Import the users

Sign-in requires each person to exist in Content Central as an AD-linked user — membership in an AD group grants nothing by itself.

1. In the web interface, go to **Administration** > **Users**.

2. Open the **New Active Directory User** page. On current versions this import screen opens in the Classic interface — if you don't see a button for it on the Users page, browse directly to `/Admin/AdminNewActiveDirectoryUser.aspx` under your Content Central address and it will switch views for you.

3. Pick the **Domain**, narrow the list with the **Filter** (it takes wildcards, like `sm*`), check the users to import, choose their initial permissions, and click **Apply**.

**Success check:** back on the Users page, imported accounts show **Yes** in the **AD** column. Have one imported user sign in — the login page now offers a **Domain** choice, and their Windows password works.

> **IMPORTANT:** Named-user licensing counts imported AD users like any others — import the people who'll actually use the system, not the whole directory.

## What stays true afterward

- **Passwords live in AD.** Content Central never stores them; profile fields on AD-linked users are managed in the directory (the user page says so: "These settings can be changed only in Active Directory").
- **Disabled in AD means locked out here.** Content Central follows the directory's disabled state automatically.
- **Permissions still live in Content Central.** AD answers *who you are*; what you can reach is still assigned per user and group inside Content Central.
- **Keep one local administrator.** If the domain controller is ever unreachable, a local admin account is your way in — [How signing in works](/content-central/administration/how-signing-in-works) covers that safety net and the whole three-layer picture.

## If sign-in fails after setup

Work the layers in order: does **Test Login** still succeed in Configuration Manager? Does the user exist with **AD: Yes**? Is their AD account enabled? The concepts article's troubleshooting section — [How signing in works](/content-central/administration/how-signing-in-works) — walks the full checklist, including the classic mistake of expecting an AD group membership to create users.

## What's next

- [How signing in works: local, Active Directory, and SSO](https://help.ademero.com/content-central/administration/how-signing-in-works)
- [Add a user](https://help.ademero.com/content-central/administration/add-a-user)
- [Offboard a user without breaking approvals](https://help.ademero.com/content-central/administration/offboard-a-user)
