<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>directory services | vnceb</title>
    <link>https://www.20-100.net/topics/directory-services/</link>
    <description>Recent content in directory services on vnceb</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 25 Jun 2026 00:00:00 &#43;0000</lastBuildDate>
    <atom:link href="https://www.20-100.net/topics/directory-services/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>LDAP in 2026: A Strategic Assessment for Hybrid Enterprises</title>
      <link>https://www.20-100.net/research/ldap-in-2026-a-strategic-assessment-for-hybrid-enterprises/</link>
      <pubDate>Thu, 25 Jun 2026 00:00:00 &#43;0000</pubDate>
      <guid>https://www.20-100.net/research/ldap-in-2026-a-strategic-assessment-for-hybrid-enterprises/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Independent Research Note | June 2026&lt;/strong&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;bottom-line&#34;&gt;Bottom Line&lt;/h2&gt;
&lt;p&gt;LDAP is not dying, but it has stopped evolving, and its perimeter is shrinking. The protocol remains actively maintained across all three major implementations, and no vendor has formally deprecated infrastructure-level LDAP support. Yet the IETF working group that produced the modern specification concluded years ago, and its standards are now frozen&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;. The gaps enterprises have complained about for a decade, among them no native MFA and no standard change-notification mechanism, will never be fixed at the protocol level. LDAP&amp;rsquo;s role is narrowing from general-purpose identity protocol to infrastructure-layer plumbing for systems that cannot speak anything else. Enterprises that treat LDAP as a strategic platform, rather than a managed dependency, accumulate technical debt at an accelerating rate.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;key-findings&#34;&gt;Key Findings&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;All three major implementations are maintained, but the work is custodial, not transformative.&lt;/strong&gt; OpenLDAP shipped 2.6.13 as an LTS release in March 2026&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;, yet its core team is four people and leans heavily on Symas for funding and engineering&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;. Red Hat dropped openldap-servers from RHEL 8&lt;sup id=&#34;fnref:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;, and SUSE retired its OpenLDAP server to the Legacy module&lt;sup id=&#34;fnref:5&#34;&gt;&lt;a href=&#34;#fn:5&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;5&lt;/a&gt;&lt;/sup&gt;. 389 Directory Server is the healthiest of the three: it completed its BerkeleyDB-to-LMDB migration in version 3.1.3&lt;sup id=&#34;fnref:6&#34;&gt;&lt;a href=&#34;#fn:6&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;6&lt;/a&gt;&lt;/sup&gt; and remains Red Hat&amp;rsquo;s strategic platform behind FreeIPA and Identity Management&lt;sup id=&#34;fnref:7&#34;&gt;&lt;a href=&#34;#fn:7&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;7&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Microsoft is hardening Active Directory&amp;rsquo;s LDAP, not retiring it.&lt;/strong&gt; Windows Server 2025 requires LDAP signing by default on new deployments, sets channel binding to &amp;ldquo;when supported,&amp;rdquo; adds TLS 1.3 for LDAP over TLS, and deprecates RC4&lt;sup id=&#34;fnref:8&#34;&gt;&lt;a href=&#34;#fn:8&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;8&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref:9&#34;&gt;&lt;a href=&#34;#fn:9&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;9&lt;/a&gt;&lt;/sup&gt;. Entra ID does not speak LDAP natively; cloud-only organizations that need it run Entra Domain Services, which Microsoft itself frames as a &amp;ldquo;transitional capability&amp;rdquo; for &amp;ldquo;AD minimization&amp;rdquo;&lt;sup id=&#34;fnref:10&#34;&gt;&lt;a href=&#34;#fn:10&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;10&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;The market is bifurcating.&lt;/strong&gt; SaaS vendors are walking away from LDAP: Docebo deprecated its LDAP integration in August 2025&lt;sup id=&#34;fnref:11&#34;&gt;&lt;a href=&#34;#fn:11&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;11&lt;/a&gt;&lt;/sup&gt;, and Barracuda stopped accepting new insecure LDAP connections in January 2025&lt;sup id=&#34;fnref:12&#34;&gt;&lt;a href=&#34;#fn:12&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;12&lt;/a&gt;&lt;/sup&gt;. Infrastructure vendors are not: Cisco, Palo Alto Networks, Fortinet, and VMware all keep LDAP as a first-class identity source&lt;sup id=&#34;fnref:13&#34;&gt;&lt;a href=&#34;#fn:13&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;13&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref:14&#34;&gt;&lt;a href=&#34;#fn:14&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;14&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Roughly 40% to 70% of a large enterprise&amp;rsquo;s application portfolio still carries an LDAP dependency.&lt;/strong&gt; No analyst publishes this number; it is our estimate from vendor documentation and practitioner accounts. The hardest dependencies cluster in network access control, VPN authorization, the Linux identity stack, multifunction printers, and SAP and Oracle systems, where SAP alone has committed to maintenance through 2040&lt;sup id=&#34;fnref:15&#34;&gt;&lt;a href=&#34;#fn:15&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;15&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Authentication is largely a solved replacement problem; authorization and directory queries are not.&lt;/strong&gt; OIDC, passkeys, and service-mesh mTLS now cover new application and workload authentication&lt;sup id=&#34;fnref:16&#34;&gt;&lt;a href=&#34;#fn:16&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;16&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref:17&#34;&gt;&lt;a href=&#34;#fn:17&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;17&lt;/a&gt;&lt;/sup&gt;. They do not replace LDAP as a queryable user and group store, and no pull-based cloud equivalent to an LDAP search exists. Cross-environment authorization remains unstandardized; the OpenID AuthZEN effort is early&lt;sup id=&#34;fnref:18&#34;&gt;&lt;a href=&#34;#fn:18&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;18&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Every directory alternative trades away something.&lt;/strong&gt; Entra ID needs a managed LDAP bridge&lt;sup id=&#34;fnref1:10&#34;&gt;&lt;a href=&#34;#fn:10&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;10&lt;/a&gt;&lt;/sup&gt;, JumpCloud offers genuine cloud LDAP but prices linearly per user&lt;sup id=&#34;fnref:19&#34;&gt;&lt;a href=&#34;#fn:19&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;19&lt;/a&gt;&lt;/sup&gt;, Okta&amp;rsquo;s LDAP Interface supports only BIND, UNBIND, and SEARCH&lt;sup id=&#34;fnref:20&#34;&gt;&lt;a href=&#34;#fn:20&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;20&lt;/a&gt;&lt;/sup&gt;, and FreeIPA has no SaaS edition and no native OIDC or SAML&lt;sup id=&#34;fnref1:7&#34;&gt;&lt;a href=&#34;#fn:7&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;7&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Migrations run far longer and cost far more than budgets assume.&lt;/strong&gt; The CloudBees 2025 DevOps Migration Index reports an average cost overrun of about $315,000 per migration, with the typical project running roughly 18% over budget&lt;sup id=&#34;fnref:21&#34;&gt;&lt;a href=&#34;#fn:21&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;21&lt;/a&gt;&lt;/sup&gt;. Coverage of Gartner&amp;rsquo;s 2025 IAM Summit describes application onboarding backlogs of 600-plus apps and timelines beyond eight years&lt;sup id=&#34;fnref:22&#34;&gt;&lt;a href=&#34;#fn:22&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;22&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id=&#34;forward-looking-assumptions&#34;&gt;Forward-Looking Assumptions&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Through 2030, no major infrastructure or ERP vendor removes LDAP from its products.&lt;/strong&gt; The pattern is additive: modern protocols ship alongside LDAP, not in place of it. SAP&amp;rsquo;s commitment runs to 2040&lt;sup id=&#34;fnref1:15&#34;&gt;&lt;a href=&#34;#fn:15&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;15&lt;/a&gt;&lt;/sup&gt;, and Oracle Internet Directory remains core to Oracle&amp;rsquo;s on-premises stack&lt;sup id=&#34;fnref:23&#34;&gt;&lt;a href=&#34;#fn:23&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;23&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;By 2028, OIDC and passkeys are the unquestioned default for new application authentication, yet the directory-query gap stays unsolved.