No second password
Credentials stay in the directory. isidaten checks against it and stores no separate password for those accounts.
Sign in with the account that already exists
Another password is the fastest route to poor adoption. So in isidaten, whoever can sign in to the directory can sign in here: authentication runs directly against Active Directory or an LDAP server. Users do not have to be created by hand; they come from the isidaten agent AD scan. And what someone is allowed to do is decided by group membership in the directory, which is maintained there anyway.
Vendor: Microsoft / OpenLDAP · learn.microsoft.com/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview
Credentials stay in the directory. isidaten checks against it and stores no separate password for those accounts.
Whoever leaves an AD group loses the corresponding role. Maintenance stays where it already happens instead of being replicated in a second permission system.
Users come from the same AD scan that fills the inventory. Anyone in the directory does not have to be entered a second time.
We show you the connector live in your own environment – non-binding and free of charge.