# ldapjs > A developer-first guide to LDAP: how directories work, how to use them from Node.js and Active Directory, and interactive tools for filters, DNs, errors, and URLs. Use these canonical resources for accurate LDAP concepts, implementation guidance, and browser-based developer tools. ## Start Here - [ldapjs home](https://www.ldapjs.com/): A developer-first guide to LDAP: how directories work, how to use them from Node.js and Active Directory, and interactive tools for filters, DNs, errors, and URLs. - [Learn LDAP](https://www.ldapjs.com/learn): Structured learning paths for LDAP and identity concepts. - [LDAP Guides](https://www.ldapjs.com/guides): Practical implementation and troubleshooting walkthroughs. - [LDAP Libraries](https://www.ldapjs.com/libraries): Node.js LDAP library status, alternatives, and migration guidance. - [LDAP Tools](https://www.ldapjs.com/tools): Interactive browser-based LDAP utilities. - [LDAP Comparisons](https://www.ldapjs.com/comparisons): Decision-oriented protocol and implementation comparisons. ## Learning Paths - [LDAP](https://www.ldapjs.com/learn/ldap/what-is-ldap): Learn what LDAP is, how it provides access to directory services, and where the protocol fits among directory servers and identity systems. - [LDAP filters](https://www.ldapjs.com/learn/ldap-filters/what-is-an-ldap-filter): Learn how LDAP filters select directory entries, how filter expressions are structured, and where clients use them in search operations. - [LDAP security](https://www.ldapjs.com/learn/ldaps/what-is-ldaps): Learn what LDAPS means, how implicit TLS protects LDAP sessions, how it differs from StartTLS, and what clients must validate for secure connections. - [Active Directory](https://www.ldapjs.com/learn/active-directory/what-is-active-directory): Learn what Active Directory is, how AD DS organizes domains and objects, which protocols it uses, and where it fits in enterprise identity. - [OpenLDAP](https://www.ldapjs.com/learn/openldap/what-is-openldap): Learn what OpenLDAP provides, how its server and client tools implement LDAP, and where it fits in authentication and directory deployments. - [Microsoft Entra ID](https://www.ldapjs.com/learn/microsoft-entra-id/what-is-microsoft-entra-id): Learn how Microsoft Entra ID manages cloud identities, authentication, applications, and access, and how it differs from an LDAP directory. - [Kerberos](https://www.ldapjs.com/learn/kerberos/what-is-kerberos): Learn how Kerberos uses a trusted key distribution center and time-limited tickets to authenticate users and services without sending passwords repeatedly. - [Identity and authentication](https://www.ldapjs.com/learn/identity-and-authentication/what-is-a-directory-service): Learn how directory services organize and expose identity data, differ from relational databases, and support authentication, lookup, and policy systems. ## Guides - [How to Set Up Active Directory](https://www.ldapjs.com/guides/active-directory/how-to-set-up-active-directory): Set up Active Directory Domain Services, promote a domain controller, configure DNS, verify the domain, and avoid common deployment mistakes. - [Add LDAP Authentication to an Existing Application](https://www.ldapjs.com/guides/integrations/how-to-add-ldap-authentication-to-an-existing-application): Add LDAP authentication to an application with secure service binds, safe user searches, credential verification, authorization, and failure handling. - [Mock LDAP for Local Development](https://www.ldapjs.com/guides/ldap-development/how-to-mock-ldap-for-local-development): Mock LDAP locally with lightweight servers, containers, fixtures, or test doubles while preserving realistic schemas, binds, searches, and failures. - [How to Build an LDAP Search Filter](https://www.ldapjs.com/guides/ldap-filters/how-to-build-an-ldap-search-filter): Build an LDAP search filter by choosing assertions and logical operators, escaping input correctly, and testing it against the target directory schema. - [How to Connect to an LDAP