The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →LDAP (Lightweight Directory Access Protocol) is a standard way for a client to communicate with a directory service—for example, to search for an entry or request a change. LDAP is the protocol, not the directory database or a complete directory-service product.
LDAP is a protocol, not a directory service
Think of LDAP as an agreed language a client uses to ask a directory server for information or request an update. The directory service stores and manages the information; LDAP defines operations for interacting with it. The analogy has limits: LDAP does not prescribe every vendor’s directory architecture or administrative choices.
RFC 4511 describes LDAP as providing access to distributed directory services that follow X.500 data and service models. Microsoft likewise notes that LDAP cannot create directories or specify how a directory service operates. In practical terms, an application can use LDAP to communicate with a compatible directory, but LDAP itself is not the directory.
How a directory stores information
Entries, attributes, and values
A directory is organized into entries. Each entry has attributes, and each attribute has a type and one or more values. For example, an entry might have a common-name attribute (cn) and an email attribute (mail).
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Used Book in Good Condition
Schema and object classes
A directory’s schema defines the meaning of attribute types and the rules for using them. An entry’s objectClass attribute identifies the classes that determine which attributes are required or allowed. The exact schema and tree structure depend on the directory deployment, so examples should not be treated as universal templates.
What are an RDN and a DN?
An entry is identified by a distinguished name (DN), which combines its relative distinguished name (RDN) with the names of its ancestors. The RDN identifies the entry relative to its parent; the DN identifies it within the directory. RFC 4514’s abstract states: “The X.500 Directory uses distinguished names (DNs) as primary keys to entries in the directory.” The RFC was edited by Kurt Zeilenga and published in June 2006.
Rank #2
- Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
- ABIS BOOK
- Packt Publishing
OpenLDAP’s example DN is uid=babs,ou=People,dc=example,dc=com. Here, uid=babs is the RDN; the full comma-separated string is the DN. The string representation of DNs is standardized in RFC 4514.
How an LDAP search works
A search specifies four main things: where to start, how much of the tree to search, what condition entries must meet, and which attributes to return.
Rank #3
- Base: the starting entry, identified by its DN.
- Scope: whether the search applies at the base entry, its immediate children, or the subtree below it.
- Filter: the condition used to select entries. LDAP filter syntax is standardized in RFC 4515.
- Requested attributes: the information the client wants returned for matching entries.
For example, an equality filter can be written as (mail=babs@example.com). This is an illustration of filter syntax, not a claim that a particular live directory contains a matching entry. OpenLDAP’s guide illustrates searching the subtree at and below dc=example,dc=com for Barbara Jensen and requesting the matching entry’s email address.
The server evaluates the search and returns matching entries subject to access controls and other restrictions. A query’s filter alone does not guarantee that the client can see every matching entry or attribute.
Rank #4
LDAP does more than search
LDAP also defines operations to add, delete, modify, and rename entries. Search is a common use, but a client can use the protocol for directory updates as well. Whether a particular client may perform an operation depends on the directory server’s configuration and permissions.
Authentication and security depend on the server
LDAP defines authentication methods and security mechanisms, and clients authenticate through bind operations. The LDAP standard also specifies LDAP over TCP. That does not make one port, encryption mode, authentication method, or bind configuration universal: supported options and deployment procedures vary by server and organization.
Best Value
- Used Book in Good Condition
When connecting an application, check the documentation for the specific directory server and follow the organization’s security policy. Confirm which authentication and transport protections are supported, how access controls apply, and which credentials the application is permitted to use.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What to check when choosing or integrating a directory service
LDAP is a protocol, not a product selection. For a directory implementation or application integration, assess the factors that affect compatibility and operation:
Quick Recap
- Schema and feature compatibility with the attributes and operations the application needs.
- Supported authentication methods and TLS/SASL capabilities.
- Access-control model and the permissions required by clients.
- Replication and availability requirements.
- Integration with the applications in use and the available administration tools.
- Support lifecycle and the operational expertise needed to maintain the service.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

