Skip to main content

Entrosity Vertex

Entrosity Vertex manages a tenant's Active Directory from the browser: users with every attribute, passwords, groups and their members, organizational units, Group Policy Objects (links, registry-based settings, security filtering, backups), fine-grained password policies and CSV bulk imports of users. Every change is checked, recorded in the audit log and carried out on a domain controller of the customer's network.

Vertex is part of the Entrosity platform: you sign in on Entrosity Hub and open Entrosity Vertex for your organization, like every Entrosity product. Its address is /vertex on the Hub's host.

Entrosity Vertex is in beta, and its web interface is in development

The Vertex API is ready: everything on these pages can be done through it (Vertex API). The web interface is still being built, so these pages describe what you can do, not where to click. On the Hub, Vertex is registered disabled and in beta: nobody sees it until a platform admin enables it and releases it to organizations (Running Entrosity Vertex).

What it does​

AreaWhat you get
UsersSearch and filter users (by text, OU, enabled, locked, group); create users; change any attribute that is not on the deny list, including binary ones; reset passwords, unlock, enable and disable; move, rename and delete; change group memberships; the same action on up to 500 users at once (Users).
Bulk importCreate or update thousands of users from a CSV file: a preview of every row first, then one confirmed commit, and a result file without passwords (Bulk import).
Groups and OUsCreate groups (security or distribution, any scope), add and remove members; create, rename, move and delete organizational units (Groups and OUs).
Group PolicyList GPOs and where they are linked; create, rename, enable or disable parts of, and delete GPOs; link, unlink, enforce and order links; set registry-based policy settings; security filtering and delegation; backups on the domain controller; the full XML report of every GPO (Group Policy).
Password policiesFine-grained password policies (PSOs): create them, change their settings, and choose the users and groups they apply to (Password policies).
Operations and auditEvery request is an operation with a status, progress and result; every change is in the tenant's audit log.

Vertex does not manage computer accounts, does not change the default domain policies, never touches objects outside the OUs it is given, never changes privileged or built-in objects, and never writes the attributes on its deny list.

How it reaches the directory​

Vertex has no connector of its own. It uses the tenant's Entrosity Axis site connector, installed on a domain controller, which runs a fixed PowerShell script for every request as the AD account configured in Vertex.

  1. Vertex checks a request and records it as an operation.
  2. It queues a job (vertex.op for changes, vertex.read for reads) for the tenant's chosen connector through Axis's internal API. The job carries no secrets.
  3. The Axis connector on the domain controller checks its local guard, then asks for the job's secrets (the AD account's password and any new user passwords). Axis relays the request to Vertex, which checks again that the operation is still allowed and hands the secrets out once.
  4. The connector opens a PowerShell session to its own machine as the AD account and runs the operation with the ActiveDirectory and GroupPolicy modules. The script checks scope and protection again before it writes.
  5. Results come back as the job result, and large ones (a sync, an import, a GPO report) in chunks while the job runs. Vertex updates its mirror.

Nothing on the customer network has to be reachable from the Internet: the connector only connects out to Axis. Protocol details: Vertex protocol.

The mirror​

Lists (users, groups, OUs, GPOs, password policies) come from Vertex's mirror of the directory, not from a live query, so they are fast and work while the connector is busy. The mirror is refreshed:

  • by a sync every 30 minutes (the tenant's interval, 5 to 1,440 minutes) and on request;
  • after every change, with the object as the domain controller returns it;
  • for one object, by a live read that also returns every attribute and which attributes the AD account may write.

A sync reads users, groups, OUs, password policies and GPOs of the whole domain, including what lies outside the managed OUs (shown, but not changeable). Users always get a core set of attributes; the tenant can add more in the settings.

Operations​

Every request that reaches the directory, a change or a live read, is an operation:

StatusMeaning
pendingChecked and recorded; being handed to Axis.
queuedWaiting for the connector.
runningThe connector is running it (with progress for long ones).
succeededDone; the mirror is updated.
failedRefused or failed, with an error code (Troubleshooting).
cancelledCancelled by a user before it finished.
timeoutNo answer in time.

A queued operation that the connector has not started within an hour (six hours for an import batch) is not run any more. A change runs for at most 10 minutes, a read for 30 minutes and an import batch for an hour. Changes run one at a time, in order on the connector; reads can run next to them.

Safety layers​

A change reaches Active Directory only when all of these agree:

  1. Your role. You hold the permission for the operation in that tenant (Roles). The helpdesk is limited to password resets, unlocks, enabling and disabling, contact attributes and group membership.
  2. Write switches. The tenant's directory settings allow this kind of change: users, groups, OUs, GPOs, password policies, and separately deletes. All are off by default.
  3. Managed OUs. The object (and, for a move or a new object, the target OU) is one of the tenant's managed OUs or below one. Everything else is read-only.
  4. Protected objects. Privileged and built-in objects are never changed: adminCount=1 (members of administrative groups and those groups), isCriticalSystemObject, and objects whose relative ID is below 1000. Nobody can add a protected object to a group through Vertex. The Default Domain Policy and Default Domain Controllers Policy are read-only.
  5. Denied attributes. Identity, security, delegation and password attributes are never written through attribute edits (the list); passwords, membership, enabling and names have their own operations.
  6. Change limits. At most 600 changes per user and 2,000 per tenant per minute (429 rate_limited; each member and each registry value counts). A committed bulk import is one confirmed action and is not limited per minute.
  7. Step-up. Changing the directory settings, every delete and committing a bulk import need a fresh confirmation of your password on the Hub.
  8. Checked again when it runs. When the connector asks for the job's secrets, Vertex checks again that the operation is live, the switches are still on, the connector is still the chosen one and the author still holds the right. A right taken away after the request stops it (author_revoked). The secrets are handed out only once.
  9. The connector's local guard. A local administrator of the domain controller must accept the managed OUs and switch on GPO, password policy and delete changes locally; the connector also caps writes per minute (The connector's local guard). Nothing over the wire changes the guard.
  10. Checked on the domain controller. The script checks the managed OUs, protection and the denied attributes again before every write; it is the final authority.
  11. The AD account's own rights. The script runs as the configured AD account, so Active Directory refuses anything that account was not delegated (access_denied).
  12. Audit. Every change is recorded in the tenant's audit log with its author, target and parameters, never with a password. GPOs are backed up on the domain controller before every change and before deletion.

The AD account's password and new user passwords are stored encrypted (AES-256-GCM) and are never returned by the API, shown in operations or written to the audit log.

Concepts​

Tenants​

A tenant is a customer organization: an organization on Entrosity Hub with Entrosity Vertex enabled, with the same ID. One tenant manages one Active Directory domain through one chosen connector.

Directory settings​

Per tenant: the connector (an Axis connector of the tenant on a domain controller), an optional specific domain controller to talk to, the AD account (DOMAIN\name or name@domain) and its password, the managed OUs (up to 100), the default user OU for new users, the UPN suffix for new logon names, extra user attributes for syncs, the sync interval and the write switches (Getting started).

Objects​

Users, groups, OUs (and the domain itself) and password policies are objects, identified by their objectGUID, so a renamed or moved object keeps its identity. Each has in_scope (below a managed OU, so changeable) and protected (never changed).

Signing in​

  1. Sign in on Entrosity Hub (https://hub.entrosity.com).
  2. Open Entrosity Vertex for your organization. You need a Vertex role there: Tenant admin or Helpdesk (Roles). Organization admins give roles on the Hub (Organization members).

In this section​

For operators of the server: Running Entrosity Vertex. For integrators: Vertex API and Vertex protocol.