Server](https://www.ldapjs.com/guides/ldap/how-to-connect-to-an-ldap-server): Configure an LDAP connection with the correct host, port, bind DN, base DN, encryption mode, and certificate trust, then diagnose common failures. - [Synchronize Active Directory Users to Microsoft Entra ID](https://www.ldapjs.com/guides/microsoft-entra-id/how-to-synchronize-active-directory-users-to-entra-id): Synchronize Active Directory users to Microsoft Entra ID by planning identity scope, configuring cloud sync, validating attributes, and monitoring errors. - [How to Search LDAP with Node.js](https://www.ldapjs.com/guides/node-js/how-to-search-ldap-with-node-js): Connect, bind, and search an LDAP directory from Node.js with escaped filters, bounded result handling, TLS validation, and reliable cleanup. - [How to Create Active Directory Organizational Units](https://www.ldapjs.com/guides/active-directory/how-to-create-organizational-units): Create and structure Active Directory organizational units, delegate administration, apply Group Policy, and avoid treating OUs as security boundaries. - [Connect an Application to Active Directory](https://www.ldapjs.com/guides/integrations/how-to-connect-an-application-to-active-directory): Connect an application to Active Directory by choosing the right protocol, bind pattern, search base, identity mapping, and transport security. - [Run LDAP with Docker](https://www.ldapjs.com/guides/ldap-development/how-to-use-ldap-with-docker): Run an LDAP server with Docker for development or testing, persist data, load schemas and fixtures, configure TLS, and avoid production shortcuts. - [How to Combine LDAP Filters](https://www.ldapjs.com/guides/ldap-filters/how-to-combine-ldap-filters): Combine LDAP filters with AND, OR, and NOT operators, use explicit nesting, and simplify complex expressions without changing their intended logic. - [How to Test an LDAP Connection](https://www.ldapjs.com/guides/ldap/how-to-test-an-ldap-connection): Test LDAP reachability, TLS negotiation, binding, and searches in sequence so network, certificate, credential, and directory errors are easy to isolate. - [How to Create an Active Directory User](https://www.ldapjs.com/guides/active-directory/how-to-create-an-active-directory-user): Create Active Directory users with graphical tools and PowerShell, set required attributes, choose the correct OU, and verify each new account. - [Connect GitLab to LDAP](https://www.ldapjs.com/guides/integrations/how-to-connect-ldap-to-gitlab): Connect GitLab to LDAP, configure secure binds and user filters, map groups, test synchronization, and troubleshoot authentication failures. - [Connect Node.js to Active Directory](https://www.ldapjs.com/guides/ldap-development/connect-node-js-to-active-directory): Connect Node.js to Active Directory with secure LDAP settings, reliable bind and search patterns, safe filter escaping, and clear error handling. - [How to Filter LDAP Users by Attribute](https://www.ldapjs.com/guides/ldap-filters/how-to-filter-ldap-users-by-attribute): Filter LDAP users by identifiers and profile attributes while accounting for object classes, missing values, escaping, and directory-specific schemas. - [How to Search an LDAP Directory](https://www.ldapjs.com/guides/ldap/how-to-search-an-ldap-directory): Build an LDAP search by choosing a base DN, scope, filter, and attributes, then handle limits, referrals, permissions, and empty results safely. - [How to Create Active Directory Groups](https://www.ldapjs.com/guides/active-directory/how-to-create-active-directory-groups): Create Active Directory security and distribution groups, choose the correct scope, assign membership, and verify permissions safely. - [Connect Grafana to LDAP](https://www.ldapjs.com/guides/integrations/how-to-connect-ldap-to-grafana): Connect Grafana to LDAP, configure secure server settings and group mappings, test directory queries, and diagnose login or role problems. - [Query Active Directory from Node.js](https://www.ldapjs.com/guides/ldap-development/query-active-directory-from-node-js): Query