# Revision history [back]

### How to create users with keystone and Active Directory backend?

None of the examples and configuration guides for setting up Keystone with Active Directory work for the "Create User" operation. The failures, at least in my case (Win 2008 R2 AD Server), seem to stem from an incorrect combination of user_objectclass and the additional fields that keystone attempts to set when creating an LDAP user.

Settings:

user_tree_dn = cn=Users,dc=example,dc=com
user_objectclass = User
user_filter = (&(objectClass=person)(!(objectClass=computer)))
user_id_attribute = cn
user_name_attribute = sAMAccountName
user_mail_attribute = mail
user_enabled_attribute = userAccountControl