A well-designed video CMS integration connects the video platform to existing user, role, and authentication structures. This allows companies, universities, and public authorities to avoid maintaining separate user management systems. With LDAP integration and SAML authentication, VIMP offers two distinct ways to integrate the platform into existing IT infrastructures.

In short:
LDAP connects VIMP to a directory service. SAML connects VIMP as a service provider to an identity provider and is a common method for enabling browser-based single sign-on (SSO).

Table of Contents
- Why Is a Well-Designed Video CMS Integration Important?
- Video CMS Integration with SSO, LDAP, and SAML: What Is the Difference?
- Video CMS Integration via LDAP: How the Connection Works
- Video CMS Integration via SAML: How Single Sign-On Works
- LDAP or SAML: Which Video CMS Integration Fits Your IT Infrastructure?
- Secure Video CMS Integration: What IT Teams Should Consider
- Video CMS Integration with VIMP
- Conclusion: Planning Video CMS Integration Together
- Frequently Asked Questions About Video CMS Integration
Why Is a Well-Designed Video CMS Integration Important?
A well-designed video CMS integration uses existing identity and authorization structures. Many organizations already manage their users centrally, for example via Microsoft Active Directory, OpenLDAP, or an identity provider. Introducing a separate user management system for the video platform, on the other hand, increases administrative effort and can cause accounts, roles, and permissions to become inconsistent.
By connecting to the existing identity infrastructure, VIMP can use existing user information and organizational structures. This simplifies the login process while also providing a consistent foundation for assigning roles and permissions.
Video CMS Integration with SSO, LDAP, and SAML: What Is the Difference?
Single sign-on (SSO), LDAP integration, and SAML authentication serve different purposes in video CMS integration.
Single Sign-on (SSO)
Users authenticate once through a central system and can then access connected applications without having to sign in again.
LDAP
Authenticates users and retrieves the required user and group information from a directory service.
SAML
Exchanges authentication and authorization information between an identity provider and a service provider. In this setup, VIMP acts as the service provider.
Important: An LDAP integration alone does not automatically provide single sign-on. SSO, LDAP, and SAML are therefore not three equivalent technologies.
Video CMS Integration via LDAP: How the Connection Works
With an LDAP integration, VIMP authenticates users against an existing directory service such as Microsoft Active Directory or OpenLDAP. VIMP also uses the required user and group information to assign roles and permissions.
- The user signs in to VIMP.
- VIMP authenticates the user via the configured LDAP directory service.
- VIMP retrieves the required user and group information.
- LDAP role mapping assigns the appropriate VIMP roles and permissions.
- After the first successful login, VIMP creates a local user record.
This local record enables VIMP to clearly associate media, permissions, and actions with a specific user.
VIMP supports up to three LDAP configurations. The user base, group base, filters, and relevant LDAP attributes can be configured individually.
Using LDAP Groups for VIMP Roles
VIMP can map LDAP groups to existing VIMP roles, allowing existing organizational structures to be used for role and permission management. Optionally, VIMP can update role assignments each time a user signs in. This means that changes made in the directory can be reflected in VIMP’s role assignments at the next login.

