Active Directory integration
Integrates on-premises Active Directory to bring AD objects, GPO context, and authentication data into service workflows.
What it connects
- User accounts, organizational units, security groups, and distribution lists from on-premises AD.
- Group Policy Objects, linked OUs, and GPO setting details for configuration visibility.
- Account lockout events, password expiry timelines, and logon audit data for proactive support.
- Computer objects, domain trust relationships, and site topology for infrastructure mapping.
What it automates
- Unlock accounts and reset passwords directly from self-service tickets without AD admin involvement.
- Add users to security groups upon access request approval, provisioning access end-to-end.
- Detect and alert on stale accounts exceeding inactivity thresholds to reduce attack surface.
- Correlate account lockout events with source workstation data for faster incident diagnosis.
In practice
Account lockout tickets are auto-enriched with the source workstation, lockout timestamp, and bad password count from AD, enabling agents to resolve without manual log hunting.
STLabs detects that a user's password expires in 3 days and proactively sends a self-service reset link, preventing the inevitable Monday morning lockout ticket.
Security group membership requests are validated against OU-based policies and approved memberships are provisioned directly in AD, closing the ticket end-to-end.
Stale computer objects inactive for 90+ days are flagged with tickets for review, keeping AD clean and reducing attack surface.