Hello ABP Team,
We are currently working on a multi-tenant application built using the ABP Framework, and we would like to implement LDAP/Active Directory authentication.
Our main requirement is to support LDAP configuration at the tenant level, meaning:
Each tenant should be able to configure its own LDAP/AD settings independently. Different tenants may connect to different LDAP servers (e.g., different domains or organizations). Authentication should dynamically resolve the LDAP configuration based on the current tenant context.
- Is tenant-level LDAP configuration supported out-of-the-box in ABP?
- Or is LDAP integration only designed for host-level configuration?
- If not supported natively:
- What is the recommended approach to implement per-tenant LDAP authentication?
- Should we:
- Store LDAP settings using the Setting Management system (per tenant)?
- Override or extend a specific service (e.g., ILdapAuthenticationService or similar)?
- How should we properly integrate this with:
- The Identity module
- The login flow (Account module / Angular UI)
- Existing authentication pipelines
- Are there any official examples or best practices for:
- Multi-tenant LDAP scenarios?
- Dynamic external authentication providers per tenant?
🧾 Technical Context ABP Framework version: 10.1.1 UI: Angular
2 Answer(s)
-
0
- Tenant-level LDAP configuration is not provided as an out-of-the-box, “ready” feature in ABP’s LDAP integration. ABP’s built-in LDAP provider is designed around a single configuration source (typical usage is host-level configuration + a feature flag to enable/disable LDAP login).
- However, implementing per-tenant LDAP is fully achievable by leveraging ABP’s multi-tenancy + Setting Management + service replacement/extension patterns.
- Recommended approach for per-tenant LDAP/AD
Store LDAP settings per tenant
- Define your own setting definitions (server, domain/base DN, bind DN, bind password, SSL, port, etc.).
- Persist them per-tenant using Setting Management (
ISettingManager/ISettingProvider), which already supports tenant-scoped values.
Resolve LDAP configuration using
ICurrentTenantat runtime- In your LDAP auth implementation, always read LDAP settings via
ISettingProvider(orISettingManager) so the current tenant context automatically selects the correct values.
- In your LDAP auth implementation, always read LDAP settings via
Replace/extend the LDAP authentication implementation
- ABP’s common pattern for tenant-specific behavior is to replace the related helper/service (using
[Dependency(ReplaceServices = true)]) and implement tenant-aware resolution logic. - Concretely, you implement a custom LDAP authentication service that:
- reads tenant-specific LDAP settings,
- tries LDAP bind/validate for the provided username/password,
- then maps/creates the corresponding ABP user (Identity module) and proceeds with the normal sign-in flow.
- ABP’s common pattern for tenant-specific behavior is to replace the related helper/service (using
- Integration points (Identity + Account login flow + Angular)
Keep the standard ABP login flow (Account module) and plug LDAP in as an authentication option.
Typical pattern:
- User enters username/password on the existing login page (Angular).
- Server-side login flow checks whether LDAP login is enabled (feature) and/or tenant has LDAP settings configured.
- If enabled/configured: attempt LDAP authentication for the current tenant.
- If LDAP success: find/create/link the ABP Identity user, then sign-in using the standard ABP/Identity pipeline.
- If LDAP fails or not enabled: fallback to local Identity password sign-in (if you want hybrid behavior).
Enable/disable per tenant:
- You can also use Feature Management to toggle “LDAP login enabled” per tenant (in addition to settings), similar to how ABP’s account LDAP feature is handled in general.
