Securing Enterprise Active Directory
  • Products
    • AD Guardian
    • AD Guardian (+)
    • AD Guardian Cloud – Azure – AAD, EntraID, Office 365 security
    • Entra ID Audit and Recovery
  • About
    • Our Company
    • Press
  • Blog
  • Community
  • Partner
  • Free
  • Contact
  • Demo
  • Support
  • Menu Menu

White Papers
AD News
  • “In virtually every single significant ransomware case… the attacker took advantage of weaknesses in the victim’s Active Directory platform.” – Mandiant
  • |
  • 95 million Active Directory accounts are attacked daily (1000 while you have read this line) – Microsoft
  • |
  • Penetration Testers breach Active Directory almost 100% of the time – IT World Canada
  • |
  • 90% of businesses are vulnerable to breaches from Active Directory mismanagement - DarkReading

The most comprehensive Active Directory solution on the market

Entra ID | Office 365 Real Time Change Alerts

Know all changes as they are made to Entra ID | Office 365 including incorrect logins, access, roles, group membership, PIM, provisioning changes via email, reports and more.

Entra ID | Office 365 Undo

Undo changes from change logs with a click of button.

Entra ID | Office 365 Dashboard

Status of Entra ID at real time, audit changes, risky logins, other critical object status.

Entra ID | Office 365 Restore

Restore specific attributes, objects, entities, single or bulk along with object dependencies and relationships with a click of a button. Quickly view differences between backup images.

Easy Management

Give administrators AD superpowers to effortlessly manage many domains and secure all objects and applications from a single web console.

Advanced Reporting

Unrivalled deep visibility over your entire AD and Enterprise infrastructure with hundreds of OOTB reports with many customization options.

Delegation

Effortlessly delegate tasks to others via role-based access control while reducing high privileged accounts; enhancing your security posture.

Workflow

Easily enforce proper governance for access control of resources (4 stage workflow). Allow resource owners to attest right people and have the right access with no exceptions.

User and Access Provisioning

Policy based user & access entitlement (de)provisioning,while securely managing user life cycle across multiple domains.

GPO Control

Take back control of unwieldy enterprise-wide GPO policies with our specialist solution that standardizes and properly secures enterprise infrastructure.

Real Time Change Alerts

AD is very dynamic! It must be monitored in real-time (e,g, password based attacks); know all changes including the ones that are not picked-up by events/SEIM.

SSPR

Secure Self-Password Reset via many mechanisms for many end targets, easily enforce and apply strong password policies with password ‘disallowed’ dictionaries.

Self Access Management (SAM)

Dynamic groups, self-groups and group membership management, with complete workflow via web/email and audit.

Multi-Factor Authentication (MFA)

Enforce strong authentication using many auth factors (push/pull) for interactive/remote logins of Windows systems and application. Bridge Azure MFA to on-premise applications.

Disaster Recovery – Objects | Attributes

Recover from unintentional accidental changes to the most critical infrastructure – AD. Quickly recover any object down to a single attribute.

Disaster Recovery – Domain | Forest

If AD is severely breached or disaster strikes, your enterprise could be down for days/months; with our software it will be a fraction of this time.

DirSync from OpenLdap

Easily and quickly adopt Office365/Azure AD without needing to change non-Microsoft infrastructure and directory like openLDAP.

Cloud Reports

Easily manage Office365 licenses, permissions via our extensive reports. Quickly know who has what permissions across the enterprise.

Cloud Identity Minder (CIM)

IDP & Proxy Authentication that works with any identity store on the cloud or on-premise. Re-use corporate identities without exposing them to internet risks and remove the need for your applications to manage user life cycles.

Multi-Factor Authentication as a Service

Enforce strong authentication using many auth factors (push/pull) for interactive/remote logins of Windows systems and application.

Automated user, access, entitlement provisioning & de-provisioning

Secure, simple & scalable – the best way to manage user and access life cycle entitlements

  • Workforce and business is very transitionary in nature.
  • Changes are happening to workforce system of record on a daily or weekly basis.
  • Not de-provisioning and revoking access is a “security risk”
  • Automate users, access control of the workforce creation, modification and deletion via nightly runs to IT directory and systems.
  • You don’t have to develop a custom solution, adopt error prone procedures and increase the security risk.
  • Easy to use Web based User Interface, works in collaboration with Active Directory Manager pro.
  • Simple to define templates and policies for provisioning and de-provisioning.
  • NO Scripting and NO coding required.
  • Decision templates.
  • And much more…
End-to-end group policy management

Take back control of cumbersome and unwieldy enterprise-wide GPOs now

Active Directory Group Policy Management allows users administrators to implement specific configurations for users and computers. Group Policy settings are contained in Group Policy objects (GPOs), which are linked to the following Active Directory service containers: sites, domains, or organizational units (OUs).

