Skip to content
Anexet
Product
Solutions
Features
Company
Services

Active Directory Integration

Your directory structure syncs into the console at deployment, so every intercepted event ties to a real employee, department and role — not a bare hostname.

Schedule a Demo
Anexet Administrator Console showing directory-synced user cards

Directory Context, Built Into Every Event

Monitoring by machine name loses the context security teams actually need — Anexet pulls your directory structure in at the source so every event carries the name, department, and role of the person behind it.

Most monitoring tools capture data by machine: a workstation name, a network address, an agent ID. What security teams actually need is context — which person, which team, which manager, which policy — and that context lives in your directory service. Anexet pulls it in at the source, at deployment, and keeps it synchronised.

When a directory object changes — a user moves departments, a group is renamed, a new hire is added — Anexet reflects that change in the console. Intercepted communications, activity timelines, policy violations, and reports all carry the current organizational context: full name, department, job title, and the group memberships that determine which agent profile and monitoring scope applies to that person.

Anexet covers three directory scenarios out of the box: local Active Directory for on-premise Windows domains, FreeIPA for Linux-native infrastructure on the same integration model, and Microsoft Entra ID for organizations running cloud or hybrid tenants. Entra ID sync keeps user profiles current automatically as your cloud directory changes — no manual re-mapping step.

Organizations intercepting mail through Microsoft 365 benefit from the same identity layer: see the Microsoft 365 mail interception feature page for the cloud mail connector that pairs with Entra ID sync.

Why it matters

  • People, not machines

    Every intercepted event, screenshot, and alert is tied to a named employee with department and role — not a raw device ID.

  • Policy by directory object

    Assign agent profiles and monitoring scope to OUs, security groups, or individual accounts — adding a user to the right group configures them automatically.

  • Always in sync

    New hires, movers, and leavers are reflected automatically so monitoring coverage tracks the live organizational structure.

What Directory Integration Covers

Active Directory, FreeIPA, and Microsoft Entra ID integration are all included from the Standard plan and form the foundation for every capability built on top.

Directory sync & user cards

  • Active Directory sync

    Standard

    User cards created and updated from your on-premise Active Directory domain controller.

  • Microsoft Entra ID sync

    Standard

    Automatic synchronization of user profiles for cloud and hybrid tenants on Microsoft Entra ID (formerly Azure AD). Pairs with the Microsoft 365 mail connector for organizations covering both identity and cloud mail interception.

    Learn more
  • FreeIPA integration

    Standard

    Linux-native infrastructure covered through FreeIPA — the same integration model as Active Directory, no separate workflow.

  • User identity attributes

    Standard

    Display name, department, job title, email, manager, and group memberships synced into user cards in the Client Console.

Agent assignment & policy scope

  • Directory-object agent rights

    Standard

    Assign agent profiles and monitoring scope to OUs, security groups, or individual accounts — not per-machine lists.

  • Organizational context in console views

    Standard

    Department, job title, and manager visible in profile cards; filter investigations, reports, and search results by team or role.

  • Automatic coverage for new hires and movers

    Standard

    Directory changes — new accounts, department moves, leavers — reflected in Anexet so policy coverage stays current.

Foundation for advanced capabilities

  • Security Policies & Blocking Rules

    Advanced

    Directory-linked user identity used for policy targeting and alert routing.

  • Risk Analysis & User Relations graph

    Premium

    Risk scores attributed to named employees; relations graph maps communication between known directory objects.

  • SIEM event export

    Premium

    Security events forwarded to your SIEM platform already carry the directory-resolved user context.

    Learn more

The scope of OUs, groups, and accounts to synchronise is configured during setup, for on-premise Active Directory, FreeIPA, and Microsoft Entra ID alike.

Directory Context Across Every Endpoint Event

When an Anexet agent installs on a workstation, it resolves the logged-in user to their directory record and applies the matching agent profile and monitoring policy. From that point, all data flowing into the Client Console — intercepted communications, activity reports, security policy alerts, Risk Analysis scores — carries the resolved user identity and organizational context, so analysts can search, filter, and build cases by name, department, or group without any manual mapping step.

