Cloud LDAP for Zoho Directory

Cloud LDAP for Zoho Directory

What is LDAP?

Cloud LDAP in Zoho Directory enables organizations to utilize LDAP (Lightweight Directory Access Protocol) for authentication and user management, eliminating the need to maintain an on-premises LDAP server. By using Zoho’s cloud-based infrastructure, admins can integrate Zoho Directory with LDAP-compatible applications and services, making it easier to manage user identities and control access securely.

This eliminates the hassle of managing physical directory servers while still giving you the flexibility of traditional LDAP. Cloud LDAP is especially useful for those who want:
  1. A single source of truth for all users and credentials.
  2. Easy integration with LDAP-supported applications like Linux systems, Atlassian Jira, OpenVPN, printers, and more.
  3. Secure authentication over the cloud (LDAPS).

What is a service account?

A service account in Cloud LDAP is an account created in Zoho Directory solely for enabling applications to connect to the directory and perform authentication and directory lookup operations in a secured way. It is used by applications or services (like Jira and VPN servers) to bind to Cloud LDAP. In LDAP terms, this is usually the BindDN (distinguished name) + password that the application uses.To set up and manage Cloud LDAP, you'll first need to add LDAP clients to Zoho Directory (eg., printers, Atlassian Jira), configure access permissions for each client, and connect them to the Cloud LDAP service.

Prerequisites

  1. Zoho Directory account with admin privileges
  2. Cloud LDAP enabled in your Zoho Directory admin console
  3. Users already added or synced to your Zoho Directory account

Add LDAP clients

  1. Sign in to Zoho Directory, then click Admin Panel in the left menu.
  2. Go to LDAP in the left panel, if not configured, click Configure LDAP. If already configured, click Add LDAP Client in the Clients tab.
  3. Under LDAP client name field, enter a name (for example, Printer).
  4. Under BindDN service account, if not added already, click Add service account. Enter a username for the service account, copy the generated password, and then click Save
    Notes
    You'll need the generated password when connecting your client to the Secure LDAP service, so make sure to save it. Otherwise, you will have to regenerate a new password.
  5. Now, select from the added accounts and click Save and Next.

Configure access permissions and attributes

The access permissions page will automatically be displayed once you have added an LDAP client. It determines how applications interact with your directory and what data can be accessed. It has two sections:

 User Authentication - This setting allows the admins to restrict which users are allowed to authenticate via Cloud LDAP. In other words, only the users with LDAP permissions can authenticate successfully. This operation is read-only, so the application cannot modify the user credentials in Zoho Directory. 
Read User Information - This setting specifies which attributes of the user the LDAP client can access to retrieve user information. You can choose the attributes you want to expose via Attribute mapping in Zoho Directory.
  1. To include users that an LDAP client can access to verify the user credentials, tick the checkbox Verify user credentials.
  2. Tick the checkbox Read user information to select the attributes that the LDAP client can have access to.
  3. Select one from the available LDAP attributes and click Save and Next.
  4. To add a custom attribute, go to the Attributes tab, click Manage Attributes.
  5. Click Add Attribute. Enter an attribute name.
  6. For Field value, select from the profile fields or enter a hardcoded value. Then, click Add. You can select the custom-added attribute on the permissions page. 

Assign members

Once you've added LDAP client and configured permissions for it, you can now assign members to each client.
  1. In the Summary page, click Assign Members at the bottom page to assign users to the client.
  2. Under Choose Users, click to either select users manually or attach file.
  3. After selecting, click Assign.

Add a service account

  1. Under LDAP section, go to Service Accounts tab.
  2. Click Add Service Account.
  3. Enter a username for the service account, copy the generated password, and then click Save.
Notes
You'll need the generated password when connecting your client to the Secure LDAP service, so make sure to save it. Otherwise, you will have to regenerate a new password.

Delete a service account

  1. Under LDAP section, go to Service Accounts tab.
  2. Hover over the required service account, and click Delete.
Notes
If the service account is mapped to clients, you'll have to dissociate the clients from the service account to delete.

