Configuration: Managing AD connectors
AD connectors allow users to easily monitor Active Directory environments on segregated networks with minimal network changes.
NOTE: In the current version of Cayosoft Guardian, AD connector is for Change Monitoring and partially for Threat Detection environments. Forest Recovery scenarios are not supported with AD connector.
AD connectors are typically deployed in environments where Cayosoft Guardian and the monitored Active Directory infrastructure reside in different networks or network segments. This separation is common in hybrid or secure deployments and requires network configuration (i.e., firewall rules) to allow communication between the Guardian server and the remote AD connector host(s).
This article describes how to enable, install, and manage the AD connector.
Enabling AD connectors in Settings
To enable the AD connector in Settings:
- Navigate to Guardian > Settings > Service Settings>Connection Settings for Active Directory, enable Allow domain management via AD connectors, and click Save.
- Refresh the page.
- Open Change Monitoring > AD connectors.
- Click Register AD connector.
- Enter a unique hostname in the Hostname field.
- A new AD connector will be added, and the configuration file will be downloaded.
- Click Download AD connector.
- Double-click the installer to start the installation.
- Agree to the terms and conditions and click Install.
- After the installation, click Launch.
- The AD connector service will open. Login with your admin credentials which you have used when registering AD connector.
- From AD connector > Configuration > Guardian Services, click Connect to Guardian service.
- Import the configuration file downloaded in the 6th step and click Connect.
- The connection will be established, and the AD connector will be displayed on the page.
After setting up the connector, navigate to Managed domains and configure the connection account. Learn more: Configuration: Add a Domain.
Managing AD connector
To manage the added AD connector:
- Select the AD connector and click Properties.
Here the following actions are available:
- Retrieve logs - allows retrieving logs
- Regenerate configuration - regenerates a new configuration file for the AD connector
- Upgrade AD connector - upgrades the AD connector to the latest available version. This option is usually disabled because the AD connector is automatically upgraded when the primary host is updated.
- Delete - deletes the AD connector
- To manage the AD connector settings:
- Authentication Settings - use this option to enable Application-only authentication for secure access
- Connection settings for Active Directory - view or configure Active Directory connection settings
- Database Settings - view initialization history and modify data storage settings
- Network Settings - view or configure network parameters such as proxy settings, IP bindings, or service endpoints.
- Remote PowerShell Settings – configure PowerShell remoting settings to allow remote script execution between Guardian and domain controllers.
- Support Log Settings - configure extended service log settings to send log files to Cayosoft support if needed
- System Log Settings - view or configure system-level logging such as categories, retention policies.
Replacing AD connector
In some cases, it may be necessary to replace the existing AD connector for a domain—for example, when the connector host is changed or reinstalled. This can be done by re-assigning the AD connector using the domain wizard.
To replace an AD connector:
-
Go to the Managed Domains section of the Guardian interface.
-
Select the AD connector from the list. For more information on how to add a domain, see Configuration: Add a Domain.
Or,
-
Click on the domain for which you want to replace the AD connector.
-
In the domain Properties view, switch to the AD connectors tab. Here you can view, assign, or remove the current connector.
Use the Assign AD connector button to launch the configuration wizard. - Fill out the necessary details and click Assign.
Comments
0 comments
Please sign in to leave a comment.