Anexet is deployed on-premise; the vendor has no access to your data. Directory credentials and synced user attributes stay entirely within your infrastructure and are never transmitted externally.

Anexet Administrator Console showing directory connection configuration
User profile card in the Client Console with department and role from Active Directory

How Directory Integration Works — 4 Steps

From a directory connection configured once to organizational context in every console event.

In the Administrator Console, configure a connection to your directory service — Active Directory, FreeIPA, or Microsoft Entra ID — by providing the domain controller address, bind credentials, and the scope of OUs or groups to synchronise.

1

Anexet reads the directory tree and creates or updates user cards in the Users and Privileges Server, storing display name, department, job title, email, group memberships, and manager hierarchy.

2

Agent deployment rules are written against directory objects — an OU, a security group, or an individual account — so adding a user to the right group automatically applies the correct monitoring configuration on their workstation.

3

All data flowing into the Client Console carries the resolved user identity and organizational context, enabling analysts to search, filter, and build cases by name, department, or group without any manual mapping.

4

In the Administrator Console, configure a connection to your directory service — Active Directory, FreeIPA, or Microsoft Entra ID — by providing the domain controller address, bind credentials, and the scope of OUs or groups to synchronise.

1

Anexet reads the directory tree and creates or updates user cards in the Users and Privileges Server, storing display name, department, job title, email, group memberships, and manager hierarchy.

2

Agent deployment rules are written against directory objects — an OU, a security group, or an individual account — so adding a user to the right group automatically applies the correct monitoring configuration on their workstation.

3

All data flowing into the Client Console carries the resolved user identity and organizational context, enabling analysts to search, filter, and build cases by name, department, or group without any manual mapping.

4

Arrow

Directory Integration by Plan

StandardCore employee activity monitoring.
Network traffic interception
USB control
Printer monitoring
Messenger interception
Browser interception
and 4 more
Most popular
AdvancedAdds DLP and deeper visibility.
Standard plan included
DLP features
Network share monitoring
Keylogger
Webcam pictures
and 4 more
All-in-one
PremiumAll-in-one solution.
Standard + Advanced plans included
Advanced search (digital fingerprints, hash search)
File system monitoring
User relationship analysis
Risk analysis
and 6 more

Frequently Asked Questions

Common questions about Anexet's Active Directory, Entra ID, and FreeIPA integration.

Which directory services does Anexet integrate with?

Anexet integrates with local Microsoft Active Directory (on-premise), FreeIPA for Linux-native infrastructure, and Microsoft Entra ID (formerly Azure AD) for cloud and hybrid tenants — all three supported from the Standard plan. Entra ID sync automatically keeps user profiles current in cloud and hybrid environments.

The integration syncs user identity attributes — display name, department, job title, email address, manager, and group memberships — along with the organizational unit structure. These appear in user cards in the Client Console and are used to filter reports, search results, and security policy views by team or role.

Yes. This is the primary operational benefit of directory integration. Agent profiles and monitoring scope are assigned to directory objects — security groups, OUs, or individual accounts — so that adding a user to the right group automatically applies the correct monitoring configuration on their workstation, without updating a list of machine names.

Changes in the directory — new accounts, moves between departments, leavers — are reflected in Anexet through synchronization, so monitoring coverage tracks the live structure. The sync interval and scope are configured in the Administrator Console. Specific sync cadence can be confirmed during the demo.

Yes. Active Directory, FreeIPA, and Microsoft Entra ID integration are all included from the Standard plan and are the foundation for everything else: Advanced policies, Premium risk analysis, and SIEM event export all rely on the user context this integration provides.

Anexet is deployed on-premise; the vendor has no access to your data. The directory credentials and synced user attributes stay entirely within your infrastructure and are never transmitted to Scinero or any external server.

SIEM integration is included in the Premium plan. It forwards security events — already enriched with the directory-resolved user identity — to your SIEM platform.

Three professionals collaborating and looking at a tablet in a meeting

Connect Your Directory to Anexet

Tell us about your directory infrastructure — Active Directory, FreeIPA, or Entra ID — and we'll show you how Anexet maps your organizational structure to monitoring policies in a demo or a free trial.

I accept that my personal data can be processed in accordance with the Privacy Policy