AD Group Manager Web - Online Manual

System Requirements

Before installing AD Group Manager Web, verify that your environment meets the following requirements.

Server requirements

Component Requirement
Operating system Windows Server 2016, 2019, 2022, or later
Web server IIS (Internet Information Services) with the Web Server role enabled
Runtime ASP.NET Core 10 Hosting Bundle
Database None required — the application uses an embedded SQLite database (adgm.db)
Disk space Approximately 50 MB for the application files, plus space for log files and the SQLite database
Memory Minimal — the application has a small footprint and runs within an IIS Application Pool

The server must be joined to the Active Directory domain (or have network access to a domain controller).

Active Directory requirements

Component Requirement
Domain functional level Windows Server 2003 or higher
Schema extensions None — AD Group Manager Web uses only standard AD attributes (managedBy, msExchCoManagedByLink, member, standard user/group properties)
Permissions The application pool identity (or service account for Windows Authentication) needs Read access to user, group, computer, and contact objects, and Write Members permission on the groups that managers will manage

If you use the default Basic authentication mode, each manager authenticates with their own AD credentials, and their own permissions determine what they can do. A dedicated service account is only required when using Windows Authentication.

Client requirements

Component Requirement
Browser Any modern browser: Chrome, Edge, Firefox, Safari
Plugins None — the application is a standard web application with no client-side plugins or ActiveX controls
Operating system Any — managers can access the portal from Windows, macOS, Linux, or mobile devices
Network The client must be able to reach the IIS server over HTTP or HTTPS

For Windows Authentication (Kerberos SSO), the client machine should be joined to the same AD domain (or a trusted domain) and the browser must support Negotiate/Kerberos authentication.

Network requirements

The IIS server needs the following network connectivity:

  • LDAP (TCP 389) or LDAPS (TCP 636) to at least one domain controller in the target domain.
  • Global Catalog (TCP 3268) if your environment uses universal groups across multiple domains.
  • SMTP (TCP 25, 465, or 587) to your mail server, if you want to use email notifications or scheduled reports.
  • HTTP/HTTPS from client machines to the IIS server.

No outbound internet connectivity is required. The application runs entirely on-premises and does not phone home or contact external services.

Next steps



Use of this site constitutes acceptance of our Privacy Policy and EULA. Copyright © Albus Bit SIA