Monitoring AD and Microsoft Entra ID with a Primary-Secondary deployment model
Overview
Monitoring and recovering changes across Active Directory and Entra ID are essential for security, compliance, and operational efficiency. Cayosoft Guardian provides real-time change monitoring across environments using a multi-instance deployment model.
The primary-secondary deployment model enables centralized monitoring by deploying a single primary instance that aggregates and processes data from multiple secondary instances, ensuring comprehensive visibility across all environments.
Deployment Architecture
The deployment could have the following components:
-
Primary Instance: A central instance that receives, aggregates, and processes the changes and alerts coming from the secondary instances.
The primary instance becomes the single source for monitoring, analyzing, and managing changes.
Secondary Instances: Deployed in a single Active Directory Domain or Entra ID tenant to collect changes to the primary instance, minimizes performance impact while still enabling full monitoring capabilities.
When to use the Primary-Secondary deployment model
Scalability and Performance Optimization
Separate Change Monitoring and Threat Detection from Forest Recovery, this model could be utilized to distribute the load from a single instance into multiple, Also, vertical scaling could be taken as an option in this scenario as well.
Distribute the single forest with different domains into separate guardian instances, this is another way to optimize performance
Geographically distributed organizations (e.g.: Ad forests/domains in North America, Europe, and Asia) can monitor local environments with secondary instances before merging data into a primary instance.
Subsidiaries and business units need localized monitoring with central oversight.
Organizations that have multiple Active Directory forests segregated by departments/units, and roles can use a standalone secondary instance to maintain separation while enabling centralized management. Organizations that have multiple Active Directory forests segregated by departments/units, and roles can use a standalone secondary instance to maintain separation while enabling centralized management.
Deployment scenarios
-
Single Tenant, Multiple Domains
A primary instance consolidates monitoring across multiple AD domains
Secondary instances are deployed in each domain to provide localized monitoring.
-
Hybrid Cloud Monitoring
Separate secondary instances monitor both on-premises AD and cloud-based Entra ID, with data aggregated into a centralized primary instance.
-
Multi-Tenant Organizations
Managed service providers (MSPs) or enterprises managing multiple Entra ID tenants can use secondary instances per tenant.
The primary instance merges data across all tenants for centralized oversight.
-
Large-scale deployments with Logical Partitions
Organizations with a large number of users and groups can divide the environments based on products and tools (Entra ID, Intune, Teams, etc...)
The primary instance merges the monitoring data into a single view.
Authentication and authorization in multi-instance topology
SQL Server authentication: database users establish a connection with the database which then checks information such as the domain and instance names, port number, and user account credentials.
Windows authentication: To do this, the token is passed to SQL Server, which in turn validates the token against a domain controller to decide whether to grant access. Now SQL Server can trust the user who they say they are. From there it consults its user information to decide whether or what access to grant.
Role-based access control (RBAC) ensures that admins only access data relevant to their assigned instances.
How to configure
Follow the instructions to install Cayosoft Guardian. Learn more: Installing Cayosoft Guardian
Configure the database by following these instructions: Configuration: Database configurations.
Based on your deployment plan, you can configure AD or Entra ID for the primary instance.
After configuring the secondary instance, navigate to your primary instance.
Navigate to Settings > Archive Databases and click New.
-
Fill in the required field to connect with your secondary database:
Navigate to Archive > Change History to monitor and manage changes in your secondary instance
Navigate to Archive > Change Alerts to monitor alerts in your secondary instance.
Navigate to Archive > Threat Alerts to monitor threat alerts in your secondary instance.
NOTE: Rollback action is disabled for all change records related to Entra ID, Exchange Online, or Microsoft Teams for “as Archive” (RO, Read only) connection.
Comments
0 comments
Article is closed for comments.