Help center support eXpress

We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.

Registration Settings

CTS
eCTS

Click Save to apply changes.

CTS-Only Registration

Parameter Description
Allow registration without phone number A global server parameter that determines whether a user can log in without a phone number: via corporate email or corporate server address.
Display a warning that registration will be forbidden soon If enabled, client app users will receive a notification that registration using a phone number will soon be mandatory: Add a phone number. The administrator has prohibited login without a telephone number. Add a telephone number to continue using the app.
⚠️ If you, as an administrator, plan to prohibit logging in without a phone number, be sure to enable the warning so users have time to add phone numbers and avoid login errors. Otherwise, uncheck this box.
Additionally, in builds of the branded ETS app, some login method buttons may be disabled.
Allow skipping two-factor authentication within the contour If enabled, users with a phone number can skip SMS code verification when connecting from within the Corporate Data Transfer Network (CDTN) contour if they previously logged in without a number but were later detected with one.
Display warning about the need to add number to log in outside of a contour If the parameter is enabled, client app users will receive a notification that using a phone number for registration will soon become mandatory when logging into the app from outside the secure corporate network.

User Contact Management

For information on how a user can manage the phone number linked to their account, see this article.

Parameter Description
Allow to add phone number Server users can link a mobile phone number to their account for authentication and to allow others to find them by number in contacts.
Allow to edit phone number Server users can modify their linked phone number.
Allow to delete phone number Server users can remove their linked phone number.

Corporate Data Visibility in Unauthorized Zone

Parameter Description
Show the corporate server address on the login screen Users going through registration will not see the corporate server address and will only see the name specified in the server properties on
RTS
/
ETS
. Available from server and client version 3.49.
Prefill the credentials found by email Populate the login and domain fields if a match was found via simplified authentication mapping.

Registration Methods

Select the registration and authentication method for the corporate server: E-mail, NTLM (Active Directory), or OpenID. Only one method can be selected.

Method Description Availability
E-mail

Authentication is performed using a code sent to the linked email.

If not all users have accounts in LDAP, enable E-mail authentication. This allows some corporate accounts to be created on the server via LDAP synchronization, while others are added manually in the admin panel. All users will authenticate using the email code.

Authentication via email code is available for accounts added from AD as well as those created manually in the admin panel.
NTLM

Authentication is performed using AD login and password. User data is synchronized with AD. Synchronization runs on long and short cycles.


Full synchronization runs every 3 hours, as well as on the schedule specified in the Full synchronization schedule (cron format) field. During synchronization, new users are added, the address book is updated based on AD changes, and users excluded from the sync filter are disabled.


Short synchronization runs every 10 minutes. It checks the status of the AD account (disabled account, lockout, expired password, expired account, password change).


If needed, synchronization can be manually triggered using the Sync button.

Authentication via AD login and password is only available for accounts added from AD if NTLM is selected.
OpenID Authentication mechanism using an OpenID account. For example, users without an AD account or corporate email can log in using a special token. Authentication via OpenID is only available for accounts added from OpenID if OpenID is selected.

How to Check the Current Authentication Method?

The current corporate server authentication method can be checked not only in the admin panel but also by entering the following URL in a browser: https://the_server_FQDN/api/v2/ad_integration/register_methods. The response will indicate: "register_methods":["current_authentication_type"]}.

Can Users Be Synced from AD and Authenticated via OpenID?

Mixed user synchronization and authentication is possible, but requires the system customization and consultation with architects as part of the deployment project.

How Do I Connect Multiple Active Directory Domains?

CTS
ETS
eCTS

The connection method depends on how the directory is structured in your organization.

How the domains are structured How to connect
Root domain with subdomains Configure corporate server synchronization with the root domain directory — subdomains will be included in the selection along with it. Authentication type — NTLM.
Several separate domains, even connected by trust relationships Via an intermediate directory. The organization deploys an AD LDS collector domain, which gathers users from the connected domains into a single database; synchronization is performed from it. Authentication type — Email: the collector only gathers user information and does not support managing them, so sign-in with domain credentials is not available.


Via Keycloak. The organization connects its domains to Keycloak in a federation. Authentication type — OpenID: the sign-in scenario is configured on the Keycloak side and can be of any complexity; the app displays its forms.

The connection scheme is chosen during the implementation phase together with an eXpress specialist: it affects both the user sign-in method and how terminated employees are deactivated.

Synchronization Settings

Parameter Description
Synchronization sources Select the corporate system from which user accounts are synchronized.
Full synchronization schedule Configure the synchronization time in Cron format.
The minimum interval is 1 hour (0 * * * *). This is an additional synchronization schedule, apart from the standard one (every 3 hours).
Sync This button forces synchronization of users with the connected corporate system.
⚠️ Synchronization with OpenID does not create user accounts. For accounts to appear, the user must authenticate on
CTS
/
eCTS
.