Edit access permissions

  1. Sign in to Zoho Directory, then click Admin Panel in the left menu.
  2. Go to LDAP, and click Clients tab.
  3. Click on the required client from the list, click Edit, and then click Save and Next.
  4. Tick or untick the access permissions checkbox based on your preference.

Edit LDAP client details

  1. Go to Clients tab, and hover over the required client name.
  2. Click , then click Edit.
  3. Edit the necessary details on the page and click Save and Next.

Deactivate/ Delete LDAP client

  1. Go to Clients tab, and hover over the required client name.
  2. Click  , then click Deactivate.
  3. To delete a client, click Delete. Once deleted, you can no longer retrieve the client's information. 

Connect LDAP clients to the Cloud LDAP service

Before connecting your LDAP client to the Cloud LDAP service, make sure you have added your client to Zoho Directory as a LDAP server, configured access permissions, and optionally generated access credentials.
Info
Depending on the type of client, there are different instructions for connecting them to the LDAP service.
To begin, open the LDAP client's authentication or directory settings and enter the necessary details listed below. Alternatively, you can find them in the Info tab > LDAP > Admin Panel.

 Hostname
 ldap.zoho.com
 Ports
 389 for LDAP port (StartTLS enabled)
 636 for LDAPS port (SSL/TLS enabled)
 Base DN
 Your domain in DN format (LDAP client base DN)
 dc=zohodirectory, dc=com for zohodirectory.com
 Username and password
 For LDAP clients that require a username and password, use the username and saved password from when you created a service account while adding the LDAP client to Zoho Directory.

Info
For encryption between the client and LDAP server, LDAPS is preferred. But, if you choose to use LDAP, it is necessary to enable StartTLS for security purposes.

LDAP-supported operations

Below are some of the supported operations to ensure smooth and safe access to directory information:

1. Request Rate Limit 
- Up to 4 Requests Per Second:
Each user or application can send a maximum of 4 LDAP requests every second. Avoid sending too many requests in a short time to prevent connection issues.

2. Connection Time Limit 
- Each Connection Can Stay Open for Up to 1 Minute:
Any LDAP connection you make to the service can last a maximum of one minute before it is closed automatically. This helps keep the system efficient and stable.

3. Concurrent Connection Limit 
- Maximum of 100 Connections at the Same Time:
The service supports up to 100 simultaneous connections from all users or apps combined.

4. Supported LDAP Operations 
bind:
Log in to the directory to prove your identity.
unbind: Log out to close your session cleanly.
search: Look up information stored in the directory (like users, groups, or devices).
extended operations: Includes:
  1. StartTLS: A way to encrypt the connection, keeping your data safe while it’s sent over the network.
  2. Who Am I?: Lets you check which user or application you’re currently authenticated as.
Below are the links to configuration instructions for a few LDAP clients. Otherwise, you can refer to the documentation of the relevant client.
Info
Certain LDAP clients, such as Atlassian Jira and SSSD, perform a user lookup to get more information about a user during user authentication. To make sure user authentication works correctly for such LDAP clients, you'll need to turn on Read user information for all organizational units where Verify user credentials is turned on.


      Create. Review. Publish.

      Write, edit, collaborate on, and publish documents to different content management platforms.

      Get Started Now


        Access your files securely from anywhere

          Zoho CRM Training Programs

          Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.

          Zoho CRM Training
            Redefine the way you work
            with Zoho Workplace

              Zoho DataPrep Personalized Demo

              If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

              Zoho CRM Training

                Create, share, and deliver

                beautiful slides from anywhere.

                Get Started Now


                  Zoho Sign now offers specialized one-on-one training for both administrators and developers.

