How-to · Active Directory sync

AD into Monosign,
in four moves.

Treat Active Directory as the canonical source while Monosign sits on top and feeds every downstream app. Delta sync keeps profiles fresh without nightly batches.

  • Delta sync
  • Per-OU base DN
  • ~4 minutes to read
Walkthrough

Source. Mapping. Sync. Delta.

The lifecycle of an AD source — from create to steady-state delta sync.

  1. 01

    Create the AD source in Monosign

    In the admin console, add a new directory source of type Active Directory. Point it at your DC, supply the service account credentials, and specify the base DN you want to sync.

    Tip — Use a dedicated read-only service account for sync — never reuse a domain admin.
  2. 02

    Map attributes

    Map AD attributes (sAMAccountName, mail, displayName, department, groups) to the Monosign identity model. The defaults handle the most common cases, but every org has a few custom fields.

  3. 03

    Run the initial sync

    Trigger the full sync. Monosign pulls the user objects, normalizes them, and applies your attribute mapping. The progress is visible in the dashboard and replayable in the audit log.

    Tip — Start with a small OU to validate the mapping, then expand the base DN.
  4. 04

    Enable delta sync

    Switch from full to delta sync once the initial run completes. AD changes flow into Monosign on a few-minute cadence; webhook-triggered changes can fire in near-real-time.

Ready for the full picture?

The complete walkthrough — with every screenshot, every flag, and version-specific notes — lives in our help center.

Continue in the full docs

Ready to start managing
identities the right way?

Spin up a fully-loaded trial tenant in under five minutes. No credit card. No sales gate.