Active Directory: add directory context without sending AD passwords

The optional VaultPilot DC Agent runs next to the domain controller and sends approved directory and health information. Neither the AD bind password nor AD user passwords go to VaultPilot.

Synced material
Directory metadata
AD bind password
Stays with the agent setup
Selection
Separate sign-in and import choices
Illustration of a directory agent enrolling next to the domain controller

See the connection state on one screen

The Active Directory screen shows provider status, last sync, domain controller, domain, base DN, agent version, and a searchable tree of OUs, groups, and users. From there you can tell whether a problem lies in the connection or in a selection you have not made yet.

Sign-in and import are chosen separately

You choose in one place which directory identities may sign in to VaultPilot, and in another which managed credential candidates may be imported. A successful sync makes neither choice for you.

Account actions need a verified target

An Owner queues the four account actions below through a connected DC Agent. Each one needs a writable license, a Connected agent that is ready at version 1.2.20 or later and reports the matching capability, and a target bound to a verified directory identity. If that identity evidence is missing or has drifted, the action stays disabled; an ambiguous result goes to audited review. Built-in identities and the agent's bind identity are always protected, and any other privileged target needs a second confirmation.

Reconciliation finishes in the browser

After a sync, encrypted records of users selected for import can take new identity and AD-state details. The server and the agent cannot decrypt a vault record, so this only completes while the matching writable vault is unlocked in an authorized browser.