Lightweight Directory Access Protocol, the standard way to bind to and query directories like Active Directory. In Azure it is provided by Entra Domain Services.
Also called Lightweight Directory Access Protocol.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-3052V0-17.25AZ-900SC-900SC-300AZ-802MD-102ALZ
Each book explains LDAP in context, with comparison tables and the common traps.
Terms in this definition
- Standard deployment type
A Foundry deployment type billed per token that keeps processing of prompts and responses inside the Azure geography of the resource, meeting data residency needs at lower volumes.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
- Microsoft Entra Domain Services
Domain hosted and managed in Azure that provides Kerberos, NTLM and LDAP. Its contents come from Entra ID, so no connection to on-premises is required.
Related terms
- AD LDS
Directory service role offering applications an LDAP store on its own, with no Group Policy or domains.
- Distinguished name
The complete LDAP path that pins down exactly one object in Active Directory, for example CN=Server1,OU=Servers,DC=contoso,DC=com.
- ECMA connector
Lets Entra push user provisioning out to on-premises apps backed by LDAP or SQL; HR-driven inbound provisioning is a different thing.
- Insecure Protocols workbook
A workbook in Microsoft Sentinel that detects the use of weak protocols, for example SMBv1, NTLMv1, SSL/TLSv1 and unsigned LDAP binds.
- LDAP signing
Signing of LDAP traffic on connections not already wrapped in TLS, so nobody can alter it in transit. Freshly deployed Windows Server 2025 domain controllers insist on it by default.
- LDAPS
Secure LDAP: directory lookups wrapped in TLS, which normally listen on port 636. Support for TLS 1.3 arrived with Windows Server 2025.
- OU
Organisational unit, a container within LDAP or Active Directory; CSRs include it as a field too.
- SASL sealing
An LDAP setting where the SASL bind both signs and encrypts directory traffic, keeping it confidential even when TLS isn't used.