Identity Management

AD Connect Sync

One-to-One

Synchronize your identities from any on-premises Active Directory to the Cloud.

Download

(30-day free trial)

One-to-One Active Directory synchronization topology
One-to-Many Active Directory synchronization topology
Many-to-One Active Directory synchronization topology
On-premises Active Directory to cloud IAM synchronization
Active Directory synchronization to heterogenous targets

Synchronization of Identity Data

Hosting Controller's AD Connect Sync is a synchronization tool between source Active Directory instances and multiple other targets.

Single Source of Truth Architecture

Hosting Controller's AD Connect Sync, is a tool designed to support an architecture where the existing on-premises Microsoft Active Directory serves as the single source of truth for core Identity and Access related data. This core data includes:

  • User Accounts
  • Passwords
  • Groups
  • Group Memberships

Watch Video

See how AD Connect Sync synchronizes identities across Active Directories.

Active Directory to Cloud IAM Synchronization

Enable an organization to setup automatic synchronization between master AD and one or more public IAM systems including Amazon AWS, Microsoft 365, Microsoft Azure, Google Cloud Platform, and any other cloud hosted Active Directory. Synchronize identities, group membership and passwords to various IAM targets with ease.

Active Directory to Cloud IAM Synchronization and integration with IAM targets like Amazon AWS, Microsoft 365, Azure, Google Cloud Platform, and other cloud-hosted directories.

Various IAM Targets

Synchronize identities, group membership and passwords to various IAM targets with ease.

  • Amazon AWS
  • Microsoft 365
  • Microsoft Azure
  • Google Cloud Platform
  • Any Other Cloud Hosted Active Directory
Read More

AD Connect Sync Is Not Standard AD Replication

Used to synchronize Active Directory data where normal Active Directory replication cannot be used for any reason.

Active Directory to Active Directory Synchronization

Enables one master Active Directory and changes are synchronized to other AD instances.

Synchronize Passwords

Keep your Active Directory passwords synchronized across your internal and external Active Directories. Make it easier for administrators to replicate and track password changes across Active Directories.

Synchronize Identities

Perform one-way synchronization of identity data (users, groups) between master AD and your hosted Active Directory. Manage account changes across multiple systems.

Synchronize Group Memberships

Reflect group membership changes made in master Active Directory, to the hosted environment in real-time. Provide a complete and efficient identity management solution to your business.

Multi-Cloud Synchronization

The bulk of security still revolves around having users, identified by their passwords, having access to resources through a role based security or group policy. Organizations have spent years maturing their Active Directory infrastructure and processes. As an organization onboards yet another public cloud, it comes with its own set of IAM (Identity and Access Management) paradigm. While configuring security and group policies is an allied and most important task of onboarding another cloud platform, the regular assignment and revocation of those policies to users quickly becomes an operations nightmare if not automated. Hosting Controller is a unified cloud management tool and includes support for multi-cloud deployment in different ways. But all those features share a way to synchronize changes between local master Active Directory environments and public cloud IAMs. It synchronizes:

User Accounts

As a user is created in the master Active Directory, its replicated across multiple public cloud IAMs.

Passwords

Passwords are changed in the master Active Directory only through whatever security means are already in place for the organization. As soon as the password is changed in the master AD, it is automatically synchronized into multiple targets.

Group Memberships

As a user is assigned or revoked a group membership, it is synchronized in the IAM.

Comparison with AD Connect Sync Plus

Let's see how AD Connect Sync desktop solution compares to our advanced AD Connect Sync Plus web-based edition.

AD Connect Sync

Desktop Solution

AD Connect Sync is a desktop solution.

Installation

Direct installation on Domain Controllers.

Local Control

Management at the entity level with more local control.

Uni-Directional Password Sync

One-way sync of passwords.

Single Access Control

A user with significant privileges can log in to the DC.

Decentralized Logging

Logging available individually on the entity sites.

AD Connect Sync Plus

Web Based

AD Connect Sync Plus is a web-based solution.

