I've seen both Veritasium's video and this much older one: https://youtu.be/6Hl7BLXq5vA and I honestly prefer the explanation of the older video.
I do appreciate the explained history, but I found the explanation on the maths more clear and to the point in the lecture video.
Alternatively, you can add an LDAP outpost/provider to Authentik. Now you don't need to manage any LDAP server at all, and use the Authentik directory to manage users and groups. wiki link