# Active Directory

**Categories:** SSO / Identity

Sync Active Directory users and automate access provisioning across your network.

Active Directory is Microsoft's directory service for managing users, groups, and devices across an organization's network. Integrating Active Directory with Harmony ensures that employee identity data stays automatically synchronized, so access rights and IT workflows always reflect your current organizational structure. This connection allows Harmony to intelligently route tickets, enforce role-based permissions, and trigger automated onboarding or offboarding processes.

## Capabilities

- **User Sync**: Automatically import and update user profiles, groups, and organizational units from Active Directory into Harmony.
- **Role-Based Access Control**: Map Active Directory groups to Harmony roles to ensure employees have the correct permissions without manual intervention.
- **Automated Onboarding & Offboarding**: Trigger IT service workflows in Harmony when users are added, modified, or removed in Active Directory.

## What Harmony does with Active Directory

Connecting Active Directory lets employees handle common account and access requests, joining a group, getting into an app, right inside Slack or Teams, instead of filing a ticket. Your IT team gets one place to see everyone's account, attributes, and group memberships without switching consoles. When someone joins, moves, or leaves, the right access follows automatically.

## Data synced

- User profiles and account status (active or disabled)
- Contact and job details, such as email, phone, title, and department
- Group memberships for each person
- Connected apps whose access is driven by group membership

## Actions available

- Create a new account with the right attributes during onboarding
- Add or remove someone from a group to grant or pull access
- Disable an account as part of offboarding
- Update user details, such as title or department, after a role change

## Real-world use cases

**New hire, day one**: A new engineer starts and needs their account and access ready. Harmony creates the Active Directory account with the right attributes and adds them to the correct groups, so they can log in from the first morning.

**Access to a shared app**: Someone needs into a team app that's driven by group membership. They ask Harmony, it adds them to the right group, and access follows automatically.

**Clean offboarding**: When someone leaves, Harmony disables their Active Directory account and removes group memberships as part of the offboarding workflow, so nothing stays open.

## Related integrations

- [Microsoft Entra ID](/integrations/microsoft-entra-id)

- [Okta](/integrations/okta)

- [JumpCloud (IdP)](/integrations/jumpcloud-idp)

## FAQ

### What is Active Directory?

Active Directory is Microsoft's on-premises directory that stores your employee accounts and controls what they can access, managed by IT teams to run access across the company. Connecting Active Directory lets employees handle common account and access requests, joining a group, getting into an app, right inside Slack or Teams, instead of filing a ticket.

### What data does Harmony sync from Active Directory?

Harmony's Active Directory integration syncs the following into a single agent inventory: user profiles and account status (active or disabled); contact and job details, such as email, phone, title, and department; group memberships for each person; and connected apps whose access is driven by group membership.

### What can I do with Active Directory through Harmony?

Through the Active Directory integration, Harmony can create a new account with the right attributes during onboarding; add or remove someone from a group to grant or pull access; disable an account as part of offboarding; and update user details, such as title or department, after a role change.

### How does the Active Directory integration help IT teams?

A new engineer starts and needs their account and access ready. Harmony creates the Active Directory account with the right attributes and adds them to the correct groups, so they can log in from the first morning.

### What other integrations pair with Active Directory in Harmony?

Active Directory is commonly paired with Microsoft Entra ID (SSO / Identity), Okta (SSO / Identity), and JumpCloud (SSO / Identity) inside Harmony, giving IT one unified view across related systems.