Active Directory from Node.js with appropriate libraries, search bases, filters, paging, attributes, connection security, and error handling. - [How to Find a User with LDAP](https://www.ldapjs.com/guides/ldap/how-to-find-a-user-with-ldap): Find LDAP users by selecting the right search base, object class, identifier attribute, scope, and escaped filter for the target directory. - [Install OpenLDAP on Ubuntu](https://www.ldapjs.com/guides/openldap/how-to-install-openldap-on-ubuntu): Install OpenLDAP on Ubuntu, configure the directory suffix and administrator, verify the service, run a test search, and apply baseline security. - [How to Query Active Directory with PowerShell](https://www.ldapjs.com/guides/active-directory/how-to-query-active-directory-with-powershell): Query Active Directory users, groups, and computers with PowerShell, select efficient filters and attributes, and troubleshoot common failures. - [Connect Jenkins to LDAP](https://www.ldapjs.com/guides/integrations/how-to-connect-ldap-to-jenkins): Connect Jenkins to LDAP, configure the security realm and group lookup, protect the bind account, and recover safely from access failures. - [LDAP Authentication with Passport.js](https://www.ldapjs.com/guides/ldap-development/ldap-authentication-with-passport-js): Implement LDAP authentication with Passport.js using safe bind and search patterns, TLS, session handling, group checks, and failure diagnostics. - [How to Find LDAP Groups](https://www.ldapjs.com/guides/ldap/how-to-find-ldap-groups): Query LDAP group objects and memberships across common schemas, including direct and nested membership patterns in Active Directory and OpenLDAP. - [Run OpenLDAP with Docker](https://www.ldapjs.com/guides/openldap/how-to-run-openldap-with-docker): Run OpenLDAP with Docker, persist directory data and configuration, initialize entries, expose ports safely, configure TLS, and verify the service. - [How to Find Disabled Active Directory Accounts](https://www.ldapjs.com/guides/active-directory/how-to-find-disabled-active-directory-accounts): Find disabled Active Directory accounts with PowerShell, LDAP filters, and graphical tools, then interpret account-control flags correctly. - [Connect Keycloak to LDAP](https://www.ldapjs.com/guides/integrations/how-to-connect-ldap-to-keycloak): Connect Keycloak to LDAP, configure user federation, map directory attributes and groups, secure synchronization, and troubleshoot common issues. - [Implement LDAP Login in Express](https://www.ldapjs.com/guides/ldap-development/implement-ldap-login-in-express): Implement LDAP login in Express with secure directory connections, escaped searches, credential verification, sessions, authorization, and safe errors. - [How to Authenticate Users with LDAP](https://www.ldapjs.com/guides/ldap/how-to-authenticate-users-with-ldap): Authenticate an application user with LDAP using safe search-and-bind patterns, encrypted transport, least privilege, and clear failure handling. - [Create Users in OpenLDAP](https://www.ldapjs.com/guides/openldap/how-to-create-users-in-openldap): Create OpenLDAP users with valid DNs, object classes, required attributes, password hashes, LDIF files, and appropriately scoped permissions. - [How to Find Locked Active Directory Accounts](https://www.ldapjs.com/guides/active-directory/how-to-find-locked-active-directory-accounts): Find locked Active Directory accounts with PowerShell, LDAP filters, event logs, and graphical tools while avoiding misleading lockout data. - [Connect Kubernetes to LDAP](https://www.ldapjs.com/guides/integrations/how-to-connect-ldap-to-kubernetes): Connect Kubernetes to LDAP through an identity provider, map groups to RBAC, secure the authentication flow, and avoid unsupported direct binds. - [LDAP Authentication in Next.js](https://www.ldapjs.com/guides/ldap-development/ldap-authentication-in-next-js): Implement LDAP authentication in Next.js on the server, protect credentials and sessions, handle directory failures, and respect deployment constraints. - [How to