IDENTITY

LDAP access control structure

An LDAP access control structure diagram makes delegated administration easier to review. It starts with the administrator and help desk groups, maps them to directory roles and shows the scope each role controls. Directory administrators may have broad administrative access, while a help desk group can be limited to password resets within the People organizational unit. This distinction supports least privilege and gives auditors a compact view of who can perform sensitive actions. The diagram is an explanation of the intended model, not an access control list itself. Validate it against the deployed LDAP ACLs, group membership and any product-specific delegation features before relying on it for an audit or change request.

UPDATED 2026-09-24
TYPEEntity
EXAMPLELDAP access control structure
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

LDAP delegated administration

Key decisions

  • Groups: Start with the teams that need access.
  • Roles: Map group membership to directory roles.
  • Scope: Identify the directory or OU each role controls.
  • Least privilege: Limit help desk rights to the needed action.

When to reuse this

Use it for access-review conversations and align the labels with the directory product's actual group and ACL configuration.

FAQ

Frequently asked questions

Why show groups separately from roles?01
Groups identify people who receive access; roles identify the permissions or administrative function those people are assigned.
What is delegated administration?02
It is the practice of granting a limited set of directory-management actions to a group without giving it full directory control.
How does this support least privilege?03
It makes the scope of each role visible so a help desk group can be limited to the specific organizational unit and action it needs.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.