&lt;/strong&gt; Organizations will still run a directory behind their OIDC provider. Passkeys replace credential verification, not the store of record&lt;sup id=&#34;fnref:24&#34;&gt;&lt;a href=&#34;#fn:24&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;24&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Infrastructure-level LDAP persists past 2030.&lt;/strong&gt; Network gear, printers, and legacy Unix are the categories with no standards-based replacement and replacement cycles measured in years, not quarters.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Freeze-and-bridge becomes the dominant enterprise pattern, and the identity orchestration layer becomes a standard architectural component.&lt;/strong&gt; Strata, Microsoft, and Okta already sell the connective tissue, and Gartner named identity orchestration in its June 2025 IAM technical-debt research&lt;sup id=&#34;fnref:25&#34;&gt;&lt;a href=&#34;#fn:25&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;25&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;The policy-engine market stays fragmented into 2027.&lt;/strong&gt; OPA, Cedar, and OpenFGA each win different niches&lt;sup id=&#34;fnref:26&#34;&gt;&lt;a href=&#34;#fn:26&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;26&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref:27&#34;&gt;&lt;a href=&#34;#fn:27&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;27&lt;/a&gt;&lt;/sup&gt;, and Apple&amp;rsquo;s hire of Styra&amp;rsquo;s OPA maintainers in August 2025 leaves OPA&amp;rsquo;s commercial trajectory unclear&lt;sup id=&#34;fnref:28&#34;&gt;&lt;a href=&#34;#fn:28&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;28&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id=&#34;analysis&#34;&gt;Analysis&lt;/h2&gt;
&lt;h3 id=&#34;1-the-protocol-is-maintained-not-advancing&#34;&gt;1. The protocol is maintained, not advancing&lt;/h3&gt;
&lt;p&gt;All three major LDAP implementations are under active development, but the nature of the work shows the trajectory.&lt;/p&gt;
&lt;p&gt;OpenLDAP continues steady LTS releases: 2.6.13 shipped on March 9, 2026, with a 2.7 feature release on the roadmap&lt;sup id=&#34;fnref1:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref:29&#34;&gt;&lt;a href=&#34;#fn:29&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;29&lt;/a&gt;&lt;/sup&gt;. The project is genuinely maintained, not abandoned. But its core team is four people, and it depends heavily on Symas for funding and engineering&lt;sup id=&#34;fnref1:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;. Red Hat dropped the openldap-servers package starting in RHEL 8&lt;sup id=&#34;fnref1:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;, and SUSE placed its OpenLDAP server in the Legacy module and then removed it from SLES 15 SP4&lt;sup id=&#34;fnref1:5&#34;&gt;&lt;a href=&#34;#fn:5&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;5&lt;/a&gt;&lt;/sup&gt;. The 2.7 roadmap is evolutionary: a native RADIUS server and password policies scoped by LDAP URI&lt;sup id=&#34;fnref1:29&#34;&gt;&lt;a href=&#34;#fn:29&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;29&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;389 Directory Server is the healthiest of the three. Red Hat maintains several release streams in parallel, completed the BerkeleyDB-to-LMDB backend migration in version 3.1.3, and keeps investing in the Cockpit web console, JSON audit logging, and connection handling at scale&lt;sup id=&#34;fnref1:6&#34;&gt;&lt;a href=&#34;#fn:6&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;6&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref:30&#34;&gt;&lt;a href=&#34;#fn:30&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;30&lt;/a&gt;&lt;/sup&gt;. It is Red Hat&amp;rsquo;s strategic LDAP platform, the foundation under FreeIPA and Identity Management&lt;sup id=&#34;fnref2:7&#34;&gt;&lt;a href=&#34;#fn:7&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;7&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Active Directory&amp;rsquo;s LDAP layer received its most significant security update in years with Windows Server 2025: LDAP signing required by default on new deployments, channel binding set to &amp;ldquo;when supported,&amp;rdquo; TLS 1.3 for LDAP over TLS, RC4 deprecation, and new performance counters for LDAP operations&lt;sup id=&#34;fnref1:8&#34;&gt;&lt;a href=&#34;#fn:8&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;8&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref1:9&#34;&gt;&lt;a href=&#34;#fn:9&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;9&lt;/a&gt;&lt;/sup&gt;. Microsoft is hardening LDAP, not deprecating it, and has announced no plan to retire AD&amp;rsquo;s LDAP interface. Entra ID does not support LDAP natively. Cloud-only tenants that need it deploy Entra Domain Services as a managed bridge, which Microsoft positions explicitly as a &amp;ldquo;transitional capability&amp;rdquo; supporting &amp;ldquo;AD minimization&amp;rdquo;&lt;sup id=&#34;fnref2:10&#34;&gt;&lt;a href=&#34;#fn:10&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;10&lt;/a&gt;&lt;/sup&gt;. On-premises AD and its LDAP interface therefore remain load-bearing inside Microsoft&amp;rsquo;s own hybrid architecture.&lt;/p&gt;
&lt;p&gt;The CVE record keeps the operational risk concrete. Two related Windows LDAP flaws patched in December 2024 make the point. CVE-2024-49112 (CVSS 9.8) is a critical unauthenticated remote code execution vulnerability in the Windows LDAP client. CVE-2024-49113 (CVSS 7.5), the denial-of-service companion that SafeBreach named &amp;ldquo;LDAPNightmare,&amp;rdquo; crashes the LSASS process and reboots the server. On January 1, 2025, SafeBreach published the first public proof-of-concept, which reliably crashes unpatched servers; the researchers noted that full remote code execution through CVE-2024-49112 was plausible but not demonstrated&lt;sup id=&#34;fnref:31&#34;&gt;&lt;a href=&#34;#fn:31&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;31&lt;/a&gt;&lt;/sup&gt;. Windows Server 2019 through 2025 were vulnerable if unpatched&lt;sup id=&#34;fnref:32&#34;&gt;&lt;a href=&#34;#fn:32&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;32&lt;/a&gt;&lt;/sup&gt;. 389 DS has its own history: multiple denial-of-service issues, and an access-control bypass (CVE-2022-1949) that could let an unauthenticated user craft a filter returning data they should not see, including password hashes&lt;sup id=&#34;fnref:33&#34;&gt;&lt;a href=&#34;#fn:33&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;33&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;At the standards level, LDAP is frozen. The IETF ldapbis working group concluded years ago&lt;sup id=&#34;fnref1:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;, and the RFC 4510 series from June 2006 remains the definitive specification with no revision effort underway&lt;sup id=&#34;fnref:34&#34;&gt;&lt;a href=&#34;#fn:34&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;34&lt;/a&gt;&lt;/sup&gt;. A few peripheral SASL drafts exist, such as SCRAM extensions for two-factor authentication and a SASL mechanism for passkeys, but both are expired Internet-Drafts, and no coordinated effort to revise the core protocol exists&lt;sup id=&#34;fnref:35&#34;&gt;&lt;a href=&#34;#fn:35&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;35&lt;/a&gt;&lt;/sup&gt;. Innovation happens at the implementation level, in OpenLDAP overlays and AD extensions, not in the protocol.&lt;/p&gt;
&lt;h3 id=&#34;2-where-ldap-cannot-yet-be-replaced&#34;&gt;2. Where LDAP cannot yet be replaced&lt;/h3&gt;
&lt;p&gt;The useful question is not whether LDAP is replaceable in theory, but what share of a real portfolio carries hardwired dependencies that modern protocols cannot serve today. No analyst publishes that figure. From vendor documentation, practitioner accounts, and infrastructure analysis, our estimate is that 40% to 70% of a typical large enterprise application portfolio retains some form of LDAP dependency: direct authentication, user lookup, or group-membership queries.&lt;/p&gt;
&lt;p&gt;The hardest categories cluster predictably.&lt;/p&gt;
