Email securitywithout Entra ID.With your own AD.
Licences, policies, signatures and recipient validation need people and groups. Conbool takes them straight from your local Active Directory, without syncing to the Microsoft cloud.
Why Entra ID often becomes a precondition
Four hurdles for companies with a local directory.
Services read Entra ID only
Many security services take people and groups from Entra ID alone. The local AD first has to reach the cloud through Entra ID Connect.
Sync as a matter of principle
Whoever keeps the directory in-house on purpose does not want to set up a cloud sync for a filter or a signature.
Access into the directory from outside
The alternative would be a published LDAP endpoint or a firewall rule to the domain controller. Nobody wants to own that.
No directory, no recipient validation
If the gateway does not know the valid addresses, it accepts mail for invented recipients and creates bounces.
How the directory agent works
Outbound, with a dry run, without a password.
1. Service on a member server
The agent runs as a Windows service in the domain and signs in to the domain controller with Kerberos over LDAPS. No password is stored.
2. Outbound to Conbool
People, groups and addresses go to Conbool over HTTPS. Nothing has to be opened inbound, Conbool never calls the agent.
3. Every module uses the same data
Licences, policies per group, signature fields and recipient validation at the gateway all draw on the same records.
What the agent brings
Six points from operations.
Nested groups in full
Groups within groups are resolved down to the last person. Three direct entries can turn into seven people.
Recipient validation without Entra ID
Mailboxes, distribution lists, contacts and public folders from the whole forest come along. The gateway rejects unknown recipients.
Dry run and deletion limit
After every change the agent runs dry first. If more than ten percent of people would disappear, it stops.
No right to password data
Read rights are enough. Incremental sync adds two optional replication rights, but not the right to password data.
OpenLDAP too
The same agent reads OpenLDAP and related directories. Credentials stay on the machine.
Side by side with Entra ID
Local AD and Entra ID may run side by side, several agents per tenant too. Every person counts once.
From domain controller to portal.
The agent reads, checks in a dry run and reports outbound.
No inbound access
Kerberos over LDAPS
Dry run before every write
Interval and sync controlled from the portal
Entra ID Connect or directory agent
Two ways for Conbool to know your people.
Directory agent | Sync through Entra ID Connect | |
|---|---|---|
| Entra tenant required | no | yes |
| Personal data in the Microsoft cloud | no | yes |
| Other LDAP directories | yes | Active Directory only |
| Installation | one service, one join key | sync server with its own database |
| Operation in your own data centre | possible | directory in the cloud |
Statements on Entra ID Connect based on Microsoft product documentation.
Frequently asked questions
Is email security possible without Entra ID?
Is the directory agent an alternative to Entra ID Connect?
Which ports have to be open?
Which rights does the agent need?
Are nested groups resolved?
What protects against a wrongly set filter?
Does this work with Conbool from the cloud?
Related solutions
Secure Exchange on premises
Filtering, encryption, signatures and archive for Exchange Server SE.
Encrypt internal email
Route mail between two mailboxes through the gateway.
Outlook add-ins for Exchange Server
Five add-ins without Microsoft 365 and without typing a code.
Encryption for Exchange Server
S/MIME, PGP, PDF and portal centrally at the gateway.
Signatures for Exchange Server
Automatic signatures with fields from AD.
See it with your own directory
We set up the agent in a test environment and show the first dry run before anything is written.