                  BOOK A SESSION







                              Quick LinksWorkflow AutomationData Collection
                              Web FormsEnterpriseOnline Data Collection Tool
                              Embeddable FormsBankingBegin Data Collection
                              Interactive FormsWorkplaceData Collection App
                              CRM FormsCustomer ServiceAccessible Forms
                              Digital FormsMarketingForms for Small Business
                              HTML FormsEducationForms for Enterprise
                              Contact FormsE-commerceForms for any business
                              Lead Generation FormsHealthcareForms for Startups
                              Wordpress FormsCustomer onboardingForms for Small Business
                              No Code FormsConstructionRSVP tool for holidays
                              Free FormsTravelFeatures for Order Forms
                              Prefill FormsNon-Profit

                              Intake FormsLegal
                              Mobile App
                              Form DesignerHR
                              Mobile Forms
                              Card FormsFoodOffline Forms
                              Assign FormsPhotographyMobile Forms Features
                              Translate FormsReal EstateKiosk in Mobile Forms
                              Electronic Forms
                              Drag & drop form builder

                              Notification Emails for FormsAlternativesSecurity & Compliance
                              Holiday FormsGoogle Forms alternative GDPR
                              Form to PDFJotform alternativeHIPAA Forms
                              Email FormsFormstack alternativeEncrypted Forms

                              Wufoo alternativeSecure Forms

                              WCAG

                                        Create. Review. Publish.

                                        Write, edit, collaborate on, and publish documents to different content management platforms.

                                        Get Started Now







                                                          You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.




                                                              Manage your brands on social media


                                                                • Desk Community Learning Series


                                                                • Digest


                                                                • Functions


                                                                • Meetups


                                                                • Kbase


                                                                • Resources


                                                                • Glossary


                                                                • Desk Marketplace


                                                                • MVP Corner


                                                                • Word of the Day


                                                                • Ask the Experts


                                                                  Zoho Sheet Resources

                                                                   

                                                                      Zoho Forms Resources


                                                                        Secure your business
                                                                        communication with Zoho Mail


                                                                        Mail on the move with
                                                                        Zoho Mail mobile application

                                                                          Stay on top of your schedule
                                                                          at all times


                                                                          Carry your calendar with you
                                                                          Anytime, anywhere




                                                                                Zoho Sign Resources

                                                                                  Sign, Paperless!

                                                                                  Sign and send business documents on the go!

                                                                                  Get Started Now




                                                                                          Zoho TeamInbox Resources





                                                                                                    Zoho DataPrep Demo

                                                                                                    Get a personalized demo or POC

                                                                                                    REGISTER NOW


                                                                                                      Design. Discuss. Deliver.

                                                                                                      Create visually engaging stories with Zoho Show.

                                                                                                      Get Started Now








                                                                                                                          • Related Articles

                                                                                                                          • Import users to Zoho Directory from other cloud identity solutions

                                                                                                                            Transferring user information from one identity provider to another can be tedious, and requires utmost care and effort, since even one mistake can lead to data breaches or loss. Zoho Directory provides you with different ways to import your users. ...
                                                                                                                          • Zoho Directory Sync Tool - Troubleshooting

                                                                                                                            Prerequisites Roles required to perform this action: Organization Owner Organization Admin Troubleshooting This document contains error messages you may encounter when you're setting up and using the Zoho Directory Sync Tool, and the methods to ...
                                                                                                                          • Add OneLogin to Zoho Directory

                                                                                                                            Prerequisites Roles required in Zoho Directory to perform this action: Organization Owner Organization Admin Role required in OneLogin: Admin Plan required in Zoho Directory: Free plan Professional plan (if you want to add multiple directories) In ...
                                                                                                                          • Import users from Okta to Zoho Directory

                                                                                                                            If you are currently using Okta as your cloud directory service to store your organization data, you can easily import your users to Zoho Directory. For exporting users from Okta, Okta prescribes a Chrome browser extension called rockstar. Export ...
                                                                                                                          • Import users from CyberArk to Zoho Directory

                                                                                                                            If you are currently using CyberArk as your cloud directory service to store your organization data, you can easily import your users to Zoho Directory. Export users from CyberArk Sign in to your CyberArk Admin Portal. In the left menu, click Reports ...
                                                                                                                            Wherever you are is as good as
                                                                                                                            your workplace

                                                                                                                              Resources

                                                                                                                              Videos

                                                                                                                              Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.



                                                                                                                              eBooks

                                                                                                                              Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.



                                                                                                                              Webinars

                                                                                                                              Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.



                                                                                                                              CRM Tips

                                                                                                                              Make the most of Zoho CRM with these useful tips.



                                                                                                                                Zoho Show Resources