- Official references you can use (verified)
- ABP LDAP documentation (includes a sample app link you can use to validate LDAP connectivity/config separately):
- https://abp.io/docs/latest/modules/identity/idap
- https://github.com/abpframework/abp-samples/tree/master/AbpLdapSample
- Example of tenant-specific provider selection via replacing a helper (demonstrates the exact ABP technique you’d use for “dynamic providers per tenant”):
- https://abp.io/support/questions/6637
- ABP support thread showing LDAP login is controlled via a feature + settings (useful background):
- https://abp.io/support/questions/2270
- Multi-tenancy basics (for tenant resolution concepts like
ICurrentTenant):- https://abp.io/docs/latest/framework/architecture/multi-tenancy
- ABP LDAP documentation (includes a sample app link you can use to validate LDAP connectivity/config separately):
- What to implement (practical blueprint)
// 1) Define tenant-scoped settings (server, baseDn, bindDn, bindPassword, etc.) public static class TenantLdapSettings { private const string Prefix = "TenantLdap."; public const string Server = Prefix + "Server"; public const string Port = Prefix + "Port"; public const string BaseDn = Prefix + "BaseDn"; public const string BindDn = Prefix + "BindDn"; public const string BindPassword = Prefix + "BindPassword"; public const string UseSsl = Prefix + "UseSsl"; } public class TenantLdapSettingDefinitionProvider : SettingDefinitionProvider { public override void Define(ISettingDefinitionContext context) { context.Add( new SettingDefinition(TenantLdapSettings.Server), new SettingDefinition(TenantLdapSettings.Port, "389"), new SettingDefinition(TenantLdapSettings.BaseDn), new SettingDefinition(TenantLdapSettings.BindDn), new SettingDefinition(TenantLdapSettings.BindPassword, isEncrypted: true), new SettingDefinition(TenantLdapSettings.UseSsl, "false") ); } }// 2) Implement a tenant-aware LDAP authentication service (pseudo-outline) // Replace the service that the login flow uses to validate credentials. [Dependency(ReplaceServices = true)] public class TenantAwareLdapAuthenticator /* : SomeAbpLdapService */ { private readonly ISettingProvider _settingProvider; private readonly ICurrentTenant _currentTenant; public TenantAwareLdapAuthenticator(ISettingProvider settingProvider, ICurrentTenant currentTenant) { _settingProvider = settingProvider; _currentTenant = currentTenant; } public async Task<bool> ValidateAsync(string userNameOrEmail, string password) { // Read settings for CURRENT tenant (automatic due to ICurrentTenant) var server = await _settingProvider.GetOrNullAsync(TenantLdapSettings.Server); if (server.IsNullOrWhiteSpace()) { return false; // tenant not configured => treat as disabled/fallback } // read other settings... // connect/bind to LDAP and validate credentials... return true; } }This is the ABP-supported pattern: tenant-scoped settings + service replacement. The only part you must align in your solution is which exact service/class to replace in the ABP LDAP login integration you’re using (that depends on whether you use the built-in LDAP external provider as-is or a custom login path). The “dynamic provider per tenant” support answer shows the same technique in a verified way.
- Official “best practice/example” status
- There is no single official ABP example that demonstrates “full per-tenant LDAP server configuration + dynamic bind per tenant” end-to-end.
- The verified best-practice building blocks are:
- tenant-specific configuration via Setting Management,
- dynamic behavior via service replacement,
- external provider selection customization pattern (see the verified support answer above).
This response was generated by AI. If it didn’t solve your problem, feel free to post a new answer — our support team will jump in to help you soon.
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post) -
0
Hi,
LDAP does support multi-tenancy in ABP — it is not host-only.
How to set it up per tenant:
Enable the feature for the tenant: Go to SaaS → Tenants, click the Features action for the target tenant, and check LDAP Login under the Identity group.
Configure LDAP settings in the tenant context: Switch to the tenant (either by logging in as a tenant admin, or using tenant switching in the host UI), then go to Settings → Identity → Ldap tab. Each tenant can configure its own Server Host, Port, Base DC, Domain, Username, and Password independently.
The underlying implementation uses
SetForCurrentTenantAsyncfor all LDAP settings, which means settings are automatically scoped to the current tenant. The official documentation screenshots also confirm this — the "Enable LDAP feature" screenshot is the per-tenant Features dialog.Thanks
Markdown supported.Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)