IDENTITY

LDAP directory tree

An LDAP directory tree is organized around a base distinguished name, often a domain-style DN such as dc=example,dc=com. Below it, organizational units group entries by their purpose: people, groups and service accounts are common starting points. User entries, group entries and application bind accounts then sit under their respective organizational units. A diagram makes the hierarchy easier to explain during onboarding, migration planning and access reviews. It should reflect the naming conventions and actual distinguished names used in the directory, not just a generic example. Directory schemas vary between OpenLDAP, Active Directory and other services, so capture the units and object classes that matter to the systems using the directory.

UPDATED 2026-09-24
TYPEEntity
EXAMPLELDAP directory tree
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

LDAP directory documentation

Key decisions

  • Base DN: Start at the directory root.
  • Organizational units: Group entries by purpose.
  • User entries: Place people below the People OU.
  • Groups and binds: Show group and service-account entries.

When to reuse this

Use it to document a directory's intended hierarchy; replace the sample DNs with the names in the actual directory.

FAQ

Frequently asked questions

What is the base DN?01
The base distinguished name is the directory root from which LDAP searches and subordinate entries are organized.
What is an organizational unit?02
An organizational unit, or OU, is a container that groups related directory entries, such as users or service accounts.
Why separate service accounts?03
A separate OU makes application bind accounts easier to identify, manage and review independently from human users.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.