---
sourceDocument: Yokohama Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/platform-security

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# LDAP integration

# LDAP integration {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of LDAP integration

LDAP integration in ServiceNow allows your instance to use your existing LDAP server as the primary source of user data.
This integration streamlines user login, automates user creation and role assignment, and facilitates single sign-on (SSO) implementations.
It uses a read-only connection to query user information without storing LDAP passwords or writing back to the LDAP directory.
Authentication occurs by validating user credentials directly against the LDAP server during login.
Show full answer Show less  

## Key Features

* **Scheduled LDAP refresh:** A nightly scan compares LDAP user attributes with instance records and updates any changes. This process should be scheduled during off-peak hours to avoid performance conflicts.
* **LDAP listener:** A persistent query mechanism that listens for changes in LDAP user accounts, enabling near real-time synchronization (within approximately 10 seconds) of user information.
* **On-demand LDAP login:** Allows new users without existing instance accounts to log in. The system queries LDAP for the user, authenticates credentials, then creates and populates the user record automatically.
* **LDAP data population:** Enables importing user data from LDAP into the instance with control over which attributes are imported via transform maps. This prevents data inconsistencies and optimizes import times.
* **LDAP authentication:** Users authenticate using their LDAP credentials, leveraging existing password and security policies such as account lockout and password expiration. The system updates user records to reflect LDAP authentication status and source.

## Important Considerations

* LDAP passwords are never stored in the instance; authentication happens securely within HTTPS sessions.
* The integration requires direct connectivity between the instance and the LDAP server; authentication through a MID Server is not supported.
* If Active Directory requires users to reset passwords at login, those users cannot log into the instance because password changes are not managed through ServiceNow.
* Post-deployment customization by an experienced administrator or ServiceNow consultants is needed to fully implement LDAP data population features.

## Practical Benefits for ServiceNow Customers

By implementing LDAP integration, you can centralize user management and authentication, reduce administrative overhead, and improve security by reusing existing network credentials and policies. The combination of scheduled refreshes and near real-time LDAP listeners ensures that user data in ServiceNow stays current with minimal delay. On-demand login enhances user experience by allowing immediate access without prior manual account setup.  
An LDAP integration allows your instance to use your existing LDAP server as the
primary source of user data.

Administrators integrate with a Lightweight Directory Access Protocol
(LDAP) directory to streamline the user login process and to automate administrative tasks
such as creating users and assigning them roles. An LDAP integration allows the system to use
your existing LDAP server as the primary source of user data. Typically, an LDAP integration
is also part of a single sign-on implementation.{#c_LDAPIntegration__p_LDAPIntegration1}

The integration uses the LDAP service account credentials to retrieve
the user distinguished name (DN) from the LDAP server. Given the DN value for the user, the
integration then rebinds with LDAP with the user's DN and password. The password that the user
enters is contained entirely in the HTTPS session. The integration never stores LDAP
passwords.{#c_LDAPIntegration__p_LDAPIntegration2}

The integration uses a read-only connection that never writes to the
LDAP directory. The integration only queries for information, and then updates its internal
database accordingly.{#c_LDAPIntegration__p_LDAPIntegration3}  
Note:  
For detailed information about setting up the integration, see [LDAP integration setup](https://www.servicenow.com/docs/RJSGen6yV6t_FjzuNBl1Jw "Administrators can enable LDAP integration to allow sign-on of users from their company LDAP directory.").  
Note:  
If your instance is using an LDAP integration and the Active Directory settings require users to reset their password upon login, your users will not be able to log in the instance. The instance cannot change any user's active directory password.

## Features of LDAP integration {#c_LDAPIntegration__section_twg_x5x_qcb}

LDAP integration features include the following.  

Scheduled LDAP refresh

:   A scheduled scan of your LDAP server is usually run once a night. It queries all
    applicable user records' attributes and compares them with the account on our
    servers. If there is a difference, we modify our user record with the changed
    attribute. The load placed upon the LDAP server during the refresh depends on how
    many records are queried, and the number of attributes being compared. We recommend
    scheduling the refresh during off-peak hours. A large refresh operation can affect
    other scheduled operations, such as running reports, and should be planned to
    minimize any conflicts.