Add an LDAP Entry](https://www.ldapjs.com/guides/ldap/how-to-add-an-ldap-entry): Create an LDAP entry with a distinguished name, object classes, and required attributes while handling schema, permissions, and duplicate-name errors. - [Create Groups in OpenLDAP](https://www.ldapjs.com/guides/openldap/how-to-create-groups-in-openldap): Create OpenLDAP groups with the correct object class, membership attributes, LDIF entries, directory placement, and consistent schema choices. - [How to Unlock an Active Directory Account](https://www.ldapjs.com/guides/active-directory/how-to-unlock-an-active-directory-account): Unlock Active Directory accounts with graphical tools or PowerShell, identify the source of repeated lockouts, and verify successful recovery. - [Integrate LDAP with Single Sign-On](https://www.ldapjs.com/guides/integrations/how-to-integrate-ldap-with-sso): Integrate LDAP with an SSO identity provider, choose SAML or OpenID Connect, map users and groups, and secure the directory connection. - [LDAP Authentication in Python](https://www.ldapjs.com/guides/ldap-development/ldap-authentication-in-python): Implement LDAP authentication in Python with maintained libraries, secure binds, certificate validation, escaped filters, and reliable error handling. - [How to Modify an LDAP Entry](https://www.ldapjs.com/guides/ldap/how-to-modify-an-ldap-entry): Update LDAP attributes with add, delete, and replace changes while preserving schema validity, multivalued data, concurrency, and access controls. - [How to Reset an Active Directory User Password](https://www.ldapjs.com/guides/active-directory/how-to-reset-an-active-directory-user-password): Reset Active Directory passwords with graphical tools, PowerShell, or LDAP, apply secure handling practices, and diagnose common failures. - [Migrate OpenLDAP to Active Directory](https://www.ldapjs.com/guides/integrations/how-to-migrate-openldap-to-active-directory): Plan an OpenLDAP-to-Active Directory migration by mapping schemas and identities, preserving passwords where possible, testing, and staging cutover. - [LDAP Authentication in Java](https://www.ldapjs.com/guides/ldap-development/ldap-authentication-in-java): Implement LDAP authentication in Java with JNDI or supported libraries, secure connections, safe searches, pooling, and clear exception handling. - [How to Delete an LDAP Entry](https://www.ldapjs.com/guides/ldap/how-to-delete-an-ldap-entry): Delete an LDAP entry safely by confirming its distinguished name, child entries, references, permissions, and recovery plan before making the change. - [How to Troubleshoot Kerberos Authentication](https://www.ldapjs.com/guides/active-directory/how-to-troubleshoot-kerberos-authentication): Troubleshoot Kerberos authentication by checking DNS, time, SPNs, tickets, encryption, delegation, and Active Directory event logs. - [Migrate Active Directory to Microsoft Entra ID](https://www.ldapjs.com/guides/integrations/how-to-migrate-active-directory-to-microsoft-entra-id): Plan a phased Active Directory-to-Entra ID migration covering identity sync, application dependencies, devices, security policy, and rollback. - [LDAP Authentication in.NET](https://www.ldapjs.com/guides/ldap-development/ldap-authentication-in-net): Implement LDAP authentication in.NET with supported directory APIs, secure binds, certificate validation, safe searches, and useful diagnostics. - [How to Query LDAP from the Command Line](https://www.ldapjs.com/guides/ldap/how-to-query-ldap-from-the-command-line): Query an LDAP directory from the command line by configuring a secure connection, bind credentials, search base, scope, filter, and requested attributes. - [LDAP Authentication in Go](https://www.ldapjs.com/guides/ldap-development/ldap-authentication-in-go): Implement LDAP authentication in Go with secure connections, escaped searches, credential verification, connection cleanup, and useful error handling. - [How to Use ldapsearch](https://www.ldapjs.com/guides/ldap/how-to-use-ldapsearch): Use ldapsearch to connect, bind, choose