Overview
Trustifi provides a built-in integration with LDAP (Lightweight Directory Access Protocol) as part of its Email Infrastructure integrations. This integration establishes a secure connection to your directory using administrator credentials, allowing Trustifi to synchronize the groups, distribution lists, and aliases defined in your directory service.
By keeping Trustifi aware of your organizational groups and email aliases, the LDAP integration improves the accuracy of policy targeting, rule assignment, and threat protection across your users.
Integration Capabilities
Once connected, the LDAP integration allows Trustifi to:
• Establish a secure connection to your mail server using directory administrator credentials
• Retrieve and display your directory groups and aliases
• Synchronize groups and aliases so they can be used when assigning policies, rules, and reviewers
Knowing your groups and aliases allows Trustifi to better protect your users by applying protection and policies consistently across your organizational structure.
Requirements
Before connecting, make sure the following are in place:
• Administrator credentials (username and password) with permission to read your directory.
• The Base DN (Distinguished Name) that defines the directory tree Trustifi should search.
• The Host address of your LDAP server and the Port it listens on (the default secure LDAPS port is 636).
• Firewall allowlisting — if your directory server is behind a firewall, allow inbound access from the following Trustifi IP addresses so the connection can be established:
– 3.221.25.19
– 35.172.145.174
– 44.209.231.3
– 34.192.117.166
Note: For a secure LDAPS connection, keep the “Allow secure connection only” option enabled and use port 636.
Accessing the LDAP Integration Window
The LDAP integration settings are located in the Trustifi admin portal under the “Integrations” page, within the “Email Infrastructure” group of integrations.
To open the LDAP integration window:
1. Navigate to the “Integrations” page in the Trustifi admin portal (Outbound Integrations).
2. Locate the “LDAP” integration tile under “Email Infrastructure.”
3. Click the LDAP tile to open the connection pop-up.

Opening the Connection Credentials Section
The “LDAP Integration” pop-up displays:
• A short description of how the integration works
• The current connection status, which initially displays “Disconnected”
• A “Groups/Aliases” section used to review and synchronize directory data after connecting
Click “Connect” to open the connection credentials section.

Entering Connection Details and Connecting
In the “Connect to LDAP” window, enter the details required to establish communication between Trustifi and your directory server.
To complete the connection:
1. Enter “Username” — the administrator account Trustifi will use to authenticate to your directory.
2. Enter “Password” — the password for the administrator account.
3. Enter “Base DN” — the base Distinguished Name that defines the directory tree Trustifi should search (for example, dc=example,dc=com).
4. Enter “Host” — the address of your LDAP server.
5. Enter “Port” — the port your LDAP server listens on. The default is 636 for a secure LDAPS connection.
6. Leave “Allow secure connection only” enabled to require an encrypted (LDAPS) connection.
7. Click “Connect” to establish the connection.

Note: If your directory server is protected by a firewall, confirm that the Trustifi IP addresses listed in the pop-up have been allowlisted before connecting.
Syncing Groups and Aliases
After the connection is established, the “Groups/Aliases” section of the LDAP Integration pop-up becomes available. Use it to review the directory data Trustifi has retrieved and keep it up to date:
• Click “Show Groups” to display the groups discovered in your directory.
• Click “Show Aliases” to display the email aliases discovered in your directory.
• Click “Sync” to synchronize the latest groups and aliases from your directory into Trustifi.
Run a Sync whenever groups or aliases change in your directory so that Trustifi reflects your current organizational structure.

Connection Persistence
This connection process only needs to be completed once. After the connection is successfully established:
• The connection status updates to “Connected”
• Trustifi maintains the secure connection to your directory
• Groups and aliases can be refreshed at any time using the “Sync” option
Notes
The Username, Password, Base DN, Host, and Port values must match your directory server configuration. Administrator credentials should be stored securely. For a secure connection, keep “Allow secure connection only” enabled and use port 636.
If your directory server is behind a firewall, the Trustifi IP addresses listed in the connection window must be allowlisted for the connection to succeed. After connecting, use the “Sync” option to keep your groups and aliases current.