{"id":148,"date":"2026-03-31T13:39:33","date_gmt":"2026-03-31T12:39:33","guid":{"rendered":"https:\/\/overlaps.co.uk\/docs\/?page_id=148"},"modified":"2026-03-31T13:49:16","modified_gmt":"2026-03-31T12:49:16","slug":"active-directory","status":"publish","type":"page","link":"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/configuration\/settings\/active-directory\/","title":{"rendered":"Active Directory"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\" id=\"active-directory-structure\">Active Directory Structure<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"active-directory-structure-update-frequency\">Active Directory Structure Update Frequency<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Change this to modify how often OVERLAPS performs a full scan of Active Directory for changes to its structure. Changes it looks for include: new Organisational Units (OUs), removed OUs, and moved or renamed OUs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finding the correct values for this will depend on many things including the overall size of your domain, and how frequently it changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note that this only covers the full scan and refresh of the AD structure. In addition to this, OVERLAPS runs a smaller scan for specific changes every 30 minutes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By default this is set to \u201cEvery day (during the night only)\u201d.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"automatically-scan-on-service-start\">Automatically Scan On Service Start<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Check this box to have OVERLAPS automatically carry out a full Active Directory structure scan whenever the service reloads. This is not usually needed but can be used in combination with the Update Frequency to more accurately control when a scan takes place.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"schedule-scan-now\">Schedule Scan Now<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Check this box to request an Active Directory structure scan at the next available opportunity (usually within a few minutes).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"active-directory-groups-refresh\">Active Directory Groups Refresh<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"group-refresh-frequency\">Group Refresh Frequency<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">To decrease overhead on the login process, OVERLAPS periodically scans any groups that have been added for new users or users that have been removed. Set this value to control how often this happens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">**Note that this is not required for new group members logging in the first time, but is more important for preventing users who have been removed from a group from logging in. **<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"queue-group-refresh-operations\">Queue Group Refresh Operations<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If checked, group refresh triggers are added to a queue and processed sequentially. Otherwise the operations are handled in a multithreaded manner.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"active-directory-domains\">Active Directory Domains<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Here you will see a list of all domains that OVERLAPS has detected in your forest, and any forests with which you have a trust relationship. Each domain can be enabled or disabled for use or access within OVERLAPS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Note that the current root domain cannot be disabled.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"active-directory-credentials\">Active Directory Credentials<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">By default, the OVERLAPS server\u2019s LOCAL SYSTEM account is used to query Active Directory. However, in environments where this is not practical, you can provide the credentials of an alternate Service Account here. OVERLAPS will then use this account when retrieving any information from Active Directory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">**Note that these credentials are stored encrypted in the OVERLAPS database. **<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"directory-connection-priority\">Directory Connection Priority<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">In order to provide the maximum the level of support for all possible Active Directory configurations, OVERLAPS supports all three principal means of querying it:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Directory Searchers<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Lightweight Directory Access Protocol (LDAP)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security Principals<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By default, OVERLAPS will prefer the Directory Searchers protocol. However, if you are having domain connectivity issues then you can try the others for User, Group and Computer operations as best suit your environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Generally speaking, these should be left as the defaults unless you are experiencing problems when adding users or getting the members of groups. If you have any doubts, please contact our Support Team for assistance (<a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/getting-support\/\">Getting Support<\/a>).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"permissions-snapshot-settings\">Permissions Snapshot Settings<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Permissions snapshots are used to capture the state of your container permissions prior to making any changes so that the permissions can be restored if something goes wrong.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"snapshot-container-names\">Snapshot Container Names<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If checked, along with the permissions, the snapshot will also record the new names of any renamed containers.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"fully-revert-container-names\">Fully Revert Container Names<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If the above has been checked as well, when restoring a snapshot it will fully replace all container names with those from the snapshot. If the snapshot does not contain a new name for a container, but that container has subsequently been renamed, then it will revert it back to the default. Leaving this unchecked means that this latter situation will retain the new name.