Skip to content

LDAP Directory Service Integration

LDAP Directory Service Integration provides standardized connectivity with enterprise-grade identity sources, enabling centralized management and automatic synchronization of user identity information to build a unified, efficient, and secure identity governance system.

Version Limitation: This feature is only supported in privately deployed versions and is unavailable for cloud service editions.

Core Value

1. Unified Identity Management

  • Centralized Control:
  • Automated Synchronization:
    • Scheduled incremental sync (default: 30 minutes)
    • Real-time triggered sync (upon account changes)
    • Bidirectional attribute mapping configuration
  • Lifecycle Linkage: Automatic suspension of all associated system permissions when an employee's AD account is disabled upon departure.

2. Enhanced Security Authentication

  • Enterprise-Grade Authentication:
    Authentication MethodProtocol SupportSecurity Level
    Simple BindLDAP★★☆
    SASL AuthenticationDIGEST-MD5★★★
    Encrypted ChannelSTARTTLS/SSL★★★★
  • Password Policy Inheritance:
    • Complexity requirements synchronization
    • Mandatory password expiration synchronization

3. Efficient Operations System

  • User Provisioning Comparison:
    MethodNew Employee Activation TimeError Rate
    Manual Creation1-2 business days>8%
    LDAP Sync<5 minutes<0.5%
  • Bulk Operations:
    • One-click department structure import
    • OU-based (Organizational Unit) permission assignment
    • Group policy inheritance for permission templates

Application Scenarios

1. Rapid Onboarding for New Employees

Process:

  1. HR creates an account in AD
  2. Automatic sync to AngusGM
  3. Pre-configured permission templates take effect
    Efficiency: System readiness achieved in <10 minutes

2. Organizational Restructuring

Scenario: Department reorganization
Steps:

  1. Adjust department structure in AD
  2. Trigger real-time synchronization
  3. Permissions automatically inherit the new structure
    Advantage: Organization-wide adjustments completed within 1 hour for a thousand employees

3. Unified Security Policy

Requirement: Strengthen password security
Implementation:

  1. Enable 12-character complexity policy in AD
  2. AngusGM automatically inherits the policy
  3. System-wide forced password reset
    Outcome: Unified security level, reduced breach risk

Released under the GPL-3.0 License.