&lt;p&gt;Network access control is the most entrenched. 802.1X environments rely on RADIUS servers (Cisco ISE, FreeRADIUS, Microsoft NPS) that query LDAP or AD for credential validation and group-based authorization. Certificate-based authentication (EAP-TLS) can remove LDAP from the authentication step, but authorization (VLAN assignment, access policy, group checks) still hits LDAP or AD. Cisco ISE, Aruba ClearPass, and Juniper all support LDAP as a primary identity source, with no standards-based replacement for the authorization function&lt;sup id=&#34;fnref1:14&#34;&gt;&lt;a href=&#34;#fn:14&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;14&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;VPN gateways have moved further. Cisco Secure Client (formerly AnyConnect), Palo Alto GlobalProtect, and Fortinet FortiGate all support SAML authentication&lt;sup id=&#34;fnref:36&#34;&gt;&lt;a href=&#34;#fn:36&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;36&lt;/a&gt;&lt;/sup&gt;. But LDAP stays wired in for authorization: SAML establishes who you are, while group-to-policy mapping, user-to-IP mapping, and similar functions still query AD or LDAP. Removing LDAP from VPN infrastructure means rearchitecting authorization, not just swapping the authentication protocol.&lt;/p&gt;
&lt;p&gt;Linux infrastructure has the deepest coupling. SSSD abstracts LDAP from applications but itself connects over LDAP, or to AD via the LDAP protocol. PAM and NSS resolve users and groups against LDAP-backed directories. FreeIPA, Red Hat&amp;rsquo;s recommended path, runs 389 DS and the LDAP protocol internally&lt;sup id=&#34;fnref3:7&#34;&gt;&lt;a href=&#34;#fn:7&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;7&lt;/a&gt;&lt;/sup&gt;. You can abstract LDAP behind SSSD, but you cannot remove it from the Linux identity stack without moving to local-only authentication or a newer alternative such as Kanidm, which now ships a read-only LDAP gateway and has matured past its early releases, though its scope and adoption remain narrower than the incumbents&lt;sup id=&#34;fnref:37&#34;&gt;&lt;a href=&#34;#fn:37&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;37&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Enterprise printers are the most overlooked dependency. HP, Xerox, and Ricoh multifunction devices use LDAP for user authentication, address-book lookups, and scan-to-email. They store bind credentials in firmware, often with excessive privileges, and generally support neither SAML nor OIDC. Penetration testers routinely run LDAP pass-back attacks against these devices to capture the stored credentials&lt;sup id=&#34;fnref:38&#34;&gt;&lt;a href=&#34;#fn:38&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;38&lt;/a&gt;&lt;/sup&gt;. The hardware cannot be upgraded to modern protocols and runs on five-to-ten-year replacement cycles.&lt;/p&gt;
&lt;p&gt;SAP and Oracle embed LDAP at the connector, middleware, and authentication layers. SAP HANA supports LDAP authentication natively, SAP CUA synchronizes users between AD or LDAP and SAP, and SAP BusinessObjects uses LDAP as a primary authentication method; S/4HANA adds SAML 2.0 without removing LDAP&lt;sup id=&#34;fnref:39&#34;&gt;&lt;a href=&#34;#fn:39&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;39&lt;/a&gt;&lt;/sup&gt;. SAP&amp;rsquo;s maintenance commitment runs to 2040&lt;sup id=&#34;fnref2:15&#34;&gt;&lt;a href=&#34;#fn:15&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;15&lt;/a&gt;&lt;/sup&gt;. Oracle Internet Directory remains a core component of Oracle&amp;rsquo;s on-premises identity stack&lt;sup id=&#34;fnref1:23&#34;&gt;&lt;a href=&#34;#fn:23&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;23&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;No major vendor (SAP, Oracle, Cisco, Palo Alto Networks, Fortinet, or Microsoft) has announced plans to remove LDAP. The pattern is additive: modern protocols are offered alongside LDAP, not as replacements for it&lt;sup id=&#34;fnref1:13&#34;&gt;&lt;a href=&#34;#fn:13&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;13&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;h3 id=&#34;3-what-actually-displaces-ldap-binds-today&#34;&gt;3. What actually displaces LDAP binds today&lt;/h3&gt;
&lt;p&gt;The replacement landscape splits cleanly by application category.&lt;/p&gt;
&lt;p&gt;OIDC and OAuth 2.0 are the default for new application development. Every major identity provider (Entra ID, Okta, Google, Keycloak) treats OIDC as its preferred authentication protocol&lt;sup id=&#34;fnref1:16&#34;&gt;&lt;a href=&#34;#fn:16&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;16&lt;/a&gt;&lt;/sup&gt;, covering web apps, single-page apps, mobile, and API authorization. The limitation is fundamental: OIDC issues identity tokens and delegated authorization, but provides no general-purpose directory query. Organizations still need a directory behind the OIDC provider. OIDC replaces the LDAP bind for application login; it does not replace LDAP as a user and group store.&lt;/p&gt;
&lt;p&gt;SAML 2.0 is steady but no longer growing for new deployments. Most organizations run SAML and OIDC side by side through one provider. SAML still leads in hub-and-spoke federations (academic, government, large business-to-business) and in regulated settings that value rich attribute assertions. The reality is coexistence, not replacement.&lt;/p&gt;
&lt;p&gt;FIDO2 and passkeys show the fastest adoption. Per FIDO Alliance research, 87% of surveyed US and UK enterprises with 500 or more employees had deployed passkeys or were rolling them out for employee sign-in, in a survey conducted in late 2024&lt;sup id=&#34;fnref1:24&#34;&gt;&lt;a href=&#34;#fn:24&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;24&lt;/a&gt;&lt;/sup&gt;. Microsoft made new Microsoft accounts passwordless by default in May 2025&lt;sup id=&#34;fnref:40&#34;&gt;&lt;a href=&#34;#fn:40&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;40&lt;/a&gt;&lt;/sup&gt;, and NIST SP 800-63B Revision 4, finalized in mid-2025, requires verifiers to offer at least one phishing-resistant option at AAL2&lt;sup id=&#34;fnref:41&#34;&gt;&lt;a href=&#34;#fn:41&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;41&lt;/a&gt;&lt;/sup&gt;. But passkeys sit alongside LDAP rather than replacing it: they replace credential verification, while the directory storing user records and group memberships, typically AD or LDAP, remains.&lt;/p&gt;
&lt;p&gt;Kerberos is still the on-premises Windows backbone, tightly bound to AD&amp;rsquo;s LDAP layer. Microsoft Entra Kerberos bridges cloud and ground by issuing Kerberos tickets from the cloud for FIDO2 and passwordless users reaching on-premises resources, so passkeys can be adopted without abandoning Kerberos&lt;sup id=&#34;fnref:42&#34;&gt;&lt;a href=&#34;#fn:42&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;42&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Service-mesh mTLS (Istio, Linkerd, Consul) replaces the old pattern of services sharing an LDAP service-account credential for backend authentication. Each service gets a short-lived X.509 certificate tied to its Kubernetes ServiceAccount, which removes shared secrets&lt;sup id=&#34;fnref1:17&#34;&gt;&lt;a href=&#34;#fn:17&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;17&lt;/a&gt;&lt;/sup&gt;. This is standard in containerized environments, but it does not extend to user authentication or directory queries.&lt;/p&gt;
&lt;p&gt;The gaps are stark. Network device authentication, enterprise printers, legacy Unix PAM, and ad-hoc directory queries have no standardized LDAP replacement. OIDC and SAML do not speak to switches, printers, or NAS appliances, and no pull-based cloud directory-query protocol equivalent to an LDAP search exists.&lt;/p&gt;
&lt;h3 id=&#34;4-the-authorization-gap-is-harder-than-the-authentication-gap&#34;&gt;4. The authorization gap is harder than the authentication gap&lt;/h3&gt;
&lt;p&gt;Replacing LDAP for authentication is largely solved. Replacing the &amp;ldquo;query LDAP for group membership, then make an access decision&amp;rdquo; pattern is not.&lt;/p&gt;
&lt;p&gt;SCIM 2.0 has reached broad adoption for user and group provisioning across the major identity providers, but it is push-based with eventual consistency: sync cycles typically run 20 to 60 minutes&lt;sup id=&#34;fnref:43&#34;&gt;&lt;a href=&#34;#fn:43&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;43&lt;/a&gt;&lt;/sup&gt;. (A widely repeated claim that Gartner found 80% of large enterprises use SCIM does not trace to any Gartner publication, so we do not rely on it.) Microsoft has added inbound SCIM 2.0 provisioning APIs for Entra ID&lt;sup id=&#34;fnref:44&#34;&gt;&lt;a href=&#34;#fn:44&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;44&lt;/a&gt;&lt;/sup&gt;. SCIM still cannot answer an arbitrary &lt;code&gt;(memberOf=cn=X)&lt;/code&gt; filter, handles nested groups inconsistently across vendors, and offers no equivalent to an ad-hoc directory search.&lt;/p&gt;