Installation

Installation required only on Mediation servers.

Central Management

Central management via a single console.

Bi-Directional Password Sync

Two-way sync of passwords.

Multiple Admins

Multiple admins have administrative control.

Central Logging

Centralized monitoring, logging, and reporting.

Steps to Onboard a New Public Cloud

Steps to Onboard a New Public Cloud

Supported Deployment Topologies

As your organization evolves and finds its optimum mix of on-prem and cloud based services, AD Connect Sync tool is there to support any and all Identity management topologies.

One-to-One

One-to-One

One Source - One Destination. Typical Use Case: On-Prem to Cloud.

One-to-Many

One-to-Many

One Source - Multiple Destinations. Typical Use Cases: Distributed Applications.

Many-to-One

Many-to-One

Multiple Sources - One Destination. Typical Use Case: Cloud Service Provider.

Highlight Features

No trust relationship required

No Trust Relationship Required

No trust relationship is needed between the source and the destination

Administrator full control

Administrator Full Control

Admins can choose just what they want to copy down to a single user, group or contact

Real time synchronization

Real Time Synchronization

Passwords are also copied in real-time and synchronized automatically across all targets

LDAP compliant Active Directory

LDAP Compliant Active Directory

Uses LDAP to synchronize between Active Directories

Copying rules

Copying Rules

Copying rules enable rule based changes to data as it is being copied

Audit Trail

Audit Trail

Maintains an audit trail of all activity through comprehensive logging

Don't Expose Your Domain Controllers

Synchronize without exposing your Domain Controllers to unwarranted and unneeded installations.

  • Deploy on a Mediation Server Instead.
  • Communicate via Mediation Server.
  • Keep Domain Controllers Secure.
  • Avoid Opening Unnecessary Ports.
Learn More
Secure Synchronization Without DC Exposure

Use Cases

The business scenarios and rationale for using AD Connect Sync.

Single Source of Truth Architecture

Single Source of Truth Architecture

SSOT (Single Source of Truth) is a strategy and software architecture with its roots in data science, where every piece of data is mastered in exactly one place. Applied to identity, your on-premises Active Directory becomes that single master, and AD Connect Sync copies its users, passwords and groups outward to every other directory that needs them, so there is never a conflicting or stale copy of an identity to reconcile.

Read More
Cloud Synchronization

On-Prem to Cloud Synchronization

As cloud adoption increases, organizations are finding requirements to copy their identity data into many different Active Directory repositories in the cloud. If you are moving to AWS Active Directory or any other hosted Active Directory in the cloud, AD Connect Sync is the tool to do that.

AD Consolidation for Mergers & Acquisitions

AD Consolidation for Mergers

No two mergers ever go the same way. If you are faced with a task to arrange for the merger...

Read More
Amazon AWS Affinity for Active Directory

Amazon AWS Affinity for Active Directory

If your organization has moved many applications to Amazon AWS and you realize a need to...

Read More
Separate Single Sign-On

Separate Single Sign-On

Single Sign-on Application require public access to the AD. While most Active Directories are hosted on-prem and may be in a very secured network usually running only on Private IP addresses, it is easier for many reasons to host a copy in the cloud with just enough access to enable Single Sign-On.

Non-VPN Access for Active Directory

Non-VPN Access for Active Directory

For an organization running an master Active Directory server, all users need to login...

Read More
Read Local Repositories

Read Local Repositories

When applications are running distributed into many clouds, a local repository hosted close to the application has many benefits. If the application is made to access a remote repository, the latency and bandwidth requirements are huge. If the application only needs a subset of AD attributes, AD Connect Sync can be made to copy only the required parameters.

Business Continuity During Migrations

Business Continuity During Migrations

As cloud adoption grows, so does a need to arrange migrations. It may seem ideal...

Read More
Multi-Tenant Host

Multi-Tenant Host

This use-case was typically for the service providers where they would host a service requiring Active Directory authentication....

