# ◾ Directory Access Settings

This tab is for defining server settings for [**LDAP configuration**](/doc/how-can-i-configure-ldap-login-wDFHjZNZDI)**:**  

**LearningSpace Essentials** can be connected with directory servers that use the **Lightweight Directory Access Protocol (LDAP)** to provide you with an efficient way of **user authentication and group synchronization.**  
**LDAP synchronization** provides possibilities to import and synchronize groups of users based on the data of the selected server.

 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/48ddf0a7-308b-4fe9-b28a-e3ce1797eaa8/682d5b4b-64c0-4280-ab93-3ebfe24fc354/DIRECTORY%20ACCESS%20SETTINGS.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T151500Z&X-Amz-Expires=86400&X-Amz-Signature=7a618c9900a2a5da4a569f17ea9328f64d2ec3d98b8af5c2fc703f1dc856d0f2&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =x1042")


:::info
Available to users with **Admin** role.

:::


:::tip
Go to **Directory Access Settings** in [**System**](/doc/c3a68097-0e6c-47c9-baed-09ae681a647f), and [**configure the directory server(s)**](/doc/how-can-i-add-my-directory-servers-NDJbYrZ1iF) of your institution (more than one can be added).

See how to use the [**LDAP Server Settings**](/doc/how-can-i-add-my-directory-servers-NDJbYrZ1iF) dropdown.

:::

## LDAP login settings

* **Use for login:** the system will use the specified LDAP server for login authentication
* **Use full DN:**  search for the user directly by the user’s full distinguished name
* **Authentication ID:** you can set which field should be checked with LDAP login
* **DN prefix:** Distinguished Name will start with the given prefix
* **DN postfix:** Distinguished Name will end with the given postfix
* **Resolve samAccountName:**  authenticate the user through a specified query user who has access to the LDAP server (query user name, password and base)



:::tip
Contact your organization’s network administrator or IT professional for the exact details of your directory server.

:::

## LDAP authentication modes

Servers set for login have **two modes of authentication:**


1. **Use full DN (selected by default)**:   
   This method requests a user's full distinguished name to authenticate them. Specify the **Authentication ID**, **DN prefixes** and **postfixes** to find users on your directory server.   
   Every user who is a match for the request can log in to **LearningSpace Essentials** with their credentials stored on the directory server.  
2. **Resolve samAccountName:**  
   This method requires a query user and the users’ samAccountName to authenticate them.

   
   1. Provide the name and password of your directory server's query user.
   2. Provide a query base to define the level of the query in your directory tree.


Every user who is a match for the query can log in to LearningSpace with their credentials stored on the directory server.  
By applying a query user, you grant **LearningSpace Essentials** permission to search the provided query base and authenticate any user who has a match for their samAccountName.


:::warning
It is important that the query user has **permission to search** in the affected LDAP tree.

:::



:::tip
See more at [**How can I configure LDAP login**](/doc/how-can-i-configure-ldap-login-wDFHjZNZDI)**.**

:::


## LDAP synchronization

Switch on LDAP synchronization **to import users** with ease from your directory server(s) into a user group in LearningSpace.  

 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/48ddf0a7-308b-4fe9-b28a-e3ce1797eaa8/3b46aad5-28b3-4967-a37a-c9015ad6dc0c/image-2023-6-8_17-28-21.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T151500Z&X-Amz-Expires=86400&X-Amz-Signature=fa75d5ac6eb762791fbe56b113472d12241766798301a9f2389fa63eaa3ccb5b&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =x1260")

  
Provide the **name and password of the** **query user** (dedicated for synchronization) of your directory server.

* **Query user:** query user's full DN in the LDAP server
* **Query password:** query user’s password
* **Query base:** defines the starting point of the search on the LDAP server (query user needs access to this base)
* **Mapping:**  enter the attributes used on your directory server that correspond with each of the personal detail fields (e.g. first name, email, UCID, etc.).  
  LearningSpace needs these details in **Mapping** to match each data field with an attribute and execute a successful synchronization.

 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/6c0da235-ff99-49fd-81af-d32f613692dd/0123f1c1-fd3e-46be-8b57-df2ad89f30c5/66356121.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T151500Z&X-Amz-Expires=86400&X-Amz-Signature=3a685e5557e15184eddae4571c8b65b53e65380a7ab9e6a773d56f65e45f4099&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =448x379")  


:::tip
See more at [**How can I configure LDAP synchronization?**](/doc/how-can-i-configure-ldap-synchronization-X3J8iyKEEu)**.**

:::



:::warning
In case of **invalid users** or **missing/incorrect data** on your directory server, the system will warn you. Meanwhile, users who are successfully authenticated can still be imported.

:::


 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/6c0da235-ff99-49fd-81af-d32f613692dd/fecfe5e1-cc1b-468a-8cec-9035377ff259/55804160.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T151500Z&X-Amz-Expires=86400&X-Amz-Signature=4cd6dc443bff1462cadc90cbdaad4311d8068a854787322aeceef51d68b6289f&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =672x508")



:::success
To import users into a group, go to [**User Manager**](/doc/88d3270e-01bf-49f5-8227-5e100941a714) and edit or create a new group. Select the LDAP tab in the [**Create / Edit Group**](/doc/736b2ac8-28cf-415c-b721-daff3cbb3ced) pop-up and follow the steps [**on this page**](/doc/how-do-i-import-and-synchronize-users-from-my-directory-servers-bs5zACJANp)**.** Only **Admin** users can import users.

:::



:::info
In case your directory server is down, users authenticated by LDAP will be unable to log in with their email and password from the directory server.  
For a temporary solution, LDAP authentication can be disabled for each user one by one in their [**Edit User**](/doc/736b2ac8-28cf-415c-b721-daff3cbb3ced) window and login details can be entered manually in **LearningSpace Essentials**.

:::

---

**Documents**

- [User Guide](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/user-guide-QPZfKJ0BV1)
- [FAQ](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/faq-AZnS7tDFgM)
- [Release Notes](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/release-notes-fqaGSPScxH)
- [iPad support - Technical information](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/ipad-support-technical-information-iHec00YAzm)
- [Customer Aftercare One-Pager](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/customer-aftercare-one-pager-GOIZYTEgud)
- [Preventing Copy-Paste in LearningSpace](https://kb.learningspace.elevatehealth.net/s/ess-hs/doc/preventing-copy-paste-in-learningspace-uEubHwXVD2)