Active Directory: add directory context without sending AD passwords
The optional VaultPilot DC Agent runs next to the domain controller and sends approved directory and health information. Neither the AD bind password nor AD user passwords go to VaultPilot.
- Synced material
- Directory metadata
- AD bind password
- Stays with the agent setup
- Selection
- Separate sign-in and import choices

See the connection state on one screen
The Active Directory screen shows provider status, last sync, domain controller, domain, base DN, agent version, and a searchable tree of OUs, groups, and users. From there you can tell whether a problem lies in the connection or in a selection you have not made yet.
Sign-in and import are chosen separately
You choose in one place which directory identities may sign in to VaultPilot, and in another which managed credential candidates may be imported. A successful sync makes neither choice for you.
Account actions need a verified target
An Owner queues the four account actions below through a connected DC Agent. Each one needs a writable license, a Connected agent that is ready at version 1.2.20 or later and reports the matching capability, and a target bound to a verified directory identity. If that identity evidence is missing or has drifted, the action stays disabled; an ambiguous result goes to audited review. Built-in identities and the agent's bind identity are always protected, and any other privileged target needs a second confirmation.
Reconciliation finishes in the browser
After a sync, encrypted records of users selected for import can take new identity and AD-state details. The server and the agent cannot decrypt a vault record, so this only completes while the matching writable vault is unlocked in an authorized browser.
Limits to know
- A completed sync does not mean every sensitive action is ready or authorized.
- A sync does not upgrade the agent; you update the DC Agent separately.
- Account actions appear only for records that resolve to a current user object in the directory.
Check step by step
- 01
Confirm provider health, agent readiness, and the expected directory identity.
- 02
Review sign-in and credential-import selections one at a time.
- 03
Fix stale or ambiguous identity evidence before you run a sensitive action.
- 04
After a directory change, check the reconciliation and audit results.
Read more in the guides: Active Directory agent guide, Active Directory records screen, Domain dashboard guide