Meta-Directory
A meta-directory is a centralized directory service that gathers and reconciles identity information from multiple separate directories and data sources into a unified view. Rather than replacing the underlying directories, it helps organizations locate and manage user information that lives across many systems. In some descriptions, it holds descriptions of objects and where they reside rather than the objects themselves.
A meta-directory is a directory service that consolidates and synchronizes identity information aggregated from multiple authoritative sources, such as directories and databases, into a centralized or virtual view. Depending on the implementation, it may physically store consolidated object data or, as characterized in some definitions, hold metadata describing objects and their locations in other physical directories rather than the objects themselves. Implementations vary: some function as a virtual directory grouping other declared directories to simplify locating a user across sources, while others consolidate and manage information from multiple sources. This entry addresses the directory-consolidation concept only; specific synchronization, provisioning (for example SCIM), and reconciliation mechanics depend on the product and deployment and are out of scope here.
Why it matters
In most enterprises, identity data is fragmented across many authoritative sources, HR systems, LDAP directories, application-specific databases, and departmental stores, each maintaining its own partial view of the same people. A meta-directory matters because it addresses this fragmentation by aggregating and reconciling that scattered identity information into a unified view, allowing organizations to locate and manage user records that span multiple systems without first ripping out the underlying directories those systems depend on.
The operational value is primarily one of consolidation and findability. As characterized in some definitions, a meta-directory may hold metadata describing where objects reside rather than the objects themselves, functioning as a virtual directory that groups other declared directories to simplify finding a user across sources. In other implementations it physically consolidates and manages object data drawn from multiple sources. Either way, the goal is to reduce the effort of answering a deceptively simple question: where does authoritative information about a given user actually live?
It is worth being precise about scope. A meta-directory addresses the directory-consolidation problem, aggregating and reconciling identity data into a centralized or virtual view. It is not, by itself, an authentication mechanism, an authorization decision point, or a full identity governance platform. The specific synchronization, provisioning, and reconciliation mechanics that determine how faithfully the consolidated view reflects its sources depend heavily on the product and deployment, and organizations should evaluate those mechanics separately rather than assuming a meta-directory delivers them uniformly.
Who it's relevant to
Inside Meta-Directory
Common questions
Answers to the questions practitioners most commonly ask about Meta-Directory.
