2AYE
Active Directory defenseCore

Protect privileged directory changes with exact-action runtime authorization.

2AYE now registers certificate-pinned LDAPS connectors, confines changes to a configured base DN, prepares privacy-preserving exact-change fingerprints, consumes a single-use runtime authorization before LDAP execution, and records success or failure receipts.

  • Pinned LDAPS
  • Directory boundary
  • Exact change authority
What you can evaluate

Runtime-enforced Active Directory group and account control through guarded APIs.

01

Pinned LDAPS

Require port 636 and constant-time SHA-256 server-certificate pin validation.

02

Directory boundary

Refuse target or member distinguished names outside the configured base DN.

03

Exact change authority

Bind add member, remove member, or disable account to the agent, environment, connector, and hashed exact target.

04

Connector enforcement

Redeem once before LDAP and record an execution receipt; replay and parameter substitution never reach the adapter.

The enforcement path

Follow Active Directory defense from identity to evidence.

Each consequential action moves through the same six control points. See where 2AYE evaluates authority, requests human review, and preserves the outcome.

  1. 01IdentityWho or what is acting
  2. 02IntentSigned purpose and limits
  3. 03PolicyDeterministic evaluation
  4. 04ApprovalA named human when required
  5. 05ExecutionSingle-use grant, redeemed at the resource
  6. 06EvidenceReceipt joined to the audit chain
Deterministic decisionsSingle-use, exact-action grantsHash-linked evidence
A practical adoption path

Start with one consequential workflow. Prove the boundary before expanding.

01

Scope

Identify tenant, identities, resources, and policy inputs.

02

Configure

Create the required records and immutable policy versions.

03

Enforce

Reject missing, stale, cross-tenant, or insufficient authority.

04

Review

Inspect audit evidence and improve the control.

Review the trust architecture

What this includes

  • Certificate-pinned LDAPS connector limited to its base DN
  • Exact-change grants consumed before the directory change
  • Execution receipts
Your governed workflow

Bring the next consequential action under control.

Show us the actor, protected resource, and action that must never execute without exact authority. We’ll map the decision and evidence path with you.

Discuss your workflow Read the implementation guide
Active Directory Defense | 2AYE