LDAP listener

:   LDAP listener is our version of a persistent query (or persistent search). We issue
    a standing query for changes made to your LDAP server, and constantly listen for a
    response. Assuming your server supports a persistent search, any changes made to any
    of your applicable LDAP accounts are returned to the LDAP listener and sent to your
    instance within approximately 10 seconds. This is an extremely useful tool, allowing
    us to have a nearly real-time copy of your users' account details, without having to
    wait for the next scheduled refresh.

On-demand LDAP login

:   After an LDAP integration is established, the instance can allow new users to log
    in to the system even if they do not yet have an account on the instance. When a new
    user attempts to log in to the instance, the integration checks to see if this user
    has an account in the instance. If the integration does not find an existing user
    account, it automatically queries the LDAP server for the username that was entered.
    If a matching LDAP account is found, the integration tries to authenticate with the
    password the user entered. If the password is valid, the instance creates an account
    for the user, populates the account with all applicable LDAP information, and logs
    the user in to the instance.

    On-demand login uses the LDAP User Import transform map. For more information on
    transform map requirements, see [LDAP transform maps](https://www.servicenow.com/docs/ujosC~qrJ0xvzyDkw7Gj7w "The transform map moves data from the import set table to the target table (User or Group).").

LDAP data population
:   Note:  
    Functionality described in this integration is not available by default. This integration involves post-deployment customization performed by an experienced administrator or by ServiceNow professional services consultants.

    An integration to the LDAP servers allows you to quickly and easily populate the
    instance's database with user records from the existing LDAP database. To prevent
    data inconsistencies, you can create, ignore, or skip incoming LDAP records.

    You can also limit the data the integration imports by specifying LDAP attributes,
    thereby importing only the data that you want to expose to an instance. Typically,
    the LDAP attributes you specify become part of the integration [transform map](https://www.servicenow.com/docs/ujosC~qrJ0xvzyDkw7Gj7w "The transform map moves data from the import set table to the target table (User or Group)."). If you
    do not specify any LDAP attributes, the integration imports all available object
    attributes from the LDAP server. The instance stores imported LDAP data in temporary
    import set tables, so the more attributes you import, the longer the import time.
    For more information, see [Specify the LDAP attributes](https://www.servicenow.com/docs/BgvydAGCXTqWmOGlb4_1hQ "Specify the attributes included in LDAP server queries by using the LDAP server Attributes field. This can enhance performance as well as security.").

LDAP authentication
:   Use LDAP authentication to access using LDAP credentials.  
    When a user enters network credentials in the login page:

    1. The instance passes the credentials to an LDAP server to find the instance.
    2. With RDNs, it validates the user's DN string. It validates only if at least one of the LDAP OU configurations with `table=sys_user` has an RDN configured.
    3. The LDAP server responds with an authorized or unauthorized message that the system uses to determine whether access should be granted.
    {#c_LDAPIntegration__ol_ll4_k2z_dv}

    By authenticating against your LDAP server, users access the platform
    with the same credentials that they use for other internal resources on your network
    domain. Also, you can reuse any existing password and security policies that are
    already in place. For example, the LDAP server may already have account lockout and
    password expiration policies.

    When you enable LDAP, the system updates user
    records with these fields.

    {#c_LDAPIntegration__table_jy4_4jw_kq__entry__2}

    | Field | Description |
    |-|-|
    | Source | Identifies whether or not LDAP is used to validate a user. If the source starts with ldap, then the user is validated via LDAP. If the source does not start with ldap, then the password on the user record is used to validate the user upon login. |
    | LDAP Server | Identifies which LDAP server authenticates the user when there are multiple LDAP servers. |
    [Table 1. LDAP user record updates]

    {#c_LDAPIntegration__table_jy4_4jw_kq}

    Note:  
    The system does not support LDAP password authentication through a MID Server. An instance must be able to directly connect with an LDAP server to support password authentication.