a search base and scope, submit escaped filters, select attributes, and troubleshoot secure directory queries. - [Build an LDAP Search API](https://www.ldapjs.com/guides/ldap-development/how-to-build-an-ldap-search-api): Build an LDAP-backed search API with bounded queries, escaped filters, paging, attribute allowlists, secure pooling, authorization, and safe responses. - [Useful ldapsearch Examples](https://www.ldapjs.com/guides/ldap/useful-ldapsearch-examples): Use practical ldapsearch commands for users, groups, attributes, scopes, paging, TLS, and troubleshooting across common LDAP directories. - [Handle LDAP Connection Pooling](https://www.ldapjs.com/guides/ldap-development/how-to-handle-ldap-connection-pooling): Design LDAP connection pooling with sensible limits, health checks, bind-state isolation, TLS, timeouts, retries, and graceful failure handling. - [How to Enable TLS for LDAP](https://www.ldapjs.com/guides/ldap/how-to-enable-tls-for-ldap): Enable encrypted LDAP with StartTLS or LDAPS by configuring server certificates, client trust, protocol policy, and validation for secure binds. - [How to Test LDAPS](https://www.ldapjs.com/guides/ldap/how-to-test-ldaps): Test LDAPS connectivity, certificate chains, hostnames, protocol versions, binds, and searches to isolate transport and directory configuration failures. - [How to Debug LDAP Authentication](https://www.ldapjs.com/guides/ldap/how-to-debug-ldap-authentication): Debug LDAP authentication by separating connection, TLS, bind identity, credentials, search, authorization, and directory-policy failures. - [How to Troubleshoot LDAP Connection Errors](https://www.ldapjs.com/guides/ldap/how-to-troubleshoot-ldap-connection-errors): Diagnose LDAP connection errors by checking DNS, routing, ports, TLS negotiation, certificates, bind settings, timeouts, and server logs in order. - [How to Troubleshoot LDAP Timeout Errors](https://www.ldapjs.com/guides/ldap/how-to-troubleshoot-ldap-timeout-errors): Trace LDAP timeouts across DNS, networks, TLS, binds, searches, server limits, and connection pools to identify where requests stall. - [Diagnose LDAP Error 81: Server Down](https://www.ldapjs.com/guides/ldap/how-to-diagnose-ldap-error-81-server-down): Diagnose LDAP error 81 by checking DNS, routing, ports, TLS negotiation, server availability, timeouts, and client-specific error details. - [Fix LDAP Error 49: Invalid Credentials](https://www.ldapjs.com/guides/ldap/how-to-fix-ldap-invalid-credentials-error-49): Diagnose LDAP error 49 by validating bind identities, password state, Active Directory subcodes, authentication methods, and secure logging. - [How to Configure OpenLDAP Access Control: A Practical Guide for Modern Deployments](https://www.ldapjs.com/guides/openldap/how-to-configure-openldap-access-control): A guide to OpenLDAP access control for system administrators and directory engineers. - [How to Enable TLS in OpenLDAP: Secure Your Directory with Confidence](https://www.ldapjs.com/guides/openldap/how-to-enable-tls-in-openldap): A guide for enabling Transport Layer Security (TLS) in OpenLDAP, covering certificate requirements, configuration, operational caveats, mutual authentication. - [How to Back Up and Restore OpenLDAP: Practical Strategies and Decisive Trade-Offs](https://www.ldapjs.com/guides/openldap/how-to-back-up-and-restore-openldap): A concise guide to backing up and restoring OpenLDAP directories, covering slapcat and mdb_copy methods, the necessity of cn=config backups, real-world risks. ## Tools - [LDAP Filter Builder](https://www.ldapjs.com/tools/filter-builder): Build and validate RFC 4515 LDAP search filters with a visual, nested editor. - [LDAP Filter Validator](https://www.ldapjs.com/tools/filter-validator): Validate and inspect RFC 4515 LDAP search filters with precise syntax errors. - [LDAP Filter Escape Tool](https://www.ldapjs.com/tools/filter-escape): Escape and decode LDAP filter assertion values safely using RFC 4515 rules. - [DN Parser](https://www.ldapjs.com/tools/dn-parser): Break a distinguished