Active Directory Integration
A Microsoft Active Directory (AD) integration with Cloudhouse Guardian (Guardian) allows you to automatically sync and detect nodes from your AD instance(s) to be added to Guardian for monitoring and evaluation. This topic describes the steps you need to complete to setup an AD integration in Guardian.
Dependencies
To add an AD integration, you'll need to have an AD account. This could be an existing user account, but we recommend setting up a brand new user account named 'Guardian' for easier identification.
Add an AD Integration
Integrating AD with Guardian establishes a seamless connection to streamline the process of syncing and monitoring your AD nodes, ensuring they are efficiently scanned in Guardian.
To add an AD integration to Guardian, complete the following:
-
In the Guardian web application, navigate to the Integrations tab (Control > Integrations) and click Add Integration. The Add Integration page is displayed.
-
Select Active Directory from the list of available integrations. Here, you are required to complete the following options:
| Option | Description |
|---|---|
|
Name field |
The display name for the integration within Guardian. This name is how you will identify the integration among all others configured in your Guardian instance, so ensure it is descriptive. |
|
Windows Connection Manager Group drop-down list |
The Connection Manager group that is responsible for scanning and retrieving your AD node(s). Select a Windows Connection Manager group from the drop-down list. |
|
LDAP Path field |
The LDAP path for your domain. For example, |
|
LDAP Query field |
Enter the query you want to use to filter nodes within the directory. For example, |
|
Linux Credentials drop-down |
When synchronizing Linux nodes, provide your Linux credentials according to the following:
|
|
Windows Credentials drop-down |
When synchronizing Windows nodes, provide your Windows credentials according to the following:
|
|
Automatically start monitoring and scanning detected nodes checkbox |
Option to automatically start monitoring and scanning your nodes once the AD integration has been created. If selected, the imported nodes are automatically added to the Monitored tab (Inventory > Monitored) for regular scanning. Here, you can apply policies, create node groups, and schedule regular scans. For more information, see Monitored Nodes. If not selected, the nodes are added to the Detected tab (Inventory > Detected) for processing. To monitor the detected nodes, you must move them to the Monitored tab. For more information, see |
- Once you have set the correct values for each of the options displayed, click Done to create the AD integration.
If successful, a confirmation message is displayed and the AD integration is added to the Integrations tab of your Guardian instance. If unsuccessful, an error message is displayed. Use the information displayed in the error message(s) to troubleshoot the values in your AD Integration options.
Integration Outcomes
When integrating AD with Guardian, the following outcomes are expected:
- The integration stores the credentials that you supply to Guardian securely, within the database.
- An automatic synchronization (between Guardian and AD) occurs every two hours. For more information on how to alter this interval, see Job Schedule (Control > Job Schedule).
- The sync event calls out to AD using the supplied credentials to return a list of detected nodes and their corresponding details.
- By default, any nodes that Guardian detects within your AD instance are automatically stored within the Detected tab for processing.
- Alternatively, if the Automatically start monitoring and scanning newly detected nodes checkbox is selected, the detected nodes are added to the Monitored tab instead.
Troubleshooting
If you are experiencing issues with your integration, try the following:
- Verify that the account credentials supplied for the integration are correct.
- Depending on how the integration was configured, the synced nodes are either displayed on the Detected tab or the Monitored tab.
- To confirm the status of the integration sync, check the integration sync event in the Events tab (Control > Events) of your Guardian instance. For more information, see Events.

