Browse learn

LDAP Search Scope: Base, One Level, and Subtree

Learn how base, one-level, and subtree search scopes control which LDAP entries a query examines and how scope affects correctness and performance.

On this page

Why Search Scope Matters in LDAP

Search scope is a fundamental concept in LDAP that directly determines which directory entries are considered in a query. For developers and identity engineers, getting search scope right is critical for performance, correctness, and security. An incorrect scope can result in missing data, excessive results, or failed directory operations—common stumbling blocks in real-world LDAP integrations, application authentication flows, and directory troubleshooting.

LDAP search operations consist of a base DN (starting point), a scope, a filter, and a set of requested attributes. Among these, scope defines the "radius" of the search, specifying whether the query targets just a single entry, its immediate children, or the entire branch beneath the starting point. Selecting the appropriate scope is essential for directory efficiency, accuracy of results, and minimizing system risk.

Understanding the Three LDAP Search Scopes

LDAP defines three standardized search scopes, each with a precise meaning in the protocol (RFC 4511) and fixed registry values:

Base (baseObject) Scope

  • Definition: The search is restricted to the entry named by the base DN only. No subordinate entries are included.
  • Protocol Value: 0 (baseObject)
  • Intended Use: Directly retrieve or check for the existence of a single, known directory entry.

One Level (singleLevel) Scope

  • Definition: The search examines only the immediate children of the base DN—entries whose parent is the base DN. The base DN itself is not included, nor are any entries below the first level.
  • Protocol Value: 1 (singleLevel)
  • Intended Use: Enumerate all entries within a container or organizational unit but not the container itself or deeper descendants.

Subtree (wholeSubtree) Scope

  • Definition: The search includes the base DN as well as all entries at any depth beneath it, traversing through all branches.
  • Protocol Value: 2 (wholeSubtree)
  • Intended Use: Search deeply within a subtree for all objects matching given criteria, starting from the base DN and including the base itself.

Visualizing Search Coverage—LDAP Tree Diagrams

Visualizing an LDAP directory as a tree enhances understanding of search scopes:

text
          (A)
         /   \
      (B)     (C)
     /   \      \
   (D)  (E)    (F)
  • Base Scope (e.g., base DN = B): A search with base scope and base DN "B" targets only (B).
  • One Level Scope (base DN = B): Targets (D) and (E)—the direct children. (B) itself and deeper descendants like (none in this case) are not included.
  • Subtree Scope (base DN = B): Includes (B), (D), and (E). All descendants, no matter how deep, and the base DN itself are part of the result.

The scope you select determines the set of candidate entries considered for filtering and return.

When to Use Each Scope: Practical Use Cases and Implications

  • Base Scope: Use when you need to retrieve attributes for a single, known entry or to check if it exists. Ideal for binding/authenticating a user with a known DN or reading directory object metadata.

  • One Level Scope: Use to enumerate all immediate members of a group or container. Examples include listing all users in an organizational unit or all computer objects in a particular container. Avoids returning the container object itself or objects in nested containers.

  • Subtree Scope: Use when you must search across all levels under a branch—such as finding all users in an organization, including those in nested OUs or groups. Necessary for recursive search needs, but beware of the breadth: this can encompass thousands or millions of entries in large directories.

Choosing the wrong scope—such as a one-level search when a subtree search is needed—will result in incomplete results, often with no matching entries found. Conversely, using a subtree scope when only immediate children are needed leads to unnecessary load and potentially excessive access.

Performance, Security, and Troubleshooting Considerations

Performance

Scope selection directly impacts the size of the result set and server workload:

  • Base queries are lightweight and efficient, targeting a single object.
  • One Level queries scale linearly with the number of immediate children, making them optimal for enumerations within a container.
  • Subtree queries can be extremely expensive, especially near the root of large directories. Recursive traversal through large hierarchies may impact server response times, consume significant resources, and even risk denial-of-service conditions if unbounded.

Security

Broad scopes, particularly subtree searches, increase the risk of over-exposing directory data (intentionally or through misconfiguration). Limiting the scope reduces the risk of returning unintended objects to unauthorized callers and constrains potential data exfiltration or misuse.

Troubleshooting Common Errors

  • Zero Results: The most common cause is mismatched base DN and scope—one-level scope at a leaf node will always return zero results. Similarly, using base instead of subtree can miss all relevant entries except for the specified DN.
  • Unexpected Results: Overly broad (subtree) searches may return more data than intended, which can break consuming applications or exceed security constraints.
  • Performance Issues: Subtree searches may exhaust server or network resources, especially if filter selectivity is poor.

Best practice: Always select the narrowest scope that satisfies the query requirements, both for efficient operation and security.

Frequently Asked Questions and Misconceptions

Does one-level scope include the base DN?

No. One-level (singleLevel) scope only considers the immediate children of the base DN. The base DN itself is never included in results for this scope, as explicitly defined in RFC 4511.

Does subtree scope include the base DN?

Yes. Subtree (wholeSubtree) scope includes the base DN as well as all its descendants, regardless of depth. This is crucial for queries where the filter might match the base object itself.

What about the subordinateSubtree scope?

SubordinateSubtree, proposed in a non-standard draft, behaves like subtree but excludes the base DN from results. It is not part of the LDAP core standard or widely supported.

Are Active Directory and OpenLDAP compliant with these definitions?

Yes. Both follow RFC specifications for scope. However, UI defaults and terminology may differ across tools—always check both the effective base DN and scope setting in your client library or management tool.

Is using subtree scope the safest or best default?

No, subtree scope should not be the default. It is the broadest, most resource-intensive scope and increases the risk of excessive data exposure or system load. Use it only when required, and always pair with precise filters.

Further Reading and Authoritative References

  • RFC 4511: Lightweight Directory Access Protocol (LDAP) — Primary definition for search operation scopes
  • IANA LDAP Parameters Registry — Official mapping of search scope values
  • draft-sermersheim-ldap-subordinate-scope — Non-standard subordinateSubtree scope definition
  • RFC 2251: LDAP v3 (superseded by RFC 4511)

Sources