Pretty broad question. You'll need to figure out if you want to use ldap for identity + assignment, or use ldap for identity and sql for assignment. I'm using ldap (identity) and sql (assignment) which seems to work out well. I'm using AD as the backend to auth users.

This blog has some info on how to do it: