Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Active Directory

CTS
eCTS

This section configures the synchronization of the app with Active Directory.

AD Connection Parameters

Parameter Description
FQDN or IP address of the domain controller, the connection port, and the Active Directory domain More details admin guides.
If the Active Directory forest contains multiple domains, leave the domain field blank. Otherwise, users will need to manually clear this field when logging into the app.
Max login attempts
Failed login timeout (in seconds)
Protection against password brute-forcing. It is recommended to set this to 1 attempt less than in AD policies.
Prefill the domain part of the login on clients Here you can choose whether to pre-fill the domain on clients or not, so that users with different SamAccountName and UserPrincipalName do not experience login issues.

Logout Settings for AD

Parameter Description
Logout request by user request
(Leave Server button in the app),
Logout request by account deleted (more details),
Logout request by admin request
(Logout button for the user in the admin panel)
These logout request sources are system sources and cannot be turned off, but you can configure the auto-confirmation time for them.
Auto-confirm user logout requests Here you can configure whether requests from users via the profile settings in the app will be automatically confirmed.
Logoff by disabled Automatic logout from sessions when an account is disabled in AD and sending a logout request.
Logoff by lockout Automatic logout from sessions when an account is locked in AD and sending a logout request.
Logoff by account expired Automatic logout from sessions when an account expires in AD and sending a logout request.
Logoff by password expired Automatic logout from sessions when a password expires in AD and sending a logout request.
Automatic logout when synchronization with AD is excluded from the selection Automatic logout from sessions and sending a logout request when a user is excluded from the AD synchronization filter with the application.
Logoff by password change Automatic logout from sessions after a password is changed in AD and sending a logout request.
User Account Disabled (AD LDS) Automatic logout from sessions when an account is disabled in AD and sending a logout request.
Auto-confirm after N days For each reason, you can set the number of days after which the logout request is confirmed without administrator intervention. Since version 3.58.
For immediate confirmation, select 0 days.

Authorization Method

Choose between a simplified (matching by email domain) and a full authentication method.

Channel Binding Token (CBT) Policy Support

If the Domain Controller: LDAP server channel binding token requirements policy is set to Always or When supported, you must enable the Enable NTLM channel binding (CBT) checkbox here so that users can log in to eXpress without receiving an “Invalid credentials” error. The setting is available from version 3.60.

Attribute Mapping

Define which user attributes from AD will be used in the messenger profiles.


For proper operation, ensure the attribute case matches the LDAP records.

Manage Settings

Button Action
Default settings Resets to standard values
Delete Disables synchronization (does not affect existing users)
Save Applies changes.

Additional Questions

The Account from AD Did Not Appear in the User List. What to Do?

If an account from AD does not appear in the Users section of the admin panel:

  1. Wait for synchronization or force it manually.
  2. Check in AD: account status, password expiration, and other restrictions.
  3. Perform a test LDAP query (e.g., ldapsearch) to verify the sync filter.

What Are the Requirements for User Avatars in AD?

JPG format, 500×500 pixels, no larger than 100 KB.