<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[EntraID / AzureAD LDAP wrapper]]></title><description><![CDATA[<p dir="auto">The topic has come up several times in the forum in the past: Is there an easy way to connect the Cloudron user directory to Microsoft Entra ID (formerly Azure AD) for a same signin scenario? Microsoft offers the Entra ID Domain Services with LDAP, but it involves a very complex and cost intensive setup.</p>
<p dir="auto">I have been using the "Azure AD LDAP Wrapper" in the past which uses the Microsoft Graph API and provides an LDAP endpoint for Entra ID:<br />
<a href="https://ahaenggli.github.io/AzureAD-LDAP-wrapper/installation/run-ldap-wrapper/" target="_blank" rel="noopener noreferrer nofollow ugc">https://ahaenggli.github.io/AzureAD-LDAP-wrapper/installation/run-ldap-wrapper/</a></p>
<p dir="auto">The project is quite simple and easy to install using docker or nodejs directly. I am currently running it on a seperate server with firewall rules to allow only specific ip addresses to access the LDAP port. Now, wouldn't be great if this could run as a Cloudron app itself? If it was published on the app store, one would only need to provide the Azure App registration data in an env-file and could bind the Cloudron directory to a local (private) LDAP port on the same server.</p>
<p dir="auto">Well, I am new to packaging apps for Cloudron and have no idea how to package an app without a web interface. Heath checks would need to check the LDAP port and not HTTP, etc. Is this even a scenario wanted by the <a class="plugin-mentions-group plugin-mentions-a" href="/groups/staff" aria-label="Profile: staff">@<bdi>staff</bdi></a>?</p>
<p dir="auto">If so, I could give packaging a try and do some testing, but would need some pointers if this can/should be realized as an app within Cloudron as it would need to expose a custom LDAP port to the internal docker stack.</p>
]]></description><link>https://forum.cloudron.io/topic/13342/entraid-azuread-ldap-wrapper</link><generator>RSS for Node</generator><lastBuildDate>Thu, 17 Sep 2026 04:26:48 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/13342.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 24 Feb 2025 15:10:04 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to EntraID / AzureAD LDAP wrapper on Sun, 13 Apr 2025 17:29:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jlx89" aria-label="Profile: JLX89">@<bdi>JLX89</bdi></a> said in <a href="/post/105603">EntraID / AzureAD LDAP wrapper</a>:</p>
<blockquote>
<p dir="auto">How about just using an Enterprise App with SCIM Provisioning?</p>
</blockquote>
<p dir="auto">That would be great <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f64c.png?v=cda77ebfe05" class="not-responsive emoji emoji-android emoji--raised_hands" style="height:23px;width:auto;vertical-align:middle" title="🙌" alt="🙌" /></p>
]]></description><link>https://forum.cloudron.io/post/105629</link><guid isPermaLink="true">https://forum.cloudron.io/post/105629</guid><dc:creator><![CDATA[NCKNE]]></dc:creator><pubDate>Sun, 13 Apr 2025 17:29:30 GMT</pubDate></item><item><title><![CDATA[Reply to EntraID / AzureAD LDAP wrapper on Sat, 12 Apr 2025 21:50:36 GMT]]></title><description><![CDATA[<p dir="auto">How about just using an Enterprise App with SCIM Provisioning?</p>
]]></description><link>https://forum.cloudron.io/post/105603</link><guid isPermaLink="true">https://forum.cloudron.io/post/105603</guid><dc:creator><![CDATA[JLX89]]></dc:creator><pubDate>Sat, 12 Apr 2025 21:50:36 GMT</pubDate></item><item><title><![CDATA[Reply to EntraID / AzureAD LDAP wrapper on Mon, 24 Feb 2025 18:10:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/joseph" aria-label="Profile: joseph">@<bdi>joseph</bdi></a> said in <a href="/post/102225">EntraID / AzureAD LDAP wrapper</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nckne" aria-label="Profile: NCKNE">@<bdi>NCKNE</bdi></a> said in <a href="/post/102222">EntraID / AzureAD LDAP wrapper</a>:</p>
