Passportal Help

Configuring AD Sync in a Multi-Domain Controller Environment


  • 64-bit
  • Windows Server 2008 R2 and newer
  • Windows Server Core is not supported at this time
  • Supports TLS 1.2 or higher. More information on which versions of windows server support which TLS protocols can be found in this article.
  • If not current or installed, the agent will also deploy C++ 2013 and .NET 4.5 or newer during the install
  • Outbound FTP Endpoint: port 21 should be enabled (Optional)


If you are NOT configuring a Multi-Domain Controller Environment and you require clarification on the Windows Agent Toggles, see Active Directory Integration.

Multi-Domain Controller - Primary Domain Controller Setup Instructions

  1. Edit the client to enable Windows Sync, and download the Windows Agent.
  2. If you require clarification on the Windows Agent toggles, see Active Directory Integration.

  3. Once the agent has been downloaded, transfer the installation to the Primary Domain Controller and launch the Setup.exe.
  4. In the next step please ensure you put the local IP Address of the Primary Domain Controller. Leaving this as the loop back IP will cause errors later on.

  5. The agent has now been installed, and a restart of the server will be required for the Two-Way sync to take place. Clicking “OK” will NOT restart the server. You can however restart now, or at the end of the article.
  6. The Passportal Windows Agent application will launch, and we will be able to continue with the installation. On the first screen authenticate with your Passportal login details.
  7. The account used for authentication needs to have the Permission called “Setup AD Sync” in order to authenticate.

  8. You are prompted to create a Domain Administrator account which is used to run the Passportal and PassportalUpdater services that get created. A username you could use could be PassportalSync and a Random password.
  9. This Administrator account does not yet exist on your Active Directory Environment, so you will be prompted to create the account.
  10. When the account has finished being created you will have a success message saying “Passportal Windows Services were restarted successfully. You may close this window."
  11. The Windows Agent has finished installing. Please go to Passportal to verify the "PassportalSync" account exists.
  12. If you did not restart the Primary Domain Controller after installing the Windows Agent, please do so now so that Two-Way Sync will start to work.

Multi-Domain Controller - Secondary Domain Controller Setup Instructions

  1. Transfer the installation for the Windows Agent to the Secondary Domain Controllers.
  2. Start the installation following the same steps above. When you get prompted for type of installation stop.
  3. Enter the IP Address of the Primary Domain Controller
  4. Now that the listener has been installed, please restart the Domain Controller to ensure that Two-Way Sync works.