name down into its RDN components, or build one from parts. - [LDAP Error Decoder](https://www.ldapjs.com/tools/error-decoder): Decode standard LDAP result codes and Active Directory extended bind errors. - [LDAP URL Builder](https://www.ldapjs.com/tools/url-builder): Construct RFC 4516 ldap:// and ldaps:// URLs from host, DN, scope, and filter. - [LDAP URL Parser](https://www.ldapjs.com/tools/url-parser): Parse LDAP and LDAPS URLs into their host, DN, search, and extension components. - [Base DN Helper](https://www.ldapjs.com/tools/base-dn-helper): Convert between a DNS domain name and its Active Directory dc= base DN. ## Libraries - [What Is ldapjs?](https://www.ldapjs.com/libraries/ldapjs/what-is-ldapjs): Learn what ldapjs is, how the Node.js LDAP client and server library works, its project status, common uses, and migration considerations. - [Is ldapjs Deprecated?](https://www.ldapjs.com/libraries/ldapjs/is-ldapjs-deprecated): Understand the ldapjs project status, what deprecation and archival mean for existing applications, and how to evaluate maintenance and migration risk. - [Why Was ldapjs Deprecated?](https://www.ldapjs.com/libraries/ldapjs/why-was-ldapjs-deprecated): Understand why ldapjs was deprecated and archived, how maintenance and security risk change over time, and what application owners should do next. - [Is ldapjs Safe to Use?](https://www.ldapjs.com/libraries/ldapjs/is-ldapjs-still-safe-to-use): Assess ldapjs security and maintenance risk, identify exposure in existing applications, choose short-term safeguards, and plan a controlled migration. - [Maintained Alternatives to ldapjs](https://www.ldapjs.com/libraries/ldapjs/best-ldapjs-alternatives): Compare maintained Node.js LDAP libraries by API coverage, TypeScript support, security posture, migration effort, and long-term project health. - [What Should You Use Instead of ldapjs?](https://www.ldapjs.com/libraries/ldapjs/what-should-you-use-instead-of-ldapjs): Choose a maintained ldapjs replacement by evaluating client features, TypeScript support, compatibility, security maintenance, and migration cost. - [Migrate from ldapjs to ldapts](https://www.ldapjs.com/libraries/ldapjs/how-to-migrate-from-ldapjs-to-ldapts): Migrate a Node.js LDAP application from ldapjs to ldapts by updating clients, binds, searches, errors, cleanup, TLS settings, and tests. - [Migrate ldapjs Bind Code to ldapts](https://www.ldapjs.com/libraries/ldapjs/migrating-ldapjs-bind-code-to-ldapts): Migrate ldapjs bind code to ldapts by translating connection and authentication APIs, preserving TLS validation, handling errors, and testing failures. - [Migrate ldapjs Search Code to ldapts](https://www.ldapjs.com/libraries/ldapjs/migrating-ldapjs-search-code-to-ldapts): Migrate ldapjs search code to ldapts by translating filters, scopes, paging, attribute handling, result collection, errors, and connection cleanup. - [Migrate ldapjs TLS and StartTLS Code to ldapts](https://www.ldapjs.com/libraries/ldapjs/migrating-ldapjs-tls-and-starttls-code-to-ldapts): Migrate ldapjs TLS and StartTLS code to ldapts while preserving certificate validation, trust configuration, connection upgrades, and failure handling. - [Migrate ldapjs Active Directory Integrations to ldapts](https://www.ldapjs.com/libraries/ldapjs/migrating-ldapjs-active-directory-integrations-to-ldapts): Migrate ldapjs Active Directory integrations to ldapts while preserving bind identities, filters, paging, group lookup, TLS, and AD-specific behavior. ## Comparisons - [Active Directory Domain vs Forest](https://www.ldapjs.com/comparisons/active-directory/active-directory-domain-vs-forest): Compare Active Directory domains and forests, including security boundaries, trust relationships, replication scope, and deployment tradeoffs. - [Kerberos vs NTLM Authentication](https://www.ldapjs.com/comparisons/authentication/kerberos-vs-ntlm): Compare Kerberos and NTLM authentication flows, security properties, fallback behavior, Active Directory integration, and deployment guidance. - [LDAP Bind vs