Identity

Claro + LDAP / Active Directory

Keep your Claro user list current by syncing directly from the directory you already maintain.

Overview

Claro can sync users from LDAP or Active Directory, so the employee list used for phishing simulations and training assignments reflects your actual organization instead of a manually maintained CSV. This is particularly useful for on-premise deployments where an identity provider-based approach like SAML or SCIM may not be in place, but a directory service already exists.

As employees join, change departments, or leave, a directory sync keeps Claro's records aligned with the source of truth your IT team already manages, reducing the risk of simulations being sent to former employees or training being missed for new hires. The directory you already keep current does the work, so nobody has to reconcile a separate list by hand.

Directory attributes carry over during sync, not just names and email addresses. Fields such as department can be mapped into Claro, which means the organizational structure you already maintain becomes the basis for targeting simulations and assigning training. That keeps campaigns aligned to real teams and makes reporting by department accurate without extra setup.

Because this path relies on a directory service rather than a cloud identity provider, it fits Claro's on-premise-first deployments cleanly, keeping user data within your own environment. Sync runs on a schedule so changes are picked up regularly without manual intervention, and how removals are handled follows your configured sync behavior, with historical training and simulation data retained per your data retention settings. For organizations weighing their options, the rule of thumb is simple: use LDAP or Active Directory sync when an on-premise directory is your authoritative record of employees, and choose SCIM or SAML when a cloud identity provider already governs your user lifecycle and sign-in. Claro supports both models so you can align the integration with the identity architecture you already run rather than changing it to fit the platform.

How it works

  • Configure directory connection details

    Provide Claro with the LDAP or Active Directory connection details and credentials needed to read your directory securely.

  • Map directory attributes

    Define how directory fields, such as email, name, and department, map to Claro user fields so records carry the right structure.

  • Scope the sync

    Choose which parts of the directory to bring into Claro, so only the intended users and organizational units are provisioned.

  • Sync runs on your schedule

    Claro periodically syncs the directory so new hires, department changes, and departures are reflected in the platform without manual updates.

  • Records stay aligned

    Ongoing syncs keep Claro consistent with your directory, with removals handled per your sync behavior and historical data retained per your retention settings.

Frequently asked questions

  • It is most commonly used for on-premise deployments where a directory service is already in place, but it can be used wherever LDAP or Active Directory is your source of truth for users.

Not sure how Claro fits your stack?

Tell us what you run today and we will walk you through the integration path.

Request a demo