Read More

Easy Monitoring

It is important that you maintain a healthy synchronization between your local and Cloud Active Directories. Quickly spotting and diagnosing anomalies is the key to success. AD Connect Sync is accompanied by a robust monitoring tool, which not only identifies any bottle necks in the whole process but also makes available visual representations in the form of daily and weekly stats and reports.

  • Monitor multiple sync machines across different Domain Controllers, through a single interface.
  • Generate necessary alerts, if communication breaks either from the local AD or from the Cloud side.
  • Display system activation status.
  • Weekly and daily graphical representation of synchronized data.
  • Display number of sync objects in an organization.
  • Live view from different AD machines.
  • Advanced search filter to view successful/failed events.

Monitoring Views

Dashboard
Dashboard
Live View
Live View
Search
Search
Security Key
Security Key

Why HC ADSync?

There are plenty of good reasons to use HC ADSync for synchronizing your master AD identities with those in the Cloud. The most important ones are:

Simpler Implementation

HC ADSync is far easier to implement than other more complex options. Installing and configuring HC ADSync simply involves a few one-time configuration steps. HC ADSync is a simple service which requires an installation over the primary (or additional) domain controllers. Once installed, AD objects can be selected to initiate the sync process between the ADs.

Minimal Complexity

HC ADSync does not require a two-way trust relationship to be established between domains, neither does it demand the added complication of deploying an ADFS infrastructure. No additional servers, SSL certificates or DNS entries are required. This keeps the deployment lightweight and reduces the ongoing maintenance and security overhead, so your team can be up and running quickly without changing the existing network topology.

Reduced Costs

Costs can be cut substantially by deploying AD Connect Sync. There are no additional costs to consider above those of the licenses whereas other more expensive alternates like ADFS require additional server licensing, SSL certificates, hardware costs and/or virtual infrastructure resources and consultancy costs.

Read More

Real-Time Synchronization Features

Core features and functionality of AD Connect Sync.

Synchronize Users

Push newly provisioned users to the hosted/Cloud environment.

Synchronize User Passwords

Intercept changes to user passwords on the master AD in real time and replicate to related user object on the hosted AD.

Synchronize User Attributes

Sync any changes to user attributes such as displayName, company, mobile etc.

Synchronize Groups

Push newly created Distribution and Security groups to the hosted/Cloud environment.

Synchronize Group Attributes

Sync group attributes to the hosted environment.

Change Group Membership

Synchronize any membership changes to the Cloud environment.

Synchronize Contacts

Replicate new contacts seamlessly between master AD and Cloud.

Specify Sync Intervals

Choose convenient time intervals for synchronization.

Transfer Securely

Send requests securely over LDAPs.

Customize Attributes

Enable or prevent selected few attributes of a user to be synchronized.

Synchronize Required Users

Choose required few users, groups and contacts from a specific organization (OU) to be synced.

Synchronize across Multiple Cloud DCs

Synchronize a single local AD with multiple Cloud Domain Controllers.

Benefits

AD Connect Sync gives you a straightforward, lightweight way to keep identities consistent across on-premises and cloud directories, without the cost and complexity of heavier alternatives. It installs directly on your domain controllers, needs no two-way trust or ADFS infrastructure, and keeps working quietly in the background so administrators spend less time reconciling accounts and more time on higher-value work. The result is a simpler, more secure identity foundation that scales with your business.

  • Less complex alternative to Single Sign-On (SSO).
  • Does not require a two-way trust relationship to be established between domains.
  • A lightweight solution for synchronizing users, passwords and groups.

Showcase

AD Connect Sync Interfaces at a Glance

Local AD Setting
Local AD Setting
Cloud AD Setting
Cloud AD Setting
AD Attributes
AD Attributes
Logging
Logging
Auditing
Auditing
Sync Service
Sync Service
Licensing
Licensing
Diagnose
Diagnose
About
About
Synchronization Flow
Synchronization Flow
Objects Synchronized
Objects Synchronized

Have Questions?

Contact Now