Zimbra + External AD : Automatically Create Mailboxes Zimbra with Lazy Mode Auto-Provisioning

Previously had been explain how to automatically create mailboxes in Zimbra with eager mode auto-provisioning. In this section, we can try to using lazy mode auto-provisioning. What difference between eager mode and lazy mode?

Difference of both is process automatically create mailboxes. If using eager mode, Zimbra will process create mailboxes every certain time (example every 5 minutes) and if using lazy mode, Zimbra will process create mailboxes every users of external AD login for first time.

You can choose which method suitable with your system. But on this section, i will explain how to using lazy mode auto-provisioning.

Create file with name autoprovision.zmp and put at folder /srv/

vi /srv/autoprovision.zmp

fill with the following line

md imanudin.net zimbraAutoProvAttrMap "cn=displayName"
md imanudin.net +zimbraAutoProvAttrMap "givenName=givenName"
md imanudin.net +zimbraAutoProvAttrMap "sn=sn"
md imanudin.net +zimbraAutoProvAttrMap "description=description"
md imanudin.net zimbraAutoProvAuthMech "LDAP"
md imanudin.net zimbraAutoProvLdapAdminBindDn "cn=Administrator,cn=users,dc=imanudin,dc=net"
md imanudin.net zimbraAutoProvLdapAdminBindPassword "VerySecret123"
md imanudin.net zimbraAutoProvLdapBindDn "cn=Administrator,cn=users,dc=imanudin,dc=net"
md imanudin.net zimbraAutoProvLdapSearchBase "dc=imanudin,dc=net"
md imanudin.net zimbraAutoProvLdapURL "ldap://"
md imanudin.net zimbraAutoProvMode "LAZY"
md imanudin.net zimbraAutoProvNotificationBody "Your account has been auto provisioned. Your email address is ${ACCOUNT_ADDRESS}."
md imanudin.net zimbraAutoProvNotificationFromAddress "admin@imanudin.net"
md imanudin.net zimbraAutoProvNotificationSubject "New account auto provisioned"


imanudin.net = domain name at Zimbra
LdapAdminBindDn/LdapBindDn = User Administrator at Active Directory/Samba4
LdapAdminBindPassword = Password user Administrator
LdapSearchBase = Attribute search AD/Samba4
LdapSearchFilter = Attribute search which has been filtered

LdapURL = IP Server external AD/Samba4

After above file has been created, run the following command as Zimbra

su - zimbra
zmprov < /srv/autoprovision.zmp

Please check process automatically create mailboxes at /opt/zimbra/log/mailbox.log. Please check also mailboxes which has been created at Zimbra Admin | Manage.

Good luck and hopefully useful 😀


  1. Hello

    It’s a pleasure to read this tutorial!!
    But i have a question, this method is available only for NE version of zimbra 8.6 or NE and OSE version?


  2. HI, thank you for your job.
    When i connect with a new account, Display Name is Administrator, name is fill with no value and firstname is empty.
    THis is my autoprovision.zmp:
    md myzimbradomainname zimbraAutoProvAttrMap “cn=displayName”
    md myzimbradomainname +zimbraAutoProvAttrMap “givenName=givenName”
    md myzimbradomainname +zimbraAutoProvAttrMap “sn=sn”
    md myzimbradomainname +zimbraAutoProvAttrMap “description=description”
    md myzimbradomainname zimbraAutoProvAuthMech “LDAP”
    md myzimbradomainname zimbraAutoProvLdapAdminBindDn “cn=Administrateur,cn=users,dc=myADdomainname”
    md myzimbradomainname zimbraAutoProvLdapAdminBindPassword “myADpassword”
    md myzimbradomainname zimbraAutoProvLdapBindDn “cn=administrateur,cn=users,dc=myADdomainname”
    md myzimbradomainname zimbraAutoProvLdapSearchBase “dc=myADdomainname”
    md myzimbradomainname zimbraAutoProvLdapURL “ldap://myIPAD:389”
    md myzimbradomainname zimbraAutoProvMode “LAZY”
    md myzimbradomainname zimbraAutoProvNotificationBody “Your account has been auto provisioned. Your email address is ${ACCOUNT_ADDRESS}.”
    md myzimbradomainname zimbraAutoProvNotificationFromAddress “admin@myzimbradomainname”
    md myzimbradomainname zimbraAutoProvNotificationSubject “New account auto provisioned”

  3. Hi Iman,
    I have configured the following regarding auto provisioning:

    [zimbra@m1 log]$ zmprov gd onlinebcits.com | grep AutoProv
    zimbraAutoProvBatchSize: 20
    zimbraAutoProvLdapAdminBindDn: cn=Directory Manager,dc=bcits,dc=co,dc=in
    zimbraAutoProvLdapAdminBindPassword: xxxxx
    zimbraAutoProvLdapBindDn: cn=Directory Manager,dc=bcits,dc=co,dc=in
    zimbraAutoProvLdapSearchBase: dc=bcits,dc=co,dc=in
    zimbraAutoProvLdapURL: ldap://
    zimbraAutoProvMode: LAZY
    zimbraAutoProvNotificationBody: Your account has been auto provisioned. Your email address is ${ACCOUNT_ADDRESS}.
    zimbraAutoProvNotificationFromAddress: admin@onlinebcits.com
    zimbraAutoProvNotificationSubject: New account auto provisioned

    The mailbox.log shows authentication error and invalid credentials. I am sure about the credentials, am I making any mistake in configuration? How to debug it?


Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.