Help center support eXpress
We've collected answers to popular questions to make eXpress easy and convenient to use. Didn't find the answer to your question? Contact our support team.
- Welcome to eXpress
- eXpress Support
- Introducing eXpress & Glossary
- Installation & Updates & Requirements
- Registering & Logging In
- User Profile
- Chats, Channels & Threads
- Contacts
- Tags & Tabs
- Files
- Calls & Conferences
- Push Notifications & Counters
- Fixing Background Work on Mobile
- Bots & SmartApps
- Diagnostics & Logs & Cache
- Admin Panel
- Admin Panel: General Information
- Users
- Chats
- Open Chats
- Calls
- Conferences
- Profile Change Request List
- Logout List
- Administrators
- Servers
- Bots
- Internal Bots
- External Clients Users
- UI Alerts
- Containers
- Audit
- Stickers
- Call Backgrounds
- Catalog
- Statistics
- Role Model
- Role Model Rules
- User Groups
- Call Reports
- Call Recordings
- Transcribings
- SMS Statuses
- Administrators Authentication
- Audit Settings
- Global Chat
- Global Bots
- Links to Chats/Calls
- Push Service
- File Service
- User Session
- Registration Settings
- Active Directory
- E-mail: self-registration
- OpenID
- Personal Data Visibility
- E-mail: sending emails
- Getting Started Instruction
- Blocked Users
- VoEx
- Server
- Support Info
- Network Security
- Registration Instruction
- SmartApps
- Mobile Menu Configuration
- Activations
- SMS
- Adapters
- Masks
- Security
- CAPTCHA
- Reserved Phone Numbers
- Suggests
- Kerberos Settings & Kerberos Suggests
- Jira Support Portal
- Technical Support for Admins
- Database Modifications Policy
- eXpress Documentation
- Privacy Policy
Registration Settings
- CTS-Only Registration
- User Contact Management
- Corporate Data Visibility in Unauthorized Zone
- Registration Methods
- Synchronization Settings
Click Save to apply changes.
CTS-Only Registration 
| Parameter | Description |
|---|---|
| Allow registration without phone number | A global server parameter that determines whether a user can log in without a phone number: via corporate email or corporate server address. |
| Display a warning that registration will be forbidden soon | If enabled, client app users will receive a notification that registration using a phone number will soon be mandatory: Add a phone number. The administrator has prohibited login without a telephone number. Add a telephone number to continue using the app.
⚠️ If you, as an administrator, plan to prohibit logging in without a phone number, be sure to enable the warning so users have time to add phone numbers and avoid login errors. Otherwise, uncheck this box.
Additionally, in builds of the branded ETS app, some login method buttons may be disabled. |
| Allow skipping two-factor authentication within the contour | If enabled, users with a phone number can skip SMS code verification when connecting from within the Corporate Data Transfer Network (CDTN) contour if they previously logged in without a number but were later detected with one. |
| Display warning about the need to add number to log in outside of a contour | If the parameter is enabled, client app users will receive a notification that using a phone number for registration will soon become mandatory when logging into the app from outside the secure corporate network. |
User Contact Management 
For information on how a user can manage the phone number linked to their account, see this article.
| Parameter | Description |
|---|---|
| Allow to add phone number | Server users can link a mobile phone number to their account for authentication and to allow others to find them by number in contacts. |
| Allow to edit phone number | Server users can modify their linked phone number. |
| Allow to delete phone number | Server users can remove their linked phone number. |
Corporate Data Visibility in Unauthorized Zone 
| Parameter | Description |
|---|---|
| Show the corporate server address on the login screen | Users going through registration will not see the corporate server address and will only see the name specified in the server properties on RTS /ETS . Available from server and client version 3.49. |
| Prefill the credentials found by email | Populate the login and domain fields if a match was found via simplified authentication mapping. |
Registration Methods 
Select the registration and authentication method for the corporate server: E-mail, NTLM (Active Directory), or OpenID. Only one method can be selected.
| Method | Description | Availability |
|---|---|---|
Authentication is performed using a code sent to the linked email. If not all users have accounts in LDAP, enable E-mail authentication. This allows some corporate accounts to be created on the server via LDAP synchronization, while others are added manually in the admin panel. All users will authenticate using the email code. |
Authentication via email code is available for accounts added from AD as well as those created manually in the admin panel. | |
| NTLM | Authentication is performed using AD login and password. User data is synchronized with AD. Synchronization runs on long and short cycles. Full synchronization runs every 3 hours, as well as on the schedule specified in the Full synchronization schedule (cron format) field. During synchronization, new users are added, the address book is updated based on AD changes, and users excluded from the sync filter are disabled. Short synchronization runs every 10 minutes. It checks the status of the AD account (disabled account, lockout, expired password, expired account, password change). If needed, synchronization can be manually triggered using the Sync button. |
Authentication via AD login and password is only available for accounts added from AD if NTLM is selected. |
| OpenID | Authentication mechanism using an OpenID account. For example, users without an AD account or corporate email can log in using a special token. | Authentication via OpenID is only available for accounts added from OpenID if OpenID is selected. |
How to Check the Current Authentication Method?
The current corporate server authentication method can be checked not only in the admin panel but also by entering the following URL in a browser: https://the_server_FQDN/api/v2/ad_integration/register_methods. The response will indicate: "register_methods":["current_authentication_type"]}.
Can Users Be Synced from AD and Authenticated via OpenID?
Mixed user synchronization and authentication is possible, but requires the system customization and consultation with architects as part of the deployment project.
How Do I Connect Multiple Active Directory Domains? 
The connection method depends on how the directory is structured in your organization.
| How the domains are structured | How to connect |
|---|---|
| Root domain with subdomains | Configure corporate server synchronization with the root domain directory — subdomains will be included in the selection along with it. Authentication type — NTLM. |
| Several separate domains, even connected by trust relationships | Via an intermediate directory. The organization deploys an AD LDS collector domain, which gathers users from the connected domains into a single database; synchronization is performed from it. Authentication type — Email: the collector only gathers user information and does not support managing them, so sign-in with domain credentials is not available.
Via Keycloak. The organization connects its domains to Keycloak in a federation. Authentication type — OpenID: the sign-in scenario is configured on the Keycloak side and can be of any complexity; the app displays its forms. |
Synchronization Settings 
| Parameter | Description |
|---|---|
| Synchronization sources | Select the corporate system from which user accounts are synchronized. |
| Full synchronization schedule | Configure the synchronization time in .
The minimum interval is 1 hour ( 0 * * * *). This is an additional synchronization schedule, apart from the standard one (every 3 hours). |
| Sync | This button forces synchronization of users with the connected corporate system.
⚠️ Synchronization with OpenID does not create user accounts. For accounts to appear, the user must authenticate on
CTS /eCTS . |