Authenticate Windows AD users on linux using LDAP

This guide explain how set a Linux server to permit authentication of LDAP user of a Windows Active Directory domain.

If you want join in domain you can use this guide.

Install all necessary packages

First of all install this two package and all dependecies

Create config file

Create (or modify) /etc/sssd.conf file as the follow

Then restart the sssd service after the modification

At the end provide this command to enable authentication through LDAP

Fine tuning

If you want that some group or user became sudoers create a file /etc/sudoers.d/domainPolicy with this content

If you want restrict ssh access to only some groups, modify the file /etc/ssh/sshd_config at this part

