Skip to main content

Configure an Application with LDAP

This guide explains how to configure an application with LDAP (Lightweight Directory Access Protocol) as an Identity Provider.

The configuration is completed in the application using the following steps:

  1. Details
  2. Connection
  3. Provisioning & access
  4. Attribute mapping
  5. Review

Prerequisites​

Before configuring LDAP in the application, make sure you have:

  • Access to the application with permission to configure Identity Providers.
  • Access to an LDAP directory server (e.g., Active Directory, OpenLDAP, FreeIPA, Google Secure LDAP).
  • The LDAP server Hostname / IP address and Port (e.g., 389 for LDAP, 636 for LDAPS).
  • A Bind DN (Service Account distinguished name) and Bind Password with read access to the directory.
  • The Base DN specifying the root search tree for users and groups.
  • The application's required user attributes, such as username, email, and display name.

For standard schema references, see RFC 4511 (LDAP Protocol) and RFC 4519 (LDAP Schema).


Step 1: Create LDAP Service Account & Connection Details​

First, prepare your LDAP server connection details and service account credentials. The service account (Bind DN) is used by the application to search and authenticate users in your LDAP directory.

1.1 Identify the Server Host and Port​

Determine your LDAP server's access protocol:

  • Standard LDAP (Unencrypted / StartTLS): Port 389
  • LDAP over SSL/TLS (LDAPS): Port 636

Example host URL:

ldap://ldap.example.com:389
ldaps://ldap.example.com:636

1.2 Create or Obtain a Bind DN Account​

Create a service account dedicated to the application in your LDAP directory with permission to search users and read directory attributes.

Example Bind DN syntax:

cn=ldap-service-account,ou=Services,dc=example,dc=com

Security Note: Use a restricted service account rather than an administrative DN (like cn=admin,dc=example,dc=com).

1.3 Determine Base DN and User Search Filters​

Identify the location in your directory tree where users reside:

  • Base DN: ou=Users,dc=example,dc=com
  • User Search Filter: (&(objectClass=person)(uid={0})) or (&(objectClass=user)(sAMAccountName={0}))


Step 2: Configure the Identity Provider in the Application​

Open the application's Identity Providers section and start a new configuration.

Select:

Identity Provider → LDAP

The configuration wizard opens with the following steps.


Step 2.1: Details​

The Details step contains the basic information about the Identity Provider.

Enter a name that makes the provider easy to identify.

Example:

FieldValue
NameCorporate LDAP
Provider typeLDAP
DescriptionPrimary LDAP Directory Service

If the application provides an Enabled option, enable the provider when you are ready to make it available to users.

Click Continue.


Step 2.2: Connection​

The Connection step contains the LDAP connection and bind settings.

Use the following LDAP connection values:

Application fieldStandard LDAP value / Example
Server Hostname / URLldaps://ldap.example.com or ldap.example.com
Port636 (for LDAPS) or 389 (for LDAP/StartTLS)
Connection ProtocolLDAPS or LDAP with StartTLS
Bind DNcn=ldap-service-account,ou=Services,dc=example,dc=com
Bind Password<service-account-password>
Base DNou=Users,dc=example,dc=com
User Search Filter(&(objectClass=person)(uid={0}))
User Object ClassinetOrgPerson / person / user

Encryption and Security Options​

  • LDAPS (SSL/TLS): Encrypts all traffic between the application and LDAP server from initial connection.
  • StartTLS: Upgrades an unencrypted connection on port 389 to TLS.
  • CA Certificate: If using a private or self-signed Certificate Authority, upload your CA certificate (ca.crt) so the application trusts the LDAP server.

Test Connection​

If your application provides a Test Connection or Test Bind button, click it to verify that:

  • Network connectivity is established.
  • The Bind DN and Password are accepted.
  • The Base DN exists and can be searched.

Click Continue.


Step 2.3: Provisioning & Access​

The Provisioning & access step controls which users can access the application via LDAP and how account lifecycle is managed.

