AD agents · Identity

Your identities and mail systems,
under control.

Lightweight agents collect your Active Directory and your mail systems — Microsoft 365, Exchange, MDaemon: accounts, groups, sign-ins and security events, correlated with everything the SOC detects.

AD / LDAPMicrosoft 365 & ExchangeMDaemonSecurity events
AD + M365
identities unified
Real time
security events
MSI
deployed on the domain controller

Most attacks come through identity: weak accounts, missing MFA, compromised mailboxes. The AD agents collect your directory AND your mail systems (M365, Exchange, MDaemon) and feed SYLink AI: every suspicious sign-in, every dangerous privilege, every brute-force attempt becomes visible — and actionable.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Directories & mail
AD · M365 · Exchange
AD agents
Real-time collection
SYLink AI
Risk score
Account isolated
Before the abuse
In the portal

The directory put under the microscope.

A permanent Active Directory audit — and, above all, what to do about it.

01

Directory posture

console.unisoc.fr/identite
Directory posture
Users, groups, computers, organisational units — with the gaps ranked by severity.
02

The problems to fix

console.unisoc.fr/identite
The problems to fix
Privileged accounts, paths leading to Domain Admin, non-expiring passwords, risky GPOs, LAPS.
03

How to fix it, concretely

console.unisoc.fr/identite
How to fix it, concretely
The problem, why it matters, exactly which objects are affected, what to do about it — with the evidence exportable as JSON.
04

Risk radar and detailed directory

console.unisoc.fr/identite
Risk radar and detailed directory
Exposure across the four axes of an AD audit, then the detail account by account: privileges, department, last sign-in.

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.

Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

Active Directory directory

  • Accounts, groups, OUs, GPOs, privileges
  • Dormant, non-expiring or MFA-less accounts
  • Attack paths to Domain Admin
  • Security events (4625, 4740, 4728…)
  • Push collection from the domain controller (MSI agent)

Mail systems connected

  • Microsoft 365 & Exchange (Graph)
  • MDaemon and third-party SMTP servers
  • Suspicious connections / impossible travel
  • Malicious forwarding rules
  • Compromised mailboxes correlated with the EDR

Driven by SYLink AI

  • A risk score per identity
  • Identity × endpoint × network correlation
  • UEBA detection (abnormal behaviour)
  • Recommendation: disable or reset MFA
  • Signed evidence for the audit

Response & compliance

  • Account disabling (signed command)
  • Password reset and rotation
  • NIS2 / DORA report on identities
  • No data leaves France
  • Complete logging
Use cases

What is it actually for?

Detect a compromised mailbox

A forwarding rule created plus a sign-in from an unusual country: the agent sees it on M365 and SYLink AI escalates an incident.

Spot a path to Domain Admin

A Kerberoastable service account opens a path to privilege: detected, prioritised and fixed before it is exploited.

Prove you have identities under control

Accounts without MFA, dormant or privileged: the report is ready for the NIS2 auditor in seconds.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
SourcesActive Directory / LDAP
Email systemsMicrosoft 365, Exchange, MDaemon
DeploymentMSI agent on the domain controller
CollectionReal-time push plus security events
ResponseDisable or reset (signed)
DataHandled by your SOC in France
Natively integrated with
SYLink AI — identity scoring and correlation
EDR agent — same user, workstation
Mobile XDR — same user, mobile
DPI sensor — network connections
Compliance module — NIS2 for identities
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.