&lt;p&gt;Open Policy Agent reached CNCF Graduated status in 2021&lt;sup id=&#34;fnref:45&#34;&gt;&lt;a href=&#34;#fn:45&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;45&lt;/a&gt;&lt;/sup&gt; and runs in production at Netflix, Goldman Sachs, and Pinterest&lt;sup id=&#34;fnref:46&#34;&gt;&lt;a href=&#34;#fn:46&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;46&lt;/a&gt;&lt;/sup&gt;. It can replace LDAP group-based authorization by evaluating group claims carried in OIDC or SAML tokens. But in August 2025 Apple hired OPA&amp;rsquo;s core maintainers from Styra, and Styra&amp;rsquo;s commercial products are being wound down, which raises real questions about the project&amp;rsquo;s commercial roadmap&lt;sup id=&#34;fnref1:28&#34;&gt;&lt;a href=&#34;#fn:28&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;28&lt;/a&gt;&lt;/sup&gt;. AWS Cedar, the language behind Amazon Verified Permissions, benchmarks 42 to 60 times faster than OPA&amp;rsquo;s Rego and adds formal verification, but has a smaller community and an AWS-centric design&lt;sup id=&#34;fnref1:26&#34;&gt;&lt;a href=&#34;#fn:26&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;26&lt;/a&gt;&lt;/sup&gt;. OpenFGA, which originated at Auth0 and Okta and reached CNCF Incubating status in late 2025, is gaining ground for relationship-based access control&lt;sup id=&#34;fnref1:27&#34;&gt;&lt;a href=&#34;#fn:27&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;27&lt;/a&gt;&lt;/sup&gt;. The policy-engine space is genuinely fragmented.&lt;/p&gt;
&lt;p&gt;The industry is moving toward hybrid models that pair role-based assignments with attribute-based policy for context (device posture, location, risk). Role explosion, where an organization accumulates more roles than users, is the usual reason teams push past simple LDAP group-based RBAC.&lt;/p&gt;
&lt;p&gt;The hardest unsolved problem is coherent authorization across hybrid environments. Cloud apps receive group claims in OIDC tokens; on-premises apps query LDAP or AD directly; sync lag between cloud providers and on-premises AD creates brief inconsistencies; group-nesting behavior differs between environments. The OpenID AuthZEN working group is standardizing an externalized authorization API, but adoption is early&lt;sup id=&#34;fnref1:18&#34;&gt;&lt;a href=&#34;#fn:18&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;18&lt;/a&gt;&lt;/sup&gt;. No universal standard for real-time cross-environment authorization queries exists today.&lt;/p&gt;
&lt;h3 id=&#34;5-directory-alternatives-all-carry-tradeoffs&#34;&gt;5. Directory alternatives all carry tradeoffs&lt;/h3&gt;
&lt;p&gt;No single product replaces LDAP and AD without giving something up.&lt;/p&gt;
&lt;p&gt;For Microsoft-centric enterprises, Entra ID is the strategic direction, with more than 610 million monthly active users by Microsoft&amp;rsquo;s most recent public figure, reported in 2023&lt;sup id=&#34;fnref:47&#34;&gt;&lt;a href=&#34;#fn:47&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;47&lt;/a&gt;&lt;/sup&gt;, and customers including Toyota, NHS England, and the US Department of Veterans Affairs&lt;sup id=&#34;fnref:48&#34;&gt;&lt;a href=&#34;#fn:48&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;48&lt;/a&gt;&lt;/sup&gt;. But Entra ID does not serve LDAP natively. Organizations that need LDAP compatibility deploy Entra Domain Services, whose Standard tier runs about $109.50 per month, with one-way sync from Entra ID, no Domain Admin rights, and no way to pause it once enabled&lt;sup id=&#34;fnref:49&#34;&gt;&lt;a href=&#34;#fn:49&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;49&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref:50&#34;&gt;&lt;a href=&#34;#fn:50&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;50&lt;/a&gt;&lt;/sup&gt;. At $6 per user per month for P1 and $9 for P2&lt;sup id=&#34;fnref:51&#34;&gt;&lt;a href=&#34;#fn:51&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;51&lt;/a&gt;&lt;/sup&gt;, a 10,000-seat deployment runs $60,000 to $90,000 per year in Entra ID licensing before Domain Services.&lt;/p&gt;
&lt;p&gt;For cross-platform environments, JumpCloud offers the strongest cloud LDAP story: a genuine hosted LDAP service rather than a proxy, with native device management across macOS, Windows, and Linux&lt;sup id=&#34;fnref1:19&#34;&gt;&lt;a href=&#34;#fn:19&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;19&lt;/a&gt;&lt;/sup&gt;. Its published per-product pricing runs from about $9 to $15 per user per month, with bundled platform packages quoted on request&lt;sup id=&#34;fnref:52&#34;&gt;&lt;a href=&#34;#fn:52&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;52&lt;/a&gt;&lt;/sup&gt;; linear per-user pricing is the main constraint at large scale. Okta dominates enterprise SSO, trusted by about two-thirds of the Fortune 100&lt;sup id=&#34;fnref:53&#34;&gt;&lt;a href=&#34;#fn:53&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;53&lt;/a&gt;&lt;/sup&gt;, but its LDAP Interface supports only BIND, UNBIND, and SEARCH&lt;sup id=&#34;fnref1:20&#34;&gt;&lt;a href=&#34;#fn:20&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;20&lt;/a&gt;&lt;/sup&gt;, which makes it a compatibility shim, not a real LDAP server.&lt;/p&gt;
&lt;p&gt;For Linux-heavy environments, FreeIPA and Red Hat IdM remain the best open-source option, with full 389 DS-backed LDAP, Kerberos, and centralized management at no cost beyond a RHEL subscription, and documented tuning to roughly 100,000 users&lt;sup id=&#34;fnref:54&#34;&gt;&lt;a href=&#34;#fn:54&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;54&lt;/a&gt;&lt;/sup&gt;. But FreeIPA has no SaaS edition and does not natively provide OIDC or SAML to applications (it fronts those with Keycloak), and it treats Windows and macOS as second-class&lt;sup id=&#34;fnref4:7&#34;&gt;&lt;a href=&#34;#fn:7&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;7&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;PingDirectory is the least-discussed but arguably most capable enterprise LDAP server, built for hundreds of millions of identities with full LDAPv3, bidirectional AD sync, and SCIM 2.0&lt;sup id=&#34;fnref:55&#34;&gt;&lt;a href=&#34;#fn:55&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;55&lt;/a&gt;&lt;/sup&gt;. Ping does not publish a list price; it sells through enterprise quotes, so the entry figures that circulate are third-party estimates rather than published rates.&lt;/p&gt;
&lt;p&gt;AWS Managed Microsoft AD provides actual Microsoft AD in the cloud at roughly $88 per month for the Standard edition and $292 per month for Enterprise, per region&lt;sup id=&#34;fnref:56&#34;&gt;&lt;a href=&#34;#fn:56&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;56&lt;/a&gt;&lt;/sup&gt;, suitable for lift-and-shift. Google Secure LDAP exposes Cloud Identity and Workspace over LDAP, subject to daily query quotas that can constrain high-volume use&lt;sup id=&#34;fnref:57&#34;&gt;&lt;a href=&#34;#fn:57&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;57&lt;/a&gt;&lt;/sup&gt;. Neither is an identity platform; both are LDAP endpoints for legacy compatibility.&lt;/p&gt;
&lt;h3 id=&#34;6-cloud-deployment-forces-hard-architectural-choices&#34;&gt;6. Cloud deployment forces hard architectural choices&lt;/h3&gt;
&lt;p&gt;All three major clouds support LDAP-dependent workloads, and their guidance converges on one message: LDAP in the cloud is a bridge, not a destination.&lt;/p&gt;
&lt;p&gt;AWS recommends Managed Microsoft AD for most scenarios, with two or more domain controllers across availability zones. Its best-practice documentation warns that broad LDAP queries across tens of thousands of objects cause CPU hot-spotting on individual domain controllers&lt;sup id=&#34;fnref:58&#34;&gt;&lt;a href=&#34;#fn:58&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;58&lt;/a&gt;&lt;/sup&gt;, and that reaching an on-premises directory over Direct Connect adds latency and a network dependency, so a connectivity failure can cut authentication entirely&lt;sup id=&#34;fnref:59&#34;&gt;&lt;a href=&#34;#fn:59&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;59&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Microsoft positions Entra Domain Services as enabling &amp;ldquo;AD minimization,&amp;rdquo; a bridge for legacy workloads during modernization rather than a long-term architecture&lt;sup id=&#34;fnref3:10&#34;&gt;&lt;a href=&#34;#fn:10&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;10&lt;/a&gt;&lt;/sup&gt;. Google&amp;rsquo;s guidance is similar: to let applications authenticate over LDAP, &amp;ldquo;you can expose or replicate an on-premises LDAP directory to Google Cloud or you can extend your Active Directory to Google Cloud&amp;rdquo;&lt;sup id=&#34;fnref:60&#34;&gt;&lt;a href=&#34;#fn:60&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;60&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Blast radius is the defining operational concern. When a cloud-hosted directory goes down, every dependent system loses authentication at once. GitLab states it plainly: &amp;ldquo;If your configured LDAP provider and/or endpoint is offline or otherwise unreachable by GitLab, no LDAP user is able to authenticate and sign-in&amp;rdquo;&lt;sup id=&#34;fnref:61&#34;&gt;&lt;a href=&#34;#fn:61&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;61&lt;/a&gt;&lt;/sup&gt;. Mitigation means multi-AZ deployment at minimum, multi-region replicas for critical workloads, and credential caching where the architecture allows.&lt;/p&gt;