<blockquote>
<p dir="auto">Entra ID / Azure AD is not LDAP</p>
</blockquote>
<p dir="auto">TIL <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=cda77ebfe05" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> Had no clue, ignore my previous comment then. Just read about it a little more and it seems you need something called Azure AD DS per <a href="https://www.reddit.com/r/sysadmin/comments/120e71z/ldaps_with_azure_ad_tenant_bundled_with_office_365/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.reddit.com/r/sysadmin/comments/120e71z/ldaps_with_azure_ad_tenant_bundled_with_office_365/</a></p>
</blockquote>
<p dir="auto">Yeah, but the Azure AD DS you mentioned is very complex and expensive (licensing costs). I just thought since the topic had come up a few time, native support of Entra ID / Azure AD might be something to consider for the future.</p>
]]></description><link>https://forum.cloudron.io/post/102237</link><guid isPermaLink="true">https://forum.cloudron.io/post/102237</guid><dc:creator><![CDATA[NCKNE]]></dc:creator><pubDate>Mon, 24 Feb 2025 18:10:06 GMT</pubDate></item><item><title><![CDATA[Reply to EntraID / AzureAD LDAP wrapper on Mon, 24 Feb 2025 16:30:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nckne" aria-label="Profile: NCKNE">@<bdi>NCKNE</bdi></a> said in <a href="/post/102222">EntraID / AzureAD LDAP wrapper</a>:</p>
<blockquote>
<p dir="auto">Entra ID / Azure AD is not LDAP</p>
</blockquote>
<p dir="auto">TIL <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=cda77ebfe05" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /> Had no clue, ignore my previous comment then. Just read about it a little more and it seems you need something called Azure AD DS per <a href="https://www.reddit.com/r/sysadmin/comments/120e71z/ldaps_with_azure_ad_tenant_bundled_with_office_365/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.reddit.com/r/sysadmin/comments/120e71z/ldaps_with_azure_ad_tenant_bundled_with_office_365/</a></p>
]]></description><link>https://forum.cloudron.io/post/102225</link><guid isPermaLink="true">https://forum.cloudron.io/post/102225</guid><dc:creator><![CDATA[joseph]]></dc:creator><pubDate>Mon, 24 Feb 2025 16:30:17 GMT</pubDate></item><item><title><![CDATA[Reply to EntraID / AzureAD LDAP wrapper on Mon, 24 Feb 2025 15:41:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/joseph" aria-label="Profile: joseph">@<bdi>joseph</bdi></a> said in <a href="/post/102221">EntraID / AzureAD LDAP wrapper</a>:</p>
<blockquote>
<p dir="auto">AD support seems to be something we should add directly to Cloudron's existing LDAP server, if this is deemed useful. Incidentally, Cloudron's ldap server  is also based on ldapjs.</p>
</blockquote>
<p dir="auto">Entra ID / Azure AD is <strong>not</strong> LDAP… that’s why either a wrapper like above is needed or Cloudron could natively implement Entra ID support (as many other apps do) and connect it to the Cloudron internal directory.</p>
]]></description><link>https://forum.cloudron.io/post/102222</link><guid isPermaLink="true">https://forum.cloudron.io/post/102222</guid><dc:creator><![CDATA[NCKNE]]></dc:creator><pubDate>Mon, 24 Feb 2025 15:41:34 GMT</pubDate></item><item><title><![CDATA[Reply to EntraID / AzureAD LDAP wrapper on Mon, 24 Feb 2025 15:30:10 GMT]]></title><description><![CDATA[<p dir="auto">AD support seems to be something we should add directly to Cloudron's existing LDAP server, if this is deemed useful. Incidentally, Cloudron's ldap server  is also based on ldapjs.</p>
]]></description><link>https://forum.cloudron.io/post/102221</link><guid isPermaLink="true">https://forum.cloudron.io/post/102221</guid><dc:creator><![CDATA[joseph]]></dc:creator><pubDate>Mon, 24 Feb 2025 15:30:10 GMT</pubDate></item></channel></rss>