Active Directory · LDAP

Email securitywithout Entra ID.With your own AD.

Licences, policies, signatures and recipient validation need people and groups. Conbool takes them straight from your local Active Directory, without syncing to the Microsoft cloud.

Why Entra ID often becomes a precondition

Four hurdles for companies with a local directory.

Services read Entra ID only

Many security services take people and groups from Entra ID alone. The local AD first has to reach the cloud through Entra ID Connect.

Sync as a matter of principle

Whoever keeps the directory in-house on purpose does not want to set up a cloud sync for a filter or a signature.

Access into the directory from outside

The alternative would be a published LDAP endpoint or a firewall rule to the domain controller. Nobody wants to own that.

No directory, no recipient validation

If the gateway does not know the valid addresses, it accepts mail for invented recipients and creates bounces.

How the directory agent works

Outbound, with a dry run, without a password.

1. Service on a member server

The agent runs as a Windows service in the domain and signs in to the domain controller with Kerberos over LDAPS. No password is stored.

2. Outbound to Conbool

People, groups and addresses go to Conbool over HTTPS. Nothing has to be opened inbound, Conbool never calls the agent.

3. Every module uses the same data

Licences, policies per group, signature fields and recipient validation at the gateway all draw on the same records.

What the agent brings

Six points from operations.

Nested groups in full

Groups within groups are resolved down to the last person. Three direct entries can turn into seven people.

Recipient validation without Entra ID

Mailboxes, distribution lists, contacts and public folders from the whole forest come along. The gateway rejects unknown recipients.

Dry run and deletion limit

After every change the agent runs dry first. If more than ten percent of people would disappear, it stops.

No right to password data

Read rights are enough. Incremental sync adds two optional replication rights, but not the right to password data.

OpenLDAP too

The same agent reads OpenLDAP and related directories. Credentials stay on the machine.

Side by side with Entra ID

Local AD and Entra ID may run side by side, several agents per tenant too. Every person counts once.

Directory agent · Windows service
Active Directory
Domain controller
OU Administration · 42
OU Sales · 18
OU Engineering · 27
Directory agent
Member server
KerberosLDAPS 636
HTTPS 443 outbound
Nothing open inbound
Dry run
before the first write
+87
new
0
changed
0
removed
Group Field sales: 3 entries, 7 people
Directory agent

From domain controller to portal.

The agent reads, checks in a dry run and reports outbound.

No inbound access

Kerberos over LDAPS

Dry run before every write

Interval and sync controlled from the portal

Entra ID Connect or directory agent

Two ways for Conbool to know your people.

 
Directory agent
Sync through Entra ID Connect
Entra tenant required
no
yes
Personal data in the Microsoft cloud
no
yes
Other LDAP directories
yes
Active Directory only
Installation
one service, one join key
sync server with its own database
Operation in your own data centre
possible
directory in the cloud

Statements on Entra ID Connect based on Microsoft product documentation.

Frequently asked questions

Is email security possible without Entra ID?
Yes. Conbool reads people, groups and addresses straight from the local Active Directory through the directory agent. An Entra tenant and a cloud sync are not required.
Is the directory agent an alternative to Entra ID Connect?
For Conbool, yes. It does not replace the sync to the Microsoft cloud for other services, but it gives Conbool everything that licences, policies, signatures and recipient validation need.
Which ports have to be open?
None inbound. The agent reaches the domain controller over LDAPS on port 636 and Conbool over HTTPS on port 443.
Which rights does the agent need?
Read rights on the user objects. Incremental sync adds DS-Replication-Get-Changes and DS-Replication-Get-Changes-In-Filtered-Set, both optional. DS-Replication-Get-Changes-All is not required.
Are nested groups resolved?
Yes. In Active Directory the server resolves the chain through the matching search rule, in other LDAP directories the agent walks the chain itself.
What protects against a wrongly set filter?
After every change the agent runs a dry run. In addition it stops every run in which more than ten percent of people would disappear.
Does this work with Conbool from the cloud?
Yes. The join key carries the target, and the same package works with the cloud and with an installation in your own data centre.

Related solutions

See it with your own directory

We set up the agent in a test environment and show the first dry run before anything is written.