&lt;p&gt;The most resilient hybrid pattern places read-only replicas in each cloud region for authentication queries, with writes directed to a primary on-premises master. That cuts latency, removes the network dependency for reads, and contains blast radius to a region. Identity orchestration layers (Strata&amp;rsquo;s Maverics, named in Gartner&amp;rsquo;s June 2025 IAM technical-debt research&lt;sup id=&#34;fnref1:25&#34;&gt;&lt;a href=&#34;#fn:25&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;25&lt;/a&gt;&lt;/sup&gt;, along with Microsoft Entra Connect and Okta&amp;rsquo;s AD agents) bridge the synchronization gap between cloud and on-premises stores.&lt;/p&gt;
&lt;h3 id=&#34;7-migration-projects-run-longer-and-cost-more-than-anyone-budgets&#34;&gt;7. Migration projects run longer and cost more than anyone budgets&lt;/h3&gt;
&lt;p&gt;The gap between vendor migration narratives and practitioner experience is wide. A focused IAM migration for a single system can finish in weeks. But coverage of Gartner&amp;rsquo;s 2025 IAM Summit describes application onboarding backlogs of 600-plus applications with projected timelines beyond eight years, and only about 10% of organizations provisioning new access within two days&lt;sup id=&#34;fnref1:22&#34;&gt;&lt;a href=&#34;#fn:22&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;22&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;The failure modes are predictable and consistently underestimated. Application discovery gaps top the list: shadow IT and line-of-business applications, which by one industry measure account for about 84% of applications sitting outside IT&amp;rsquo;s direct control&lt;sup id=&#34;fnref:62&#34;&gt;&lt;a href=&#34;#fn:62&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;62&lt;/a&gt;&lt;/sup&gt;, are routinely missed in dependency audits. No purpose-built tool maps enterprise-wide LDAP dependencies; teams combine network monitoring (ports 389, 636, 3268), AD audit logging (Windows Event IDs 2887 and 2889 for insecure binds&lt;sup id=&#34;fnref:63&#34;&gt;&lt;a href=&#34;#fn:63&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;63&lt;/a&gt;&lt;/sup&gt;), and manual inventory. Windows Server 2025&amp;rsquo;s default LDAP-signing enforcement became an unplanned discovery mechanism by breaking applications that relied on insecure binds&lt;sup id=&#34;fnref2:8&#34;&gt;&lt;a href=&#34;#fn:8&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;8&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;p&gt;Hardcoded bind credentials pervade legacy environments. Printer firmware, middleware, custom applications, and monitoring systems store service-account passwords that violate rotation policy, often with excessive privileges. Printer service accounts found with Domain Admin rights are a recurring penetration-testing finding&lt;sup id=&#34;fnref1:38&#34;&gt;&lt;a href=&#34;#fn:38&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;38&lt;/a&gt;&lt;/sup&gt;. Migration means locating and rotating every embedded credential, which can take months.&lt;/p&gt;
&lt;p&gt;Schema dependencies surface during testing, not planning. Custom schemas, non-standard attributes, and deep nested-group hierarchies accumulated over years resist clean migration, and Red Hat&amp;rsquo;s own documentation notes that IdM differs from a generic LDAP directory in schema support and tree structure&lt;sup id=&#34;fnref5:7&#34;&gt;&lt;a href=&#34;#fn:7&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;7&lt;/a&gt;&lt;/sup&gt;. Protocol mismatches compound it: applications using NTLM, LDAPv2, or anonymous binds collide with modern security requirements.&lt;/p&gt;
&lt;p&gt;Cost data specific to LDAP migrations is not published by any major analyst. As a proxy, the CloudBees 2025 DevOps Migration Index reports an average cost overrun of about $315,000 per migration project, with the average project running about 18% over budget and 57% of enterprises spending more than $1 million&lt;sup id=&#34;fnref1:21&#34;&gt;&lt;a href=&#34;#fn:21&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;21&lt;/a&gt;&lt;/sup&gt;. By analogy with comparable identity programs, a full enterprise LDAP migration touching hundreds of applications, network infrastructure, and endpoints plausibly lands in the high six to low seven figures for a large organization, but no documented case study confirms a specific range. Large-scale public case studies of complete LDAP elimination effectively do not exist, and that absence is itself a finding.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;recommendations-for-security-and-risk-management-leaders&#34;&gt;Recommendations for Security and Risk Management Leaders&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Freeze LDAP at the on-premises boundary, and mandate cloud-native identity for everything new.&lt;/strong&gt; This is not a compromise; it is the only approach that matches real portfolios. Extending LDAP into the cloud works for lift-and-shift but widens blast radius without reducing debt. Full migration is correct in direction but, at eight-plus-year timelines, is a program, not a project.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Deploy an identity orchestration layer to bridge existing LDAP to cloud workloads.&lt;/strong&gt; Strata Maverics, Microsoft Entra Connect, Okta&amp;rsquo;s AD agents, or an equivalent should mediate between on-premises LDAP and cloud-native protocols, with SCIM for provisioning and OIDC or SAML for modern application authentication&lt;sup id=&#34;fnref2:25&#34;&gt;&lt;a href=&#34;#fn:25&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;25&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Instrument directories before you migrate.&lt;/strong&gt; Turn on audit logging, watch Event IDs 2887 and 2889 for insecure binds&lt;sup id=&#34;fnref1:63&#34;&gt;&lt;a href=&#34;#fn:63&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;63&lt;/a&gt;&lt;/sup&gt;, and monitor ports 389, 636, and 3268 to map the real dependency surface. You cannot migrate what you have not discovered.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Find and rotate every hardcoded bind credential, starting with printers and middleware.&lt;/strong&gt; Treat any service account with excessive directory privileges, especially one stored on a multifunction printer, as an active exposure&lt;sup id=&#34;fnref2:38&#34;&gt;&lt;a href=&#34;#fn:38&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;38&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Build a multi-year application migration backlog, prioritized by security risk and business value.&lt;/strong&gt; Re-point applications to OIDC or SAML where you can. Accept that network gear, printers, and legacy Unix will not move on that schedule.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;For cloud-hosted directories, design for blast radius from day one.&lt;/strong&gt; Use read-only replicas per region for authentication reads, direct writes to a primary master, deploy across availability zones at minimum, and cache credentials where the architecture allows&lt;sup id=&#34;fnref1:61&#34;&gt;&lt;a href=&#34;#fn:61&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;61&lt;/a&gt;&lt;/sup&gt;&lt;sup id=&#34;fnref1:59&#34;&gt;&lt;a href=&#34;#fn:59&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;59&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Plan for permanent coexistence, not a finish line.&lt;/strong&gt; Assume some LDAP infrastructure persists past 2030. Organizations that plan for coexistence make better architectural decisions than those chasing an elimination date that does not yet exist.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;h2 id=&#34;market-outlook&#34;&gt;Market Outlook&lt;/h2&gt;
