This document summarizes LDAP (Lightweight Directory Access Protocol) and its role in authentication and authorization at the University. It discusses: - The difference between authentication (AuthN) and authorization (AuthZ) - How LDAP directories store user and group information in a hierarchical tree structure with objects, attributes, and distinguished names - How the University uses Central Auth LDAP and Active Directory for authentication and storing user attributes - How LDAP queries and operators allow searching for users and groups with certain attributes - Applications of LDAP for authorization in systems like Apache and pulling user data into web apps