# LDAP/AD or Microsoft Entra for intranets | Vindula

> Understand the differences between the connectors and learn how to organize mapping, preview, synchronization, and the access lifecycle.

Source: https://vindula.ai/en/blog/ldap-ad-or-microsoft-entra-for-intranet

Integrations

# LDAP/AD or Microsoft Entra: how to connect the corporate directory to the intranet

Understand the differences between the connectors and learn how to organize mapping, preview, synchronization, and the access lifecycle.

Vindula

Vindula Team

 September 14, 2026

 8 min read

## Introduction: choosing a connector is only the beginning

When a company decides to connect its corporate directory to the intranet, the first question is usually technical: should we use LDAP/Active Directory or Microsoft Entra? It is an important question, but it does not solve the entire challenge. The source directory needs to match the organization's identity architecture, while the synchronization process must turn technical data into profiles that are useful for communication, human resources, and access to internal services.

LDAP, Active Directory, and Microsoft Entra are not interchangeable names. LDAP is a protocol widely used to query directory services. Traditional Active Directory is a directory platform usually maintained within company infrastructure and can be accessed through LDAP. Microsoft Entra, in turn, is Microsoft's cloud identity and access service and uses its own connection model.

The right decision is therefore not to select a familiar name, but to identify where the company keeps its trusted source for people, groups, and attributes. From there, the organization must design how that information will reach the intranet, be reviewed, and remain current over time.

## The real problem behind corporate directory integration

The central problem is not simply moving names and email addresses from one system to another. An intranet uses the people structure to build audiences, present directories, organize departments, support targeted communication, and control access to specific areas. If data arrives incomplete, duplicated, or without a clear update rule, the error spreads across several routines.

There is also a difference between a technical identity and an organizational profile. The directory may know the identifier, account, email, status, and groups, while the intranet may need job title, department, unit, location, manager, and other fields that business teams understand. Their names, formats, and values do not always match.

In larger organizations, the challenge increases because there are many units, frequent moves, and different data owners. The same person may change departments, report to a new manager, or have an account suspended. The integration needs to interpret these changes without requiring manual registration in every system. This is particularly relevant for an [intranet in enterprise organizations](/en/solutions/by-company-size/enterprise), where scale increases the cost of every inconsistency.

## Common mistakes and misconceptions

A frequent mistake is treating LDAP/AD and Microsoft Entra as two identical ways to make the same connection. They can support the same goal of sourcing identities, but they require distinct connectors and authorization models. A company should select the path that corresponds to its environment instead of assuming that one configuration automatically fits the other.

Another misconception is to synchronize every available field without assessing its value. More data does not necessarily mean better quality. Old attributes, technical groups, and free-form values can create profiles that are difficult to search and unreliable for segmentation.

Applying the first synchronization without a preview is also risky. A mapping change can create unexpected records, replace a correct value, or interpret a missing field as a reason to deactivate someone. A preview makes the impact visible before execution.

Four other practices tend to increase fragility:

- using email as the only identity reference even though it can change;

- keeping manual adjustments in the intranet without defining what the next synchronization will do with them;

- ignoring accounts that are disabled, reactivated, or removed at the source;

- failing to record when a connection ran, what changed, and what the outcome was.

## How companies usually handle this today

Companies with on-premises infrastructure often connect applications to Active Directory through LDAP. They define an address, read credentials, a search base, and filters to find the people who should take part in synchronization. This design can fit organizations that keep their primary directory on their own servers or controlled networks.

Companies that concentrate identities in Microsoft's cloud ecosystem tend to use Microsoft Entra. In this path, the connection usually depends on administrator consent and permissions defined for the application. The integration queries users and attributes through the platform's own interfaces; it does not turn Entra into an LDAP server.

Hybrid environments may contain both worlds, but that does not mean both should feed the intranet at the same time. Before enabling more than one source, the organization must determine which one is authoritative for each population and how duplicates will be avoided. In many cases, choosing one primary source reduces ambiguity and makes operations more predictable.

Where no integration exists, HR or IT commonly exports spreadsheets and imports the data periodically. This may address an initial need, but it requires discipline to repeat the process, review differences, and manage changes between one load and the next. Manual work grows along with the number of people and units.