&lt;p&gt;Practitioner consensus has settled on a two-phase strategy: freeze LDAP at the on-premises boundary for existing investments, adopt cloud-native identity for all new workloads, and migrate high-value applications selectively over a multi-year horizon. Cloud-native and smaller organizations have gone cloud-only successfully. Large enterprises with network infrastructure, printers, ERP, and custom applications find complete migration multi-generational.&lt;/p&gt;
&lt;p&gt;The real disagreement is about timeline and finality. Optimists, mostly cloud identity vendors and consultancies, expect LDAP to be marginalized within three to five years for most workloads. Practitioners managing physical infrastructure counter that LDAP&amp;rsquo;s moat is not applications, which can be re-pointed to OIDC, but infrastructure-level authentication: Linux SSH, network gear, NAS and SAN storage, and printers, where no standardized replacement exists. JumpCloud frames the practitioner view bluntly: the world is moving to the cloud, but a large part of the local environment gets left behind.&lt;/p&gt;
&lt;p&gt;The analyst frameworks back the freeze-and-bridge posture. Gartner&amp;rsquo;s June 2025 IAM technical-debt research&lt;sup id=&#34;fnref3:25&#34;&gt;&lt;a href=&#34;#fn:25&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;25&lt;/a&gt;&lt;/sup&gt; and KuppingerCole&amp;rsquo;s Identity Fabric model&lt;sup id=&#34;fnref:64&#34;&gt;&lt;a href=&#34;#fn:64&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;64&lt;/a&gt;&lt;/sup&gt; both treat LDAP as one protocol within a composable identity architecture rather than a standalone strategic platform. The recommended shape is consistent: an identity orchestration layer mediating between on-premises LDAP and cloud-native protocols, SCIM for provisioning, and OIDC or SAML for modern applications.&lt;/p&gt;
&lt;p&gt;The honest assessment is that LDAP&amp;rsquo;s decline is real but slow, and its floor is higher than the cloud-only narrative admits. The protocol has stopped evolving, its standards are frozen, and its perimeter is shrinking. None of that makes it disappear from the switch closet, the printer, or the Linux fleet this decade. The organizations that come out ahead will be the ones that stop arguing about whether LDAP is dead and start managing it as the long-lived dependency it has become.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;key-sources&#34;&gt;Key Sources&lt;/h2&gt;
&lt;p&gt;Every specific figure, date, version, and quotation above links to its primary source below.&lt;/p&gt;
&lt;div class=&#34;footnotes&#34; role=&#34;doc-endnotes&#34;&gt;
&lt;hr&gt;
&lt;ol&gt;
&lt;li id=&#34;fn:1&#34;&gt;
&lt;p&gt;IETF Datatracker, &lt;a href=&#34;https://datatracker.ietf.org/wg/ldapbis/charter/&#34;&gt;LDAP (v3) Revision (ldapbis), concluded working group&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:1&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:2&#34;&gt;
&lt;p&gt;OpenLDAP, &lt;a href=&#34;https://www.openldap.org/software/release/changes_lts.html&#34;&gt;2.6.13 LTS release changes (released 2026-03-09)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:2&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:2&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:3&#34;&gt;
&lt;p&gt;OpenLDAP, &lt;a href=&#34;https://www.openldap.org/project/&#34;&gt;project page (four-member core team)&lt;/a&gt;; Symas, &lt;a href=&#34;https://www.symas.com/symas-about&#34;&gt;about (OpenLDAP funding and engineering)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:3&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:3&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:4&#34;&gt;
&lt;p&gt;Red Hat, &lt;a href=&#34;https://access.redhat.com/solutions/3816971&#34;&gt;the openldap-servers package was removed in RHEL 8 and 9&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:4&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:4&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:5&#34;&gt;
&lt;p&gt;SUSE, &lt;a href=&#34;https://www.suse.com/releasenotes/x86_64/SUSE-SLES/15-SP4/index.html&#34;&gt;SLES 15 SP4 release notes (OpenLDAP server in the Legacy module, removed in 15 SP4)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:5&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:5&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:6&#34;&gt;
&lt;p&gt;Fedora Project, &lt;a href=&#34;https://fedoraproject.org/wiki/Changes/389_Directory_Server_3.1.3&#34;&gt;389 Directory Server 3.1.3 drops BerkeleyDB for LMDB&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:6&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:6&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:7&#34;&gt;
&lt;p&gt;FreeIPA, &lt;a href=&#34;https://www.freeipa.org/page/Directory_Server&#34;&gt;Directory Server (built on 389 DS)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:7&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:7&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref2:7&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref3:7&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref4:7&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref5:7&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:8&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/ldap-signing&#34;&gt;LDAP signing required by default on new Windows Server 2025 deployments&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:8&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:8&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref2:8&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:9&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/windows-server/get-started/whats-new-windows-server-2025&#34;&gt;what&amp;rsquo;s new in Windows Server 2025 (LDAP channel binding, TLS 1.3, RC4 deprecation, performance counters)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:9&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:9&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:10&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/domain-services/overview&#34;&gt;Microsoft Entra Domain Services overview (&amp;ldquo;transitional capability,&amp;rdquo; &amp;ldquo;AD minimization,&amp;rdquo; one-way sync)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:10&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:10&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref2:10&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref3:10&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:11&#34;&gt;
&lt;p&gt;Docebo, &lt;a href=&#34;https://help.docebo.com/hc/en-us/articles/19751037466130-Deprecations-of-features-and-integrations&#34;&gt;deprecations of features and integrations (Docebo for LDAP deprecated 2025-08-20)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:11&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:12&#34;&gt;
&lt;p&gt;Barracuda, &lt;a href=&#34;https://campus.barracuda.com/product/cloudcontrol/doc/167976029/new-requirements-for-ldap-authentication/&#34;&gt;new requirements for LDAP authentication (no new insecure LDAP connections as of 2025-01-15)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:12&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:13&#34;&gt;
&lt;p&gt;Palo Alto Networks, &lt;a href=&#34;https://docs.paloaltonetworks.com/ngfw/administration/authentication/configure-ldap-authentication&#34;&gt;configure LDAP authentication (PAN-OS)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:13&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:13&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:14&#34;&gt;
&lt;p&gt;Juniper Mist Access Assurance, &lt;a href=&#34;https://www.juniper.net/documentation/us/en/software/mist/mist-access/topics/task/mist-access-identity-providers.html&#34;&gt;LDAP as an identity source&lt;/a&gt;; Cisco ISE and Aruba ClearPass likewise document LDAP as a primary identity source.&amp;#160;&lt;a href=&#34;#fnref:14&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:14&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:15&#34;&gt;
