OptionalagentIP address of the AD connector agent used to validate that authentication requests originate from the corporate network for Kerberos authentication (managed by the AD Connector agent).
OptionalagentWhen enabled, allows direct username/password authentication through the AD connector agent instead of WS-Federation protocol (managed by the AD Connector agent).
OptionalagentVersion identifier of the installed AD connector agent software (managed by the AD Connector agent).
Optionalbrute_Enables Auth0's brute force protection to prevent credential stuffing attacks. When enabled, blocks suspicious login attempts from specific IP addresses after repeated failures.
OptionalcertEnables client SSL certificate authentication for the AD connector, requiring HTTPS on the sign-in endpoint
OptionalcertsArray of X.509 certificates in PEM format used for validating SAML signatures from the AD identity provider (managed by the AD Connector agent).
Optionaldisable_When enabled, disables caching of AD connector authentication results to ensure real-time validation against the directory
Optionaldisable_When enabled, hides the 'Forgot Password' link on login pages to prevent users from initiating self-service password resets
Optionaldomain_List of domain names that can be used with identifier-first authentication flow to route users to this AD connection; each domain must be a valid DNS name up to 256 characters
Optionalicon_https url of the icon to be shown
OptionalipsArray of IP address ranges in CIDR notation used to determine if authentication requests originate from the corporate network for Kerberos or certificate authentication.
OptionalkerberosEnables Windows Integrated Authentication (Kerberos) for seamless SSO when users authenticate from within the corporate network IP ranges
Optionalnon_An array of user fields that should not be stored in the Auth0 database (https://auth0.com/docs/security/data-security/denylist)
Optionalset_OptionalsignThe sign-in endpoint type for the AD-LDAP connector agent (managed by the AD Connector agent).
Optionaltenant_Primary AD domain hint used for HRD and discovery.
OptionalthumbprintsArray of certificate SHA-1 thumbprints for validating signatures. Managed by Auth0 when using the AD Connector agent.
Optionalupstream_
Options for the 'ad' connection