Skip to main content

LDAP / Active Directory

LoginLink can authenticate users directly against an on-premises LDAP or Active Directory server — useful for enterprise tenants that want employees signing in with their existing corporate credentials without standing up a separate SAML/OIDC identity provider.

How it works​

When a tenant enables LDAP sign-in, a dedicated /console/ldap-login (or /ldap-login for end-user-facing tenants) screen accepts a username and password, which LoginLink forwards as an LDAP bind request to your configured directory server. A successful bind signs the user in; LoginLink never stores the LDAP password itself.

Configuring an LDAP connection​

Console → Connectors → LDAP requires:

  • Server host/port and whether to use LDAPS (TLS).
  • Bind DN template or a service account for directory search, depending on your directory's structure.
  • Base DN to search under.
  • Attribute mapping — which LDAP attributes map to email, display name, and any custom fields you want carried over.

A connection test is available directly on the configuration page before enabling it for real users.

User provisioning​

The first successful LDAP bind for a given directory account creates the corresponding LoginLink user (just-in-time provisioning), matching the same pattern used by social/OAuth connectors. If you'd prefer to provision accounts ahead of time from your directory instead of on first sign-in, see SCIM Provisioning — Azure AD/Entra environments in particular often already have a SCIM connector configured for exactly this.