Configure the options according to your application's access model:

SettingRecommended configuration
Provider statusEnabled
User accessRestrict by LDAP Group or Organizational Unit (OU)
Account creationEnable JIT (Just-in-Time) provisioning if supported
Existing user matchingMatch by mail or LDAP uid / sAMAccountName

Just-in-time user provisioning​

If the application supports Just-in-Time (JIT) provisioning, a user account is automatically created in the application during their first successful LDAP login.

If JIT provisioning is disabled, users must be pre-provisioned or synced via directory sync before they can log in.

The exact provisioning and access fields depend on the application. Use the access policy defined by your organization.

Click Continue.


Step 2.4: Attribute Mapping​

The Attribute mapping step maps LDAP attributes returned by your directory server to user attributes in the application.

A typical mapping for standard LDAP (inetOrgPerson) or Active Directory (user):

Application attributeStandard LDAP (inetOrgPerson)Active DirectoryPurpose
User ID / UsernameuidsAMAccountNameUnique username identifier
EmailmailmailUser email address
First namegivenNamegivenNameUser first name
Last namesnsnUser last name
Display namecn or displayNamedisplayNameUser display name
Unique IdentifierentryUUIDobjectGUIDStable binary/string identifier

uid / sAMAccountName → Username / User ID
mail → Email
givenName → First Name
sn → Last Name
displayName → Display Name

Important: Use a stable unique identifier​

While uid or mail are commonly used for sign-in, use entryUUID (OpenLDAP) or objectGUID (Active Directory) if your application supports an immutable external ID mapping, as usernames and emails may change over time.

Click Continue.


Step 2.5: Review​

The Review step displays all configuration values before the Identity Provider is saved.

Review the following:

Details​

  • Provider name is correct.
  • Provider type is LDAP.

Connection​

  • Server Hostname and Port are correct.
  • Encryption type (LDAPS / StartTLS) is configured properly.
  • Bind DN and Bind Password are verified.
  • Base DN and User Search Filters target the correct directory branch.

Provisioning & access​

  • The provider is enabled.
  • Access restrictions (by group or filter) are applied if necessary.
  • JIT provisioning is configured according to your organization's requirements.

Attribute mapping​

Verify that:

uid / sAMAccountName → Username / User ID
mail → Email
givenName → First Name
sn → Last Name
displayName → Display Name

Click Save, Create, or Finish, depending on the application's UI.


Step 3: Test LDAP Login​

After saving the configuration, test the authentication flow.

  1. Open the application's login page.
  2. Enter the LDAP user's credentials (e.g., uid or mail and LDAP password).
  3. The application binds to LDAP using the Bind DN, searches for the user, and attempts a simple bind with the user's Distinguished Name and password.
  4. Upon successful bind, LDAP retrieves the mapped attributes.
  5. The application validates the response and creates or signs in the user.
  6. Verify that the user's attributes were populated correctly.

Expected result​

After successful authentication:

  • The user is authenticated and granted access.
  • The expected email and profile information are populated from LDAP attributes.
  • The user receives the access permissions configured in the application.

Troubleshooting​

Invalid Credentials / LDAP Error 49

This error indicates authentication failed at the LDAP server during bind.

Check:

  • Service account (Bind DN) password accuracy.
  • Formatting of the Bind DN string.
  • User password accuracy during login test.

User Not Found / Search Failed

Check:

  • Base DN: Ensure it encompasses the OU where the user resides.
  • Search Filter: Verify the syntax matches your directory schema (e.g., uid={0} vs sAMAccountName={0}).

Connection Timed Out / Could Not Connect

Check:

  • Firewall rules between the application server and LDAP server.
  • Hostname resolution (DNS).
  • Port configuration (389 vs 636).

SSL/TLS Handshake Error

If using LDAPS or StartTLS:

  • Ensure the LDAP server's SSL certificate is valid and not expired.
  • Upload the LDAP server's root/intermediate CA certificate to the application's truststore if self-signed.

Email or name is missing​

Check the Attribute mapping configuration.

Make sure the application maps:

mail → Email
givenName → First Name
sn → Last Name
displayName → Display Name


Official References​