&lt;p&gt;SAP, &lt;a href=&#34;https://support.sap.com/en/release-upgrade-maintenance/maintenance-information/maintenance-strategy/s4hana-business-suite7.html&#34;&gt;maintenance strategy: mainstream maintenance for Business Suite 7 to 2027, extended to 2030, innovation commitment for S/4HANA to 2040&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:15&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:15&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref2:15&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:16&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/architecture/auth-oidc&#34;&gt;OpenID Connect on the Microsoft identity platform (OIDC as the recommended protocol for new apps)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:16&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:16&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:17&#34;&gt;
&lt;p&gt;Istio, &lt;a href=&#34;https://istio.io/latest/docs/concepts/security/&#34;&gt;security concepts (X.509 workload identity tied to the Kubernetes ServiceAccount, short-lived auto-rotated certificates)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:17&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:17&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:18&#34;&gt;
&lt;p&gt;OpenID Foundation, &lt;a href=&#34;https://openid.net/wg/authzen/&#34;&gt;AuthZEN working group (externalized authorization API)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:18&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:18&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:19&#34;&gt;
&lt;p&gt;JumpCloud, &lt;a href=&#34;https://jumpcloud.com/platform/ldap&#34;&gt;cloud LDAP (hosted LDAP as a service)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:19&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:19&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:20&#34;&gt;
&lt;p&gt;Okta, &lt;a href=&#34;https://help.okta.com/oie/en-us/content/topics/directory/ldap-interface-limitations.htm&#34;&gt;LDAP Interface limitations (BIND, UNBIND, and SEARCH only)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:20&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:20&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:21&#34;&gt;
&lt;p&gt;CloudBees, &lt;a href=&#34;https://www.cloudbees.com/newsroom/cloudbees-first-devops-migration-index&#34;&gt;2025 DevOps Migration Index (average cost overrun about $315,000 per enterprise; average project about 18% over budget; 57% of enterprises spent more than $1 million)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:21&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:21&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:22&#34;&gt;
&lt;p&gt;Gartner IAM Summit 2025, as reported: &lt;a href=&#34;https://www.zluri.com/blog/what-gartner-iam-2025-reveals-about-the-future-of-identity-governance&#34;&gt;application onboarding backlogs of 600-plus apps, 8-plus year timelines, only about 10% provision within two days&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:22&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:22&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:23&#34;&gt;
&lt;p&gt;Oracle, &lt;a href=&#34;https://docs.oracle.com/en/middleware/idm/&#34;&gt;Identity Management documentation (Oracle Internet Directory)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:23&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:23&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:24&#34;&gt;
&lt;p&gt;FIDO Alliance, &lt;a href=&#34;https://fidoalliance.org/new-fido-alliance-research-shows-87-percent-us-uk-workforces-are-deploying-passkeys-for-employee-sign-ins/&#34;&gt;87% of surveyed US and UK workforces are deploying passkeys for employee sign-ins (research published February 2025, survey conducted September 2024)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:24&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:24&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:25&#34;&gt;
&lt;p&gt;Strata Identity, &lt;a href=&#34;https://www.strata.io/resources/news/gartner-reduce-iam-technical-debt/&#34;&gt;Maverics named a sample vendor in Gartner, &amp;ldquo;Reduce IAM Technical Debt&amp;rdquo; (June 23, 2025)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:25&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:25&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref2:25&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref3:25&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:26&#34;&gt;
&lt;p&gt;AWS Security Blog, &lt;a href=&#34;https://aws.amazon.com/blogs/security/migrating-from-open-policy-agent-to-amazon-verified-permissions/&#34;&gt;Cedar benchmarks 42 to 60 times faster than Rego and adds formal verification&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:26&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:26&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:27&#34;&gt;
&lt;p&gt;CNCF, &lt;a href=&#34;https://www.cncf.io/blog/2025/11/11/openfga-becomes-a-cncf-incubating-project/&#34;&gt;OpenFGA (Auth0 and Okta origin, relationship-based access control) becomes a CNCF incubating project (November 11, 2025)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:27&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:27&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:28&#34;&gt;
&lt;p&gt;Oso, &lt;a href=&#34;https://www.osohq.com/post/opa-maintainers-join-apple-oss-community-to-maintain-styra-products&#34;&gt;OPA maintainers join Apple (August 2025); Styra products wound down&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:28&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:28&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:29&#34;&gt;
&lt;p&gt;OpenLDAP, &lt;a href=&#34;https://www.openldap.org/software/roadmap.html&#34;&gt;release road map: 2.7 native RADIUS server and scoped password policies&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:29&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:29&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:30&#34;&gt;
&lt;p&gt;389 Directory Server, &lt;a href=&#34;https://www.port389.org/docs/389ds/releases/release-3-1-3.html&#34;&gt;3.1.3 release notes (Cockpit console, JSON logging, connection handling)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:30&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:31&#34;&gt;
&lt;p&gt;SafeBreach Labs, &lt;a href=&#34;https://www.safebreach.com/blog/ldapnightmare-safebreach-labs-publishes-first-proof-of-concept-exploit-for-cve-2024-49113/&#34;&gt;&amp;ldquo;LDAPNightmare&amp;rdquo;: first proof-of-concept for CVE-2024-49113 (denial of service), published 2025-01-01&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:31&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:32&#34;&gt;
&lt;p&gt;NVD, &lt;a href=&#34;https://nvd.nist.gov/vuln/detail/CVE-2024-49112&#34;&gt;CVE-2024-49112 (Windows LDAP, CVSS 9.8 RCE; Windows Server 2019 through 2025 affected)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:32&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:33&#34;&gt;
&lt;p&gt;Red Hat Bugzilla, &lt;a href=&#34;https://bugzilla.redhat.com/show_bug.cgi?id=2091781&#34;&gt;CVE-2022-1949: 389-ds-base access-control bypass exposing password hashes&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:33&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:34&#34;&gt;
&lt;p&gt;RFC Editor, &lt;a href=&#34;https://www.rfc-editor.org/info/rfc4510/&#34;&gt;RFC 4510, LDAP technical specification road map (June 2006)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:34&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:35&#34;&gt;
&lt;p&gt;IETF Datatracker, &lt;a href=&#34;https://datatracker.ietf.org/doc/draft-bucksch-sasl-passkey/&#34;&gt;draft-bucksch-sasl-passkey (SASL Passkey, expired Internet-Draft)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:35&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:36&#34;&gt;
&lt;p&gt;Palo Alto Networks, &lt;a href=&#34;https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-user-authentication/set-up-external-authentication/set-up-saml-authentication&#34;&gt;GlobalProtect SAML authentication&lt;/a&gt;; Cisco Secure Client and Fortinet FortiGate also support SAML.&amp;#160;&lt;a href=&#34;#fnref:36&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:37&#34;&gt;
&lt;p&gt;Kanidm, &lt;a href=&#34;https://kanidm.github.io/kanidm/master/support.html&#34;&gt;project support and maturity (read-only LDAP gateway; past 1.0, v1.10.x by mid-2026)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:37&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:38&#34;&gt;
&lt;p&gt;Rapid7, &lt;a href=&#34;https://www.rapid7.com/blog/post/cve-2025-6081-konica-minolta-bizhub-pass-back-attack-vulnerability-not-fixed/&#34;&gt;LDAP pass-back attack against multifunction printers (CVE-2025-6081, Konica Minolta bizhub)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:38&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:38&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref2:38&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:39&#34;&gt;