## What actually works in practice

### Start with the right source and the necessary scope

First, confirm which system represents the current state of people. Then define the scope: the entire company, selected units, or a filtered set. The LDAP/AD connector should be configured for the on-premises directory service; the Microsoft Entra connector should follow the cloud authorization and query flow. Keeping these paths separate reduces workarounds and makes failures easier to diagnose.

### Map fields and values intentionally

Mapping relates each source attribute to the corresponding intranet field. Connecting “department” to “department” is not enough: teams need to consider empty values, abbreviations, language differences, and former names. Some companies must also convert codes into understandable labels or define which field identifies unit, location, and manager.

A simple matrix helps: source attribute, destination field, required transformation, behavior when the value is missing, and owner of the rule. The [Human Resources module](/en/platform/human-resources) provides context for how people and organization data will be used after integration.

### Review a preview before applying changes

A preview should clearly separate what will be created, updated, kept, deactivated, or flagged for review. The goal is not to demand individual inspection of thousands of people, but to allow teams to examine samples, totals, and meaningful exceptions.

Before the first run, check departments with the highest volume, people with duplicate identifiers, accounts without email addresses, manager changes, and records missing from the source. Whenever mapping changes, generate a new preview.

### Define the access lifecycle and schedule

User synchronization does not end when a profile is created. The organization must decide what happens when someone moves to another area, leaves the company, returns, or becomes active again at the source. Deactivation and reactivation based on known rules help reduce orphaned profiles and repeated manual work.

The schedule should also reflect the pace of the operation. A manual run can be enough to validate the configuration; later, a regular schedule keeps data close to the source. Pause, resume, and retry controls support configuration changes or error handling without discarding the history.

### Keep evidence for operations and governance

Run history, results by stage, and change records help HR and IT answer objective questions: when did synchronization run, which source was used, how many records changed, and which items need attention? This visibility turns the integration into an administrable process instead of a black box.

## Where Vindula fits in this scenario

Vindula provides distinct LDAP/Active Directory and Microsoft Entra connectors within a shared flow for mapping, preview, synchronization, access lifecycle, and history. The overview is available under [Integrations](/en/platform/integrations), while the connection with the Microsoft ecosystem is covered in [Microsoft 365](/en/platform/integrations/microsoft-365). This allows HR and IT to work with the same process while respecting the identity source adopted by the company.

## Practical checklist

- Confirm where the company's trusted identity source is maintained.

- Choose LDAP/AD for the on-premises directory or Microsoft Entra for cloud identity, according to the existing architecture.

- Define which people and units belong in scope.

- Select a stable identifier to reconcile records.

- Document field mapping and value transformations.

- Decide how to handle missing attributes and manual adjustments.

- Generate and review a preview before the first application and after configuration changes.

- Establish rules for creation, updates, deactivation, and reactivation.

- Start with a controlled run before setting a recurring schedule.

- Monitor history, exceptions, and attempts that require review.

- Assign HR and IT owners for data, connection, and discrepancy handling.

- Periodically confirm that the source and scope still reflect the organization.

## Conclusion

Choosing between LDAP/AD and Microsoft Entra depends on where the company manages its identities. Integration quality, however, depends on a broader set of decisions: clear scope, intentional mapping, preview before application, access lifecycle rules, and a reviewable history.

When these decisions are handled as a shared process between HR and IT, the intranet can reflect the organization more accurately. The right connector opens the path; synchronization governance keeps that path reliable as people, structures, and technologies change.

### Vindula

Vindula Team

Vindula develops intranet solutions for internal communication, people management, knowledge, and governance.

## Related Articles

 Product updates

### Vindula updates: managers, Feed, and connected directories

The update brings org structure, communication, and corporate identity closer together in a more governed operation.

 Fabio Rizzo

 September 14, 2026 • 2 min read

 People Management and Technology

### User synchronization in the intranet: mapping, preview, and access lifecycle

A guide to connecting corporate directories to the intranet with clear criteria, review before execution, and a history of changes.

 Vindula

 September 14, 2026 • 7 min read

 Intranet

### 10 social corporate intranet benefits for your company

Learn how a social corporate intranet improves internal communication, speeds up execution, strengthens culture, and drives measurable gains in productivity, engagement, and governance.

 Fabio Rizzo Matos

 October 15, 2025 • 3 min read

 View All Articles