Practical tip:
Limit the user base, group base, and LDAP filters to the objects required for VIMP wherever possible. A dedicated organizational unit for VIMP-related groups can also make administration clearer and more manageable.
-> The VIMP Helpdesk provides dedicated instructions for the specific configuration steps.
Configure Synchronization Deliberately
An LDAP integration is not a permanent full synchronization of the directory service. VIMP can update user data and role assignments when users sign in, for example. Additional functions related to user-sync are also available.
Which options are most suitable depends on the organization’s intended identity lifecycle.
Video CMS Integration via SAML: How Single Sign-On Works
With SAML authentication, an identity provider (IdP) handles the login process, while VIMP acts as the service provider (SP). When a user initiates the SAML login process, the configured IdP authenticates the user and then transmits the SAML information and attributes intended for VIMP.
VIMP can connect to a default IdP as well as additional identity providers. According to the current VIMP Helpdesk documentation, an unlimited number of IdPs can be configured. Microsoft Entra ID can also be used as a SAML identity provider with VIMP.
Assigning Roles via SAML
In addition to authentication, VIMP can use SAML attributes for role mapping. The role and permission management settings define which IdP, attribute array, and attribute value are mapped to a specific VIMP role.
Optionally, role assignments and user attributes can be updated each time a user signs in.
LDAP or SAML: Which Video CMS Integration Fits Your IT Infrastructure?
LDAP and SAML serve different purposes within an identity architecture. Which integration is more suitable therefore depends on the existing IT infrastructure.
| Requirement | LDAP | SAML |
|---|---|---|
| Connect directly to a directory service | Yes, e.g. Active Directory or OpenLDAP | Not directly; authentication is handled by the identity provider (IdP) |
| Use user and group information | Retrieved from the directory service | Attributes are transmitted by the IdP |
| Browser-based single sign-on (SSO) | Not provided by LDAP alone | A typical use case |
| Identity provider required | No | Yes |
| Assign VIMP roles | Via LDAP groups | Via SAML attribute values |
LDAP is particularly suitable when VIMP needs to authenticate users directly against an existing directory service. SAML, on the other hand, is ideal for organizations that already use a centralized identity provider and single sign-on infrastructure.
The decision should therefore be based on the existing identity architecture.
Secure Video CMS Integration: What IT Teams Should Consider
Before going live, the IT team should clarify key questions relating to identities, roles, updates, and administrative access.
Questions to Clarify Before Going Live
Identity source
Which source is authoritative for user identities?
Unique identifier
Which attribute uniquely identifies a user?
Role model
Which groups or SAML attribute values are mapped to which VIMP roles?
Synchronization
When does VIMP update user information and role assignments?
User lifecycle
How are users handled if they no longer exist in the central system?
Emergency access
How can administrative access be maintained if an external authentication service is unavailable?
The Technical Connection Must Also Be Secured
For LDAP integrations, VIMP supports LDAPS and TLS certificate validation. For SAML authentication, available security features include X.509 certificates, a dedicated certificate for the VIMP service provider, and a Strict Mode.
The service provider’s private key must remain confidential. The SAML debug mode should also be disabled in production environments.
Further criteria relating to roles, media permissions, and technical security measures are covered in the VIMP article on video data protection.
Video CMS Integration with VIMP
VIMP Enterprise and VIMP Campus can be integrated into existing identity infrastructures via LDAP and SAML, allowing organizations to continue using their established authentication and role structures.
VIMP’s internal authentication, LDAP, and SAML can also be used in parallel, enabling different user groups to use different login methods.
LDAP supports group and role mappings as well as up to three configurations. With SAML, VIMP acts as the service provider and can connect to additional identity providers alongside a default IdP. This eliminates the need for separate identity management specifically for VIMP.
Conclusion: Planning Video CMS Integration Together
A well-designed video CMS integration begins with the existing identity architecture. LDAP connects VIMP directly to a directory service and enables directory groups to be mapped to VIMP roles. SAML connects VIMP as a service provider to an identity provider and supports common single sign-on scenarios.
By jointly planning user identities, role mapping, updates, offboarding, and connection security, organizations can integrate VIMP consistently into their existing IT infrastructure.
Frequently Asked Questions About Video CMS Integration
Yes. VIMP supports SAML 2.0, with VIMP acting as the service provider and connecting to an identity provider.
No. LDAP is a protocol for accessing directory services. An LDAP integration alone does not automatically provide SSO.
Yes. With LDAP, LDAP groups can be mapped to VIMP roles. With SAML, values from a configured attribute array can be used for role mapping.
Yes. Up to three LDAP configurations can be defined to connect up to three LDAP servers.
Yes. Additional IdPs can be connected alongside the default IdP. The current VIMP Helpdesk documentation describes how to connect an unlimited number of IdPs.
Yes. The VIMP Helpdesk provides instructions for configuring Microsoft Entra ID, formerly Azure Active Directory, as a SAML identity provider.