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"scheduled-snapshots\">Scheduled Snapshots<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If checked, a snapshot of your permissions is automatically capture every night.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"remove-automatic-snapshots-once-they-are-old-than-this-many-days\">Remove automatic snapshots once they are old than this many days<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Specify how long to keep automatic snapshots if they are enabled above.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"domain-controller-settings\">Domain Controller Settings<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"enable-domain-controller-caching\">Enable Domain Controller Caching<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">By default, OVERLAPS will scan your network for Domain Controllers and maintain an internal cache of them so it knows which ones to use. However, if you regularly have DCs going offline, this can lead to errors where OVERLAPS doesn\u2019t realise this and continues trying to query it. For this reason you can uncheck this box to make OVERLAPS stop using its cache and instead request a DC from AD for each request.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"domain-controller-health-check\">Domain Controller Health Check<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If enabled, OVERLAPS will periodically scan known Domain Controllers to make sure it can talk to them. If it can\u2019t then the DC is automatically blacklisted so that no further attempts are made to use it. This can be used as an alternative to disabling the Cache, but generally shouldn\u2019t be required.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"workarounds\">Workarounds<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This section is provided for current and future workarounds we may deploy to resolve issues in very specific domain environments. These options should generally only be modified if you encounter an issue that you feel may be related, or if you want to try out one of the experimental features. If you have any doubts, or would like to know more about a specific setting, please contact our Support Team (<a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/getting-support\/\">Getting Support<\/a>).<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"enable-multi-forest-authentication\">Enable Multi-Forest Authentication<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">For environments with more than one Active Directory forest and the need for users of different (trusted) forests to login to OVERLAPS. Enabling this feature will allow you to add groups and users from the other forests in your network.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"measure-query-performance\">Measure Query Performance<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If checked, most Active Directory operations will be measured to help locate bottlenecks. This information is only written to the log, and only if the Log Level is set to Debug. Note that enabling this feature may also impact the performance of your OVERLAPS server.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"allow-users-with-the-read-computer-information-permission-to-access-bitlocker-recovery-keys\">Allow users with the Read Computer Information permission to access Bitlocker Recovery Keys<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If checked, any users who have the \u201c<strong>Read Computer Information<\/strong>\u201d permission to a container will also be able to retrieve a computer\u2019s Bitlocker Recovery Key from the <strong>Computer Information<\/strong> window.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This requires additional Active Directory permissions for the OVERLAPS service. For more information on the permissions and how to set them, see <a href=\"https:\/\/overlaps.co.uk\/docs\/overlaps-documentation\/installation-and-configuration\/active-directory\/#bitlocker-recovery-key-permissions\">Installation and Configuration -&gt; Active Directory -&gt; Bitlocker Recovery Key Permissions<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"default-search-container\">Default Search Container<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Sets the default container that the Search window will be set to use when looking up computers (this container and any children beneath it). Note that users can override this setting when performing a search.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"181\" height=\"135\" src=\"https:\/\/overlaps.co.uk\/docs\/wp-content\/uploads\/2026\/03\/overlaps-ui-computer-search-select-container.jpg\" alt=\"The Container Limit Dropdown when Searching\" class=\"wp-image-149\"\/><figcaption class=\"wp-element-caption\">The Container Limit Dropdown when Searching<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Click <strong>Browse<\/strong> to show a tree for you to select a container from. Clicking <strong>Clear Setting<\/strong> removes this default.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Active Directory Structure Active Directory Structure Update Frequency Change this to modify how often OVERLAPS performs a full scan of Active Directory for changes to its structure. Changes it looks for include: new Organisational Units (OUs), removed OUs, and moved or renamed OUs. Finding the correct values for this will depend on many things including [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":68,"menu_order":100,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-148","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/comments?post=148"}],"version-history":[{"count":2,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/148\/revisions"}],"predecessor-version":[{"id":165,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/148\/revisions\/165"}],"up":[{"embeddable":true,"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/pages\/68"}],"wp:attachment":[{"href":"https:\/\/overlaps.co.uk\/docs\/wp-json\/wp\/v2\/media?parent=148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}