&lt;p&gt;SAP Help Portal, &lt;a href=&#34;https://help.sap.com/docs/SAP_HANA_PLATFORM/b3ee5778bc2e4a089d3299b82ec762a7/868f8b988e2d42ccb89ccaf263cd9986.html&#34;&gt;SAP HANA LDAP authentication&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:39&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:40&#34;&gt;
&lt;p&gt;Microsoft Security, &lt;a href=&#34;https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/&#34;&gt;new Microsoft accounts are passwordless by default (May 1, 2025)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:40&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:41&#34;&gt;
&lt;p&gt;NIST SP 800-63B-4, &lt;a href=&#34;https://pages.nist.gov/800-63-4/sp800-63b.html&#34;&gt;verifiers shall offer at least one phishing-resistant option at AAL2 (finalized 2025)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:41&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:42&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/authentication/kerberos&#34;&gt;Microsoft Entra Kerberos issues cloud Kerberos tickets for passwordless access to on-premises resources&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:42&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:43&#34;&gt;
&lt;p&gt;Authgear, &lt;a href=&#34;https://www.authgear.com/post/what-is-scim-provisioning/&#34;&gt;SCIM provisioning is push-based and typically syncs every 20 to 60 minutes&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:43&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:44&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/app-provisioning/inbound-provisioning-api-concepts&#34;&gt;API-driven inbound provisioning with SCIM for Entra ID&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:44&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:45&#34;&gt;
&lt;p&gt;CNCF, &lt;a href=&#34;https://www.cncf.io/announcements/2021/02/04/cloud-native-computing-foundation-announces-open-policy-agent-graduation/&#34;&gt;Open Policy Agent graduation (February 4, 2021)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:45&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:46&#34;&gt;
&lt;p&gt;Open Policy Agent, &lt;a href=&#34;https://github.com/open-policy-agent/opa/blob/main/ADOPTERS.md&#34;&gt;ADOPTERS.md (Netflix, Goldman Sachs, Pinterest in production)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:46&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:47&#34;&gt;
&lt;p&gt;Microsoft FY23 Q4 earnings, as reported: &lt;a href=&#34;https://www.bigtechwire.com/2023/07/26/microsoft-entra-id-maus-linkedin-members/&#34;&gt;Entra ID monthly active users exceeded 610 million (2023 figure)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:47&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:48&#34;&gt;
&lt;p&gt;AppsRunTheWorld, &lt;a href=&#34;https://www.appsruntheworld.com/customers-database/products/view/microsoft-entra-id-formerly-azure-active-directory&#34;&gt;Microsoft Entra ID customers (Toyota, NHS England, US Department of Veterans Affairs)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:48&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:49&#34;&gt;
&lt;p&gt;Microsoft, &lt;a href=&#34;https://www.microsoft.com/en-us/security/pricing/microsoft-entra-ds&#34;&gt;Entra Domain Services pricing (Standard tier about $109.50 per month)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:49&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:50&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/domain-services/faqs&#34;&gt;Entra Domain Services FAQ (no Domain Admin rights, cannot be paused)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:50&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:51&#34;&gt;
&lt;p&gt;Microsoft, &lt;a href=&#34;https://www.microsoft.com/en-us/security/business/microsoft-entra-pricing&#34;&gt;Entra plans and pricing (P1 $6, P2 $9 per user per month)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:51&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:52&#34;&gt;
&lt;p&gt;JumpCloud, &lt;a href=&#34;https://jumpcloud.com/pricing&#34;&gt;pricing (per-product $9 to $15 per user per month; bundled platform packages quoted on request)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:52&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:53&#34;&gt;
&lt;p&gt;Okta, &lt;a href=&#34;https://www.okta.com/company/&#34;&gt;company (trusted by about two-thirds of the Fortune 100)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:53&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:54&#34;&gt;
&lt;p&gt;FreeIPA, &lt;a href=&#34;https://www.freeipa.org/page/V4/Performance_Improvements&#34;&gt;performance improvements and Red Hat IdM tuning to roughly 100,000 users&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:54&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:55&#34;&gt;
&lt;p&gt;Ping Identity, &lt;a href=&#34;https://www.pingidentity.com/en/product/pingdirectory.html&#34;&gt;PingDirectory (LDAP v3, bidirectional AD sync, SCIM 2.0, hundreds of millions of entries)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:55&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:56&#34;&gt;
&lt;p&gt;AWS, &lt;a href=&#34;https://aws.amazon.com/directoryservice/pricing/&#34;&gt;Directory Service pricing (Managed Microsoft AD about $88 Standard to about $292 Enterprise per month, per region)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:56&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:57&#34;&gt;
&lt;p&gt;Google Workspace, &lt;a href=&#34;https://knowledge.workspace.google.com/admin/apps/about-the-secure-ldap-service&#34;&gt;about the Secure LDAP service (daily query quotas)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:57&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:58&#34;&gt;
&lt;p&gt;AWS, &lt;a href=&#34;https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ms_ad_best_practices.html&#34;&gt;Managed Microsoft AD best practices (broad LDAP queries cause domain-controller CPU hot-spotting)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:58&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:59&#34;&gt;
&lt;p&gt;AWS, &lt;a href=&#34;https://docs.aws.amazon.com/whitepapers/latest/best-practices-deploying-amazon-workspaces/scenario-1-using-ad-connector-to-proxy-authentication-to-on-premises-active-directory-service.html&#34;&gt;best practices for deploying Amazon WorkSpaces (an on-premises directory over Direct Connect adds latency and a connectivity dependency)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:59&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:59&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:60&#34;&gt;
&lt;p&gt;Google Cloud, &lt;a href=&#34;https://docs.cloud.google.com/architecture/authenticating-corporate-users-in-a-hybrid-environment&#34;&gt;authenticating corporate users in a hybrid environment (expose, replicate, or extend AD to Google Cloud)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:60&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:61&#34;&gt;
&lt;p&gt;GitLab, &lt;a href=&#34;https://docs.gitlab.com/administration/auth/ldap/ldap-troubleshooting/&#34;&gt;LDAP troubleshooting (&amp;ldquo;no LDAP user is able to authenticate and sign-in&amp;rdquo; during a provider outage)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:61&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:61&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:62&#34;&gt;
&lt;p&gt;Zylo, &lt;a href=&#34;https://zylo.com/blog/saas-stats-it-strategy&#34;&gt;about 84% of applications sit outside IT&amp;rsquo;s direct responsibility&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:62&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:63&#34;&gt;
&lt;p&gt;Microsoft Learn, &lt;a href=&#34;https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/enable-ldap-signing-in-windows-server&#34;&gt;enable LDAP signing (Event IDs 2887 and 2889 for insecure binds)&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:63&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&amp;#160;&lt;a href=&#34;#fnref1:63&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li id=&#34;fn:64&#34;&gt;
&lt;p&gt;KuppingerCole&amp;rsquo;s Identity Fabric model, as discussed: &lt;a href=&#34;https://thehackernews.com/2025/11/beyond-iam-silos-why-identity-security.html&#34;&gt;LDAP as one protocol within a composable identity architecture&lt;/a&gt;.&amp;#160;&lt;a href=&#34;#fnref:64&#34; class=&#34;footnote-backref&#34; role=&#34;doc-backlink&#34;&gt;&amp;#x21a9;&amp;#xfe0e;&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
</description>
    </item>
    
  </channel>
</rss>
