# Directory Access Settings

:::info
Available to users with Admin privilege.

:::

**LearningSpace Experience** can be connected with directory servers that use the **Lightweight Directory Access Protocol** (**LDAP**) to provide you with an efficient way of user authentication and group synchronization.

Go to **Directory Access Settings** in the [**System**](/doc/system-module-TNvU3yVfhr) and [**configure**](/doc/how-can-i-add-my-directory-servers-eDSU5wTvU3) **your institution's directory server(s)** (more than one can be added).

 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/48ddf0a7-308b-4fe9-b28a-e3ce1797eaa8/3ea21536-0bc9-422b-ab4f-e11f2fd064c7/DIRECTORY%20ACCESS%20SETTINGS.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T144500Z&X-Amz-Expires=86400&X-Amz-Signature=08a2c65c96cc2c1011a964117ad54b03357f63a7dd0befb9b4df5b715fbf3c0e&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject " =x1496")

Manage further settings such as user authentication methods and synchronization.


:::success
Contact your organization’s network administrator or IT professional for the exact details of your directory server.

:::

## LDAP authentication modes


1. **Use full DN (selected by default):**   
   This method requests a user's full distinguished name to authenticate them.  
   Specify the **Authentication ID**, **DN prefixes,** and **postfixes** to find users on your directory server.   
   Every user who is a match for the request can log in to LearningSpace with their credentials stored on the directory server.  
2. **Resolve samAccountName:**  
   This method requires a query user and the user’s samAccountName to authenticate them.  

   
   1. Provide the name and password of your directory server's query user.
   2. Provide a query base to define the query level in your directory tree.

Every user who is a match for the query can log in to LearningSpace with their credentials stored on the directory server.  
By applying a query user, you grant **LearningSpace Experience** permission to search the provided query base and authenticate any user with a match for their samAccountName.


:::info
See more at [**How can I configure LDAP login**](/doc/how-can-i-configure-ldap-login-yspcQiv1Eq)**.**

:::

## LDAP synchronization

Switch on LDAP synchronization to import users from your directory server(s) into a user group in LearningSpace Experience easily.

* Provide the name and password of the query user (dedicated for synchronization) of your directory server.
* At **Mapping**, enter the attributes used on your directory server that correspond with each personal detail field (e.g., first name, email, UCID, etc.).  
  LearningSpace needs these details in **Mapping** to match each data field with an attribute and execute a successful synchronization.  


:::info
See more at [**How can I complete LDAP synchronization**](/doc/how-can-i-complete-ldap-synchronization-HvkeLjhKYX)**.**

:::



:::warning
**Note**

In case of invalid users or missing/ incorrect data on your directory server, the system warns you.  
Meanwhile, users who are successfully authenticated can still be imported.  

:::

 ![](https://outline-production-attachments.s3-accelerate.amazonaws.com/uploads/6c0da235-ff99-49fd-81af-d32f613692dd/912a91a0-ab3b-43cc-acad-fda02e415895/55804165.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIA4EOUDTOVUICLPZ4P%2F20260909%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20260909T144500Z&X-Amz-Expires=86400&X-Amz-Signature=7d2e62a24a83cbabce29b990e4f331488db75fdd7093572e91ecb932f2a86c09&X-Amz-SignedHeaders=host&x-amz-checksum-mode=ENABLED&x-id=GetObject)



:::info
To import users into a group, go to the [**User Manager**](/doc/user-manager-WiMFUUc7Zq) and edit or create a new group.  
Select the **LDAP** tab in the [**Create / Edit Group**](/doc/groups-users-mqOHllqII2) pop-up and follow the steps [**on this page**](/doc/how-do-i-import-and-synchronize-users-from-my-directory-servers-HmXgrQv114).  
Only Admin users can import users.

:::



:::info
If your directory server is down, users authenticated by LDAP cannot log in with their email and password from the directory server.  
For a temporary solution, LDAP authentication can be disabled for each user one by one in their [**Edit User**](/doc/55484e14-d984-4d65-a8a6-4abb7c822240) window and login details can be entered manually in **LearningSpace Experience**.

:::

---

**Documents**

- [User Guide](https://kb.learningspace.elevatehealth.net/s/exp-hs/doc/user-guide-oarr3rXNmH)
- [FAQ](https://kb.learningspace.elevatehealth.net/s/exp-hs/doc/faq-YLwvsQzPg1)
- [Training Videos](https://kb.learningspace.elevatehealth.net/s/exp-hs/doc/training-videos-TEIl08kVIW)
- [Release Notes](https://kb.learningspace.elevatehealth.net/s/exp-hs/doc/release-notes-W7WkHQOdlB)
- [iPad support - Technical information](https://kb.learningspace.elevatehealth.net/s/exp-hs/doc/ipad-support-technical-information-CvKg62sptV)
- [Customer Aftercare One-Pager](https://kb.learningspace.elevatehealth.net/s/exp-hs/doc/customer-aftercare-one-pager-fm7WLpsnDM)