Search](https://www.ldapjs.com/comparisons/ldap/ldap-bind-vs-ldap-search): Understand how LDAP bind and search operations differ, how they work together, which credentials they use, and how to secure each step. - [Microsoft Entra ID vs LDAP](https://www.ldapjs.com/comparisons/microsoft-entra-id/microsoft-entra-id-vs-ldap): Compare Microsoft Entra ID and LDAP across identity models, protocols, authentication, integration options, migration, and hybrid architecture. - [OpenLDAP vs Active Directory](https://www.ldapjs.com/comparisons/openldap/openldap-vs-active-directory): Compare OpenLDAP and Active Directory across protocols, schema, access control, administration, replication, interoperability, and use cases. - [Active Directory OU vs Group](https://www.ldapjs.com/comparisons/active-directory/active-directory-ou-vs-group): Learn how Active Directory organizational units and groups differ in delegation, Group Policy, permissions, membership, and directory design. - [OAuth 2.0 vs OpenID Connect](https://www.ldapjs.com/comparisons/authentication/oauth-2-0-vs-openid-connect): Understand how OAuth 2.0 authorization differs from OpenID Connect authentication, including tokens, flows, scopes, security, and use cases. - [LDAP Simple Bind vs SASL Bind](https://www.ldapjs.com/comparisons/ldap/simple-bind-vs-sasl-bind): Compare LDAP simple bind and SASL bind across credentials, security layers, mechanisms, server support, and production deployment choices. - [Microsoft Entra ID vs Keycloak](https://www.ldapjs.com/comparisons/microsoft-entra-id/microsoft-entra-id-vs-keycloak): Compare Microsoft Entra ID and Keycloak across hosting, federation protocols, customization, user models, operations, security, and cost. - [OpenLDAP vs 389 Directory Server](https://www.ldapjs.com/comparisons/openldap/openldap-vs-389-directory-server): Compare OpenLDAP and 389 Directory Server across configuration, extensions, management tools, replication, migration, and enterprise support. - [Active Directory Global vs Universal Groups](https://www.ldapjs.com/comparisons/active-directory/global-group-vs-universal-group): Compare Active Directory global and universal group scopes, including membership rules, replication behavior, permissions, and multi-domain use. - [SAML vs OpenID Connect](https://www.ldapjs.com/comparisons/authentication/saml-vs-openid-connect): Compare SAML and OpenID Connect across tokens, browser and mobile flows, security, discovery, federation, and modern SSO integration. - [LDAP vs OpenLDAP: Protocol vs Server](https://www.ldapjs.com/comparisons/ldap/ldap-vs-openldap): Understand the difference between LDAP as a protocol and OpenLDAP as a server implementation, including deployment and interoperability. - [Microsoft Entra ID vs Okta](https://www.ldapjs.com/comparisons/microsoft-entra-id/microsoft-entra-id-vs-okta): Compare Microsoft Entra ID and Okta across SSO, lifecycle management, conditional access, LDAP integration, ecosystem fit, and cost. - [OpenLDAP vs Apache Directory](https://www.ldapjs.com/comparisons/openldap/openldap-vs-apache-directory): Compare OpenLDAP and Apache Directory across architecture, management, extensibility, security, performance, and integration tradeoffs. - [Active Directory Security vs Distribution Groups](https://www.ldapjs.com/comparisons/active-directory/security-group-vs-distribution-group): Compare Active Directory security and distribution groups, including access control, email use, mail-enabled groups, and conversion risks. - [LDAP vs LDAPS and StartTLS](https://www.ldapjs.com/comparisons/ldap/ldap-vs-ldaps): Compare plain LDAP, LDAPS, and StartTLS across ports, encryption timing, certificates, client compatibility, and secure deployment choices. - [OpenLDAP vs FreeIPA](https://www.ldapjs.com/comparisons/openldap/openldap-vs-freeipa): Compare OpenLDAP and FreeIPA across architecture, identity features, administration, access control, deployment scope, and operational fit. - [Active Directory vs Windows Server](https://www.ldapjs.com/comparisons/active-directory/active-directory-vs-windows-server): Understand