Skip to main content
AD Academy
Protocols and Authentication
Intermediate14 minLast updated: Topic 1 of 2

LDAP — the Directory Access Protocol

How applications read and search information in AD.

Not read

What you will learn here

  • What LDAP is and why it exists
  • What a directory search looks like
  • How applications use it with AD

(Lightweight Directory Access Protocol) is the protocol through which clients and servers communicate with the Directory Service. It allows searching for users, checking group membership and updating object attributes.

Query example

השורש הוא DC=company,DC=local. תחתיו OU=Sales ו־OU=IT, ובתוכן אובייקטי משתמש CN=Cohen ו־CN=Levi. שם מלא לדוגמה: CN=Cohen,OU=Sales,DC=company,DC=local. השאילתה נסרקת מלמעלה למטה לפי Base DN, Scope ו־Filter.

Get-ADUser -Filter "Name -like 'Cohen*'" -Properties MemberOf
powershell
Architecture and Theory — Under the Hood

is the protocol used to query . Port 389 (Clear/Signed) and 636 (encrypted LDAPS). Every query consists of a Base DN, Scope, and Filter.

(&(objectClass=user)(objectCategory=person)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
   ^ AND        ^ only users                    ^ not disabled
text
  • = equals, ~= similar, >= greater/equal, * exists.
  • & = AND, | = OR, ! = NOT.
  • Scope: Base / OneLevel / Subtree.
Practical Configuration (PowerShell / GUI)
# Direct LDAP query
Get-ADUser -LDAPFilter "(&(objectClass=user)(department=IT))" -Properties mail

# Graphical tool for testing
ldp.exe        # Connect, Bind, Browse
adsiedit.msc   # Editing raw attributes
powershell
Troubleshooting
  • Error 49 — Invalid credentials (LdapErr sub-code 52e = password, 775 = account locked).
  • Error 32 — The object does not exist (incorrect Base DN).
  • Size Limit Exceeded — returns up to 1000 records; Paging must be used.

Check yourself

What is LDAP used for?

Was this page helpful?