# Directory Access Settings

![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/48ddf0a7-308b-4fe9-b28a-e3ce1797eaa8/b5a60cff-cb4a-401e-af8a-248ba6eecf11/DIRECTORY%20ACCESS%20SETTINGS.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T120000Z&X-Amz-Expires=86400&X-Amz-Signature=c6219791d16c31713e2450c4444ac1347d83a0f0dd295641412535f204fd6894&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =x855")


:::info
Available to users with **Admin** privilege.

:::

**LearningSpace Enterprise** can be connected with directory servers that use the **Lightweight Directory Access Protocol** (**LDAP**) to provide you with an efficient way of user *authentication* and *group synchronization*.

Go to **Directory Access Settings** in the [**System**](/doc/dde83ad9-36b6-41e3-9492-33a2b77fbec7), and [**configure the directory server(s)**](/doc/how-to-add-directory-servers-to-an-ls-system-ZdOMLtjPVs) of your institution (more than one can be added).

Manage further settings such as user authentication methods and synchronization.


:::tip
Find step-by-step guides for **System manager**-related processes on our [**System - How to**](/doc/system-how-to-jhrHFUlkwJ) pages.

:::


Contact your organization’s network administrator or IT professional for the exact details of your directory server.

## LDAP authentication modes


1. Use full DN (selected by default):   
   This method requests a user's full distinguished name to authenticate them.  
   Specify the **Authentication ID**, **DN prefixes,** and **postfixes** to find users on your directory server.   
   Every user who is a match for the request can log in to LearningSpace with their credentials stored on the directory server.  
2. **Resolve samAccountName:**  
   This method requires a query user and the user’s samAccountName to authenticate them.  

   
   1. Provide the name and password of your directory server's query user.
   2. Provide a query base to define the level of the query in your directory tree.

Every user who is a match for the query can log in to LearningSpace with their credentials stored on the directory server.  
Applying a query user grants **LearningSpace Enterprise** permission to search the provided query base and authenticate any user with a match for their samAccountName.


:::info
See more under [**How to Configure LDAP Login**](/doc/how-to-configure-ldap-login-J9ujZBfTLG)**.**

:::

## LDAP synchronization

Switch on LDAP synchronization to easily import users from your directory server(s) into a user group in LearningSpace.

* Provide the **name and password of the** **query user** (dedicated for synchronization) of your directory server.
* At **Mapping**, enter the **attributes used on your directory server** that correspond with each personal detail field (e.g., *first name, email, UCID*, etc.).  
  LearningSpace needs these details in **Mapping** to match each data field with an attribute and execute a successful synchronization.

 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/48ddf0a7-308b-4fe9-b28a-e3ce1797eaa8/6339ba0c-1b67-4ef1-9b04-59d688ed2d5a/76908842.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T120000Z&X-Amz-Expires=86400&X-Amz-Signature=c9aafcc23c7fba9101bb1c8113770979839814f8e0f3990cc92b22864733d177&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =376x504")


:::warning
The [ACID field](https://kb.learningspace.elevatehealth.net/doc/how-to-edit-individual-user-settings-1fhIS2mxuP#h-new-additional-custom-id) *(Additional Custom ID)* **can not be synced** via [LDAP synchronization](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/how-to-configure-ldap-synchronization-zRqlnJJQfk). 

:::


:::info
See more under [**How to Configure LDAP Synchronization**](/doc/how-to-configure-ldap-synchronization-zRqlnJJQfk)**.**

:::


:::warning
***Note: ***If you encounter invalid users or missing or incorrect data on your directory server, the system will notify you. Meanwhile, users who are successfully authenticated can still be imported.

:::

 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/48ddf0a7-308b-4fe9-b28a-e3ce1797eaa8/e2f94ff2-6fef-414c-86a9-e09124ad193f/55804157.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T120000Z&X-Amz-Expires=86400&X-Amz-Signature=b61b76c5d6cc891a84ed72b5cb2fae0b417aa8e81fbcf949a73086852382e6b7&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)


:::info
To **import users** into a group, go to [**Users**](/doc/3d217778-949f-4de8-b954-1e9a4c46c533) and edit or create a new group. Select the LDAP tab in the [**Create / Edit Group**](/doc/be102934-c3d8-4193-8ce5-ecd76654078b) pop-up and follow the steps [**on this page**](/doc/how-to-import-and-synchronize-users-from-your-directory-server-mEZKzqIL7U).  
Users with **Admin or User Manager** privileges can import users.

:::



:::info
If your directory server is down, users authenticated by LDAP cannot log in with their email and password from the directory server.  
For a temporary solution, **LDAP authentication can be disabled** for each user one by one in their [**Edit User**](/doc/e1a91793-4430-455c-8391-2a1dab4c6a57) window, and **login details can be entered manually** in LearningSpace Enterprise.

:::


:::info
Related pages

* [How to Add Directory Servers to an LS system](/doc/how-to-add-directory-servers-to-an-ls-system-ZdOMLtjPVs)
* [How to Configure LDAP Login](/doc/how-to-configure-ldap-login-J9ujZBfTLG)
* [How to Configure LDAP Synchronization](/doc/how-to-configure-ldap-synchronization-zRqlnJJQfk)
* [How to Import and Synchronize Users from Your Directory Server](/doc/how-to-import-and-synchronize-users-from-your-directory-server-mEZKzqIL7U)
* [How to Set Up a User for LDAP Authentication](/doc/how-to-set-up-a-user-for-ldap-authentication-fz6NXMSyXu)

  

:::


:::tip
 Find step-by-step guides for **System manager**-related processes on our [System - How to](/doc/system-how-to-jhrHFUlkwJ) pages.

:::

---

**Documents**

- [User Guide](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/user-guide-WPv4VxhtWB)
- [FAQ](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/faq-YoxOQOjvnY)
- [Training Videos](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/training-videos-D2ycsEwqPt)
- [Module Introduction Videos](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/module-introduction-videos-I6OQ6H7SUT)
- [Release Notes](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/release-notes-BcFFMsc0RV)
- [Distance Learning with LearningSpace](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/distance-learning-with-learningspace-eAfwW23Hxg)
- [Preventing Copy-Paste in LearningSpace](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/preventing-copy-paste-in-learningspace-sPD0IIUuk0)
- [Important Technical Notification Regarding Adobe Flash Player](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/important-technical-notification-regarding-adobe-flash-player-eQtMLwLmTJ)
- [iPad support - Technical information](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/ipad-support-technical-information-dLmeFvKofC)
- [TeamViewer Link](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/teamviewer-link-QyKZBMqUT9)
- [YouTube videos about LearningSpace](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/youtube-videos-about-learningspace-TMb3zdc0LC)
- [Customer Aftercare One-Pager](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/customer-aftercare-one-pager-GBWMe1BcfS)
- [Case Studies](https://kb.learningspace.elevatehealth.net/s/ent-hs/doc/case-studies-VcAbFqXSz7)