Active Directory & LDAP integration for secure SSH authentication

LDAP with Ezeelogin enables centralized user authentication by integrating Ezeelogin with an LDAP directory service such as Microsoft Active Directory or OpenLDAP. Instead of managing local user accounts on the gateway, users authenticate using their existing LDAP credentials — simplifying user management, enforcing centralized password policies, and providing easier access control by syncing users and groups from the LDAP server.
directory.bind
status : synced
DirectoryAD / OpenLDAP
GatewayEzeelogin
prod-db-01
app-cluster-03
edge-router-12
Trusted by IT teams for

Centralized Authentication

Directory-Synced Access

Automatic LDAP Failover

Self-Hosted Deployment

Why teams turn on LDAP integration

Three problems every growing IT team runs into

If any of these sound familiar, LDAP integration in Ezeelogin was built specifically to remove them.

01

A new hire needs SSH access today. Are you creating yet another password to track?

Every gateway with its own local account is one more credential to issue, reset, and eventually forget about — and one more place a former employee's access can quietly linger.

Ezeelogin authenticates against the directory you already run. No new password, no separate account.

02

An employee is disabled in Active Directory. Can they still reach servers through an old gateway login?

If the SSH gateway keeps its own local accounts, disabling someone in AD doesn't touch that account — offboarding becomes a two-system checklist instead of one action.

Ezeelogin checks the directory live on every login, so a disabled directory account is blocked at the gateway immediately.

03

Your security policy says access follows one identity source. Can you actually show that?

Local gateway accounts, side password policies, and manually maintained permission lists all drift out of sync with the directory that's supposed to be the source of truth.

Group membership and password policy come from LDAP directly — the directory is the source of truth, provably.

Getting started

Bound to your directory in under 30 minutes

Self-hosted on your own infrastructure. No directory migration required.

Install Ezeelogin

Run the installer on any Linux server — typically under 10 minutes.

Bind to LDAP / AD

Point the LDAP URI at your directory over LDAP or LDAPS.

Map groups & sync

Set the login filter and map directory groups to Ezeelogin roles.

Users sign in as-is

Existing LDAP credentials work immediately — no new accounts to create.

Capabilities

Active Directory & OpenLDAP capabilities built for every directory setup

Hybrid, on-prem, cloud, single-site, or multi-site — every real-world Active Directory and LDAP deployment has a supported path here.

LDAP authentication without directory changes

Skip touching UNIX attributes on the directory entirely. Ezeelogin authenticates the web panel against LDAP and creates the matching backend SSH account itself.

Auto-create users

Directory-driven SSH access

Prefer full directory control over SSH login too? Configure PAM-LDAP so Active Directory or LDAP credentials govern both the panel and the remote server.

PAM-LDAP

Group mapping & login filters

Import only the directory users you intend to, map them to the right Ezeelogin user group, and gate entry with a dedicated login attribute for privileged access management.

Access control

Replica & automatic LDAP failover

List primary and replica LDAP or Active Directory URIs side by side. If the primary directory server goes dark, Ezeelogin fails over automatically.

High availability

Azure AD integration over secure LDAP

Bring Azure AD Domain Services in over LDAPS, with certificate-based encryption on every query between Ezeelogin and the directory.

Cloud identity

One credential, kept consistent

Change a password on the Active Directory or LDAP side, and the user's next Ezeelogin login re-syncs it automatically — no drift between systems.

Password sync

Security Notes

Securing your Active Directory / LDAP integration

encrypt

Use LDAPS, not plain LDAP

Query the directory over TLS so credentials and attributes never cross the wire in the clear.

restrict

Always set a login filter

Without one, any account in Active Directory or LDAP can reach the gateway. A dedicated group attribute keeps the door to the ones you’ve approved.

verify

Confirm group mapping after import

Reassigning a user’s group post-import is expected and will surface as a mismatch notice — that’s a confirmation, not an error.
Real scenarios

How IT teams use LDAP integration every day

Onboarding

A new hire starts on Monday and needs access to a dozen servers

Without Ezeelogin: create a local gateway account, set a password, and manually assign server permissions one at a time. With Ezeelogin: add them to the right directory group — access is granted the moment they log in with their existing credentials.

Outcome: Access provisioned in minutes, with zero new credentials to issue.

Offboarding

An employee resigns and is disabled in Active Directory that afternoon

Without Ezeelogin: someone still has to remember there’s a separate local gateway account to remove, on top of the directory change. With Ezeelogin: the directory disable takes effect at the next login attempt — there’s no second account to track down.

Outcome: Zero risk of lingering gateway access after offboarding.

Directory outage

The primary Active Directory server goes down mid-morning

Without Ezeelogin: every login depending on that directory is blocked until someone manually repoints it. With Ezeelogin: a configured replica LDAP URI is already on standby, and the gateway fails over to it automatically.

Outcome: Logins continue uninterrupted through the outage.

Directory support

Works with the directory service you already run

Active Directory

OpenLDAP

Azure AD (LDAPS)

Frequently Asked Questions

AD/LDAP integration questions, answered

LDAP with Ezeelogin enables centralized user authentication by integrating Ezeelogin with an LDAP directory service such as Microsoft Active Directory or OpenLDAP. Instead of managing local user accounts on the gateway, users authenticate using their existing LDAP credentials, which simplifies user management, enforces centralized password policies, and provides easier access control by syncing users and groups from the LDAP server.
Yes. Ezeelogin integrates with Azure AD Domain Services over secure LDAP (LDAPS), encrypting every query between the gateway and the directory.
Yes. Replica LDAP and Active Directory servers can be added as additional URIs, and Ezeelogin automatically fails over if the primary directory server becomes unreachable.
It is, provided LDAPS is used for encrypted queries and a login filter restricts access to an approved directory group — both are standard practice for privileged access management.

Bind your directory, keep your access rules.

One Active Directory or LDAP source decides who gets in. Ezeelogin decides what they can reach once they’re there. Self-hosted, up in under 30 minutes, 30-day free trial, no credit card required.

Trusted by organizations managing thousands of servers since 2009.