Cayosoft Guardian product architecture
Overview
Cayosoft Guardian is a change monitoring, threat detection, backup, and recovery platform for hybrid Active Directory and Microsoft Entra ID environments. It lets administrators see what changed, roll back mistakes and malicious changes, and recover from domain-wide or forest-wide outages.
Cayosoft Guardian is built on a modern multi-tier architecture using current Microsoft and web technologies.
Built for every phase of the IT cloud journey
Cayosoft Guardian Is built from the ground up to monitor and recover critical platforms through each phase of the cloud journey—on-premises, hybrid, and public or private cloud. The components below are what make it flexible across all three.
Architecture tiers
Data tier. Microsoft SQL Server, either local or external, holds configuration and collected change history.
Distributed tier. Optional agents and connectors extend Cayosoft Guardian into on-premises domains and cloud recovery sites.
Jobs and plans
Jobs define how and when automated or user-initiated tasks run. A job may continuously collect changes from a connected system such as Microsoft 365 or Active Directory; another, started by an administrator, may roll back an unwanted change to a hybrid security group.
Job types include:
Change collection jobs continuously capture changes from Active Directory, Entra ID, Exchange Online, Microsoft Teams, and Intune.
Event collection jobs read native audit logs and correlate events with the changes Guardian recorded.
Rollback jobs return objects in managed systems to a previous state on request.
Backup plans create backups of Active Directory domain controllers.
Recovery plans rebuild Active Directory infrastructure, including forest recovery, standby forest, restore to clean OS, and recovery-site deployment.
Reporting and export jobs produce output in CSV, HTML, JSON, or PDF.
Threat detection jobs analyze changes in real time and on a schedule; threat reporting jobs summarize what was found.
Maintenance jobs—retention, storage maintenance, dictionary maintenance, and archive upgrade—keep the database consistent and correctly sized.
Agent jobs deploy, update, and collect logs from Guardian agents.
Plans are composite jobs that orchestrate the execution of other jobs.
Alerting rules and notification channels
Alerting rules define when and how administrators are notified about important changes in connected systems or in Guardian itself. When a change matches a rule, Guardian raises an alert and sends a notification through a communication channel.
Three communication channels are built in:
Exchange Online
Microsoft Teams
SMTP
Rules support suppression and alert counters so that repeated or expected activity does not flood recipients.
Saved queries
Saved queries define how and what collected data is presented. Administrators use them for instant access to essential data and can build a report or an alerting rule directly from a query filter. Additional curated queries are available from the in-product query marketplace.
Threat definitions
Guardian ships threat definitions containing signatures of known attacks and misconfigurations. Against these definitions, it continuously analyzes changes in your environment and runs scheduled assessments to find traces of malicious activity.
Threat signatures are delivered as a versioned plugin package and can be updated independently of the product release.
Cayosoft Guardian Service
The core of the product is a Windows service, shown as Cayosoft Guardian Service in the Services snap-in. Its service name is CayoGuardian.
The service runs as LocalSystem by default or as a service account that you specify during setup. It hosts the API, portal, scheduler, and connectors in a single process.
Database
The Guardian database stores configuration settings and the change data collected from managed systems. Guardian separates configuration content from change history content and can attach additional archive databases, including read-only archives, for long-term retention.
After installation, Guardian uses a local SQL Server LocalDB instance. For production environments, configure an external database on Microsoft SQL Server or Azure SQL.
Retention jobs remove items that are no longer required, and maintenance jobs keep the databases consistent and optimized.
Web portal
Administrators use the web portal to configure the product and perform change audit, recovery, threat review, and other management tasks. It provides fast access to critical Active Directory, hybrid, and Microsoft 365 changes and to the actions that undo them.
Authentication and roles
Cayosoft Guardian acts as its own OAuth 2.0 and OpenID Connect authorization server. Administrators can sign in with Microsoft Entra ID or Windows Integrated authentication. Agents and internal services authenticate with issued tokens.
Built-in roles let you grant day-to-day administrators and help desk staff only the permissions that their jobs require:
Global Admin—full control.
Global Reader—read-only access across the product.
Change History Reader—review the full history of configuration and object changes across connected systems.
Change Monitoring Operator—manage change monitoring, review changes, and manage alerts.
Threat Alerts Reader—review detected threats and alert details without modifying or resolving them.
Threat Detection Operator—manage threat detection jobs, configure notifications, and resolve threats.
User—the base role nested inside the roles above.
Roles can be customized and nested.
Agents and connectors
Forest Recovery Agent
Installed on domain controllers, the Forest Recovery Agent creates backups using Windows Volume Shadow Copy, copies them to backup storage, and performs recovery operations on target machines in the recovery site.
AD Connector
The AD Connector is an optional on-premises service that gives Cayosoft Guardian a local presence in a managed forest for Active Directory collection and restore operations. It runs in a master or worker role, maintains a heartbeat with the Guardian server, and updates itself under Guardian's control.
Active Directory change and event collection is supported both with and without the AD Connector. The agentless topology remains available.
Relay Server
The Relay Server is a lightweight Linux service used to establish connectivity between Cayosoft Guardian and recovery sites deployed in Azure or AWS.
Backup locations
Backup locations are the storage targets used by backup and recovery plans. Cayosoft Guardian supports:
SMB file shares
Azure Blob storage
Azure Files shares
Amazon S3
For more information, see Forest Recovery: Add backup locations.
Deployment architecture
Cayosoft Guardian can be deployed in three ways.
Single server
The typical customer deployment uses one virtual or physical Windows machine. For change monitoring, an external SQL Server or Azure SQL database is recommended.
For forest recovery, agents are deployed automatically to each domain controller included in a backup plan. A backup location in Azure or AWS is recommended for backup storage.
Azure Marketplace virtual machine
A solution template provisions a Windows Server virtual machine with networking, a public endpoint, and a certificate, and then installs and configures Cayosoft Guardian automatically.
Cayosoft Guardian hosted on Azure
Cayosoft Guardian hosted on Azure is a managed marketplace deployment that provisions the full stack in your subscription:
The Cayosoft Guardian virtual machine behind Azure Front Door and Private Link
Azure SQL databases for configuration and history
An Azure storage account
Azure Key Vault
Azure Log Analytics
A managed identity
Disaster recovery architecture
For disaster recovery, Cayosoft Guardian can additionally deploy a clean recovery site into Azure or AWS on demand. Cayosoft Guardian reaches the recovery site through the Relay Server.
Comments
0 comments
Please sign in to leave a comment.