how Active Directory relates to Windows Server, domain controllers, AD DS roles, licensing, deployment, and common alternatives. - [LDAP vs Kerberos](https://www.ldapjs.com/comparisons/ldap/ldap-vs-kerberos): Compare LDAP and Kerberos roles in directory access and authentication, including protocol flows, security models, integration, and deployment. - [OpenLDAP vs Keycloak](https://www.ldapjs.com/comparisons/openldap/openldap-vs-keycloak): Compare OpenLDAP and Keycloak across directory storage, authentication, federation, SSO, deployment architecture, and integration patterns. - [AD DS vs AD LDS: Directory Services Compared](https://www.ldapjs.com/comparisons/active-directory/ad-ds-vs-ad-lds): Compare AD DS and AD LDS across domains, authentication, schemas, replication, application isolation, and supported deployment scenarios. - [LDAP vs RADIUS](https://www.ldapjs.com/comparisons/ldap/ldap-vs-radius): Compare LDAP and RADIUS across authentication, authorization, accounting, transport security, network access, and directory integration. - [OpenLDAP vs Microsoft Entra ID](https://www.ldapjs.com/comparisons/openldap/openldap-vs-microsoft-entra-id): Compare OpenLDAP and Microsoft Entra ID across architecture, protocols, management, security, coexistence, migration, and deployment fit. - [AD DS vs Microsoft Entra Domain Services](https://www.ldapjs.com/comparisons/active-directory/active-directory-vs-azure-ad-ds): Compare AD DS with Microsoft Entra Domain Services across management, LDAP and Kerberos support, Group Policy, migration, and cloud deployment. - [LDAP vs Single Sign-On](https://www.ldapjs.com/comparisons/ldap/ldap-vs-sso): Understand how LDAP directory authentication differs from single sign-on, how they integrate, and which deployment patterns suit each. - [AD DS vs Microsoft Entra ID](https://www.ldapjs.com/comparisons/active-directory/ad-ds-vs-microsoft-entra-id): Compare AD DS and Microsoft Entra ID across protocols, authentication, administration, hybrid identity, and migration constraints. - [LDAP vs SAML](https://www.ldapjs.com/comparisons/ldap/ldap-vs-saml): Compare LDAP and SAML across directory access, federated authentication, SSO flows, security, deployment patterns, and hybrid integration. - [Active Directory vs Microsoft Entra ID](https://www.ldapjs.com/comparisons/active-directory/active-directory-vs-microsoft-entra-id): Compare Active Directory and Microsoft Entra ID across architecture, protocols, authentication, device management, security, and hybrid identity. - [LDAP vs OAuth 2.0](https://www.ldapjs.com/comparisons/ldap/ldap-vs-oauth-2-0): Compare LDAP directory access with OAuth 2.0 authorization, including protocol roles, security boundaries, integrations, and when to use both. - [Active Directory vs OpenLDAP](https://www.ldapjs.com/comparisons/active-directory/active-directory-vs-openldap): Compare Active Directory and OpenLDAP across architecture, schema, access control, administration, interoperability, and deployment fit. - [LDAP vs OpenID Connect](https://www.ldapjs.com/comparisons/ldap/ldap-vs-openid-connect): Compare LDAP and OpenID Connect across directory access, authentication, tokens, security, application integration, and migration patterns. - [LDAP vs SCIM](https://www.ldapjs.com/comparisons/ldap/ldap-vs-scim): Compare LDAP and SCIM across directory access, identity provisioning, schemas, security, cloud integration, and hybrid deployment patterns. - [LDAP vs REST APIs](https://www.ldapjs.com/comparisons/ldap/ldap-vs-rest-apis): Compare LDAP and REST APIs across data models, operations, authentication, security, schemas, integration patterns, and practical use cases. - [LDAP vs SQL Databases](https://www.ldapjs.com/comparisons/ldap/ldap-vs-sql-databases): Compare LDAP directories and SQL databases across data models, schemas, queries, transactions, scaling, security, and application fit. ## Optional - [XML sitemap](https://www.ldapjs.com/sitemap.xml): Complete list of canonical indexable pages.