11.2 Integrating Change Guardian with AD or IDM

Change Guardian only provides initiator’s user name and the ObjectSID of an event during auditing activities. However, more information is essential to detect and assess risks. This section provides details the benefits of Change Guardian integration with AD and IDM.

11.2.1 Using Change Guardian with AD

Integration of Change Guardian and AD:

  1. Permits the Change Guardian server to retrieve user information from AD and map with associated incoming events.

  2. Helps map user profiles with attributes in the web console.

These therefore allow you to enrich available information and so better detect and assess risks. Some additional features also include:

  • Receive delta values from AD.

  • Support for adding additional attributes.

  • Support for mapping custom attributes.

  • Synchronize users from multiple user containers concurrently.

  • Synchronize deleted users.

11.2.2 Using Change Guardian with IDM

If you have an IDM license and the application installed, you can integrate it with Change Guardian using the Identity Manager driver.[TBD]