  • Change control and rollback.
  • Helps prove compliance to ITIL, MOF, SOX, Base I II, HIPAA and C-198.
  • Simplifies and automates critical tasks, reduces outages by eliminating manual process and scripts.
  • Improves availability and disaster recovery via backup and rollback capabilities.
  • Simplifies and improves network security by restricting access to production GPOs.
  • Archives all GPO settings.
  • Version Comparisons: Quickly verify setting consistency and improve GPO auditing with advanced, side-by-side GPO version comparisons at different intervals.
  • Delete version history: to manage and reduce size of backup store.
  • Undo GPO changes: Rolled back to previous versions.
  • And much more…
Real-time change alerts & management

AD is dynamic and changing all the time, make sure you know what’s going on in your enterprise

Active Directory changes daily, yet most IT organizations are unaware of the changes until something breaks. This leads to downtime, loss of productivity, security breaches and higher cost of management and troubleshooting. Furthermore, not all changes generates events, so a typical seim solution will miss many changes.

  • Active Directory changes behind the scenes constantly (not visible with native tools).
  • Critical to take immediate action for any unauthorized changes to “access control”.
  • Relying on just an event log is not sufficient and may be fatal.
  • Monitor all Active Directory activities including administrative activities.
  • Real Time Notifications to administrators for immediate action.
  • Changes logged for analysis and archiving.
  • Easy light weight solution - 100% web-based.
  • Detects who changed what and when (so you can more easily find out why).
  • Filters to get notifications only critical objects.
  • Enterprise-class scalability.
  • Changes logged for analysis and archiving.
  • Reports are easily generated for easy meeting of regulatory compliance
  • And much more…
AD & Enterprise advanced reporting

Day-to-day AD monitoring and compliance are a piece of cake with our powerful reporting tools

CionSystems Active Directory Reporter helps with compliance and day to day status checks by accessing, interpreting and presenting the raw data into meaningful reports. These reports allow the administrator, senior management and auditors to obtain accurate insight into the Active Directory Infrastructure.

  • Complex tasks are simplified (no scripting needed)
  • 100% web based - manage Active Directory from anywhere and any PC running a browser.
User
OU
Group
Policy
Security/ACl
Applications/software
Logon
Forest Info
Trust
Replication
Exchange
Printer
Password
Terminal Server
Computer
Contact
Lync
Workstation
GPO
Advanced LDAP
Fileshare
Scheme and Site
Applications and OS
Server
 
Passwords, access & profile management

Banish password related headaches with our enterprise grade super solution

The easiest, most efficient way to manage your organization’s users, computers, resources, accounts and password resets using the Active Directory, Azure AD, Office 365, Openldap.

  • Reset & Unlock your password with 3 interphases (Web, Mobile, Windows logon).
  • Supports Active Directory, Openldap, Other LDAP compliant directories, Azure AD or Office365, Salesforce, Google apps
  • Out of the box Password dictionary – black list passwords.
  • Notifications for password expiry, locked users, email inbox threshold.
  • Password Synchronization.to many targets like openLDAP, Active Directory, office365, azureAD, salesforce, googleapps etc.
  • Self group creation, membership management for both distribution and security groups with a simplified workflow via email, audit and attestation.
  • Temporary security group membership.
  • Searchable employee directory and other resources, very customizable. Whitepages ala phone directory.
  • Proxy authentication and Web api to authenticate directory with your built in application. SDK for integration
  • Reports for directory, user and audit and much more
MFA for virtual machines or system login

Protect your windows servers, desktops, laptops, tablets, virtual systems in the enterprise & cloud

Imagine unauthorized access to your computer that has everything in it. If the password is compromised then the following may happen.

  • The hacker will have access to all your data, critical files, email, contacts, photos etc.
  • Login to all of your internet accounts.
  • Pretend to be you and send unwanted or harmful emails to your contacts.
  • Use your account to reset the passwords for other accounts (banking, shopping, etc.)
  • Multi factor authentication assures your data and accounts are protected and significantly reduce the chance of being hacked from all intruders.
  • SDK for integration.
  • Token based – Generic USB key.
  • Challenge-Response questions.
  • Out-of-band OTP sent as SMS on phone.
  • Out-of-band OTP sent to registered email.
  • Google & Microsoft Authenticator.
  • And much more…
Disaster recovery

When disaster strikes make sure your enterprise is down for minutes, not months…

Quickly and accurately backup your Active Directory, painlessly recover your Active Directory objects when needed down to a single attribute. You can recover complete domain or different AD objects.

  • Active Directory is one of the most critical components in a Windows environment.
  • Unintentional changes do happen! How to go back to previous state?
  • AD disaster recovery at the object and attribute, and directory level
  • Allows undelete of partitions, containers, objects down to single attributes
  • Restores both system and non-system attributes
  • Restore GPOs, groups, OUs, user objects – easily go back to previous state
  • Easy to use Web based User Interface
  • Backup Active Directory on demand on schedule
  • Recover from disaster and corruptions of objects, containers, domain controller, domain and forest
  • Bare-metal recovery for domain controller, domain or forest
  • And much more…
Delegation & workflow management

Active Directory is the beating heart of your enterprise, it’s time to take the reins & get it under control

AD Guardian provides ALL aspects of operations management, including:

  • Centralize and standardize AD Management
  • Securely manage user life cycle across multiple domains
  • Policy based user provisioning, access management and de-provisioning
  • Eliminates repetitive, routine or complex tasks associated with AD management
  • Facilitates Single or Bulk creation, modification and deletion of AD objects
  • Allows secure management of all users and objects across multiple domains
  • Automates