It's supposed to be a standard, but it's really arcane and, in places, very ugly, and there's not much good documentation on it, and some that does exist comes from early 2000-s and barely works for today.
In other words, it's so... enterprise.
I thought packages like FreeIPA could ease the pain, but no.
I mean, it still beats setting up OpenLDAP by hand, but it has its own pile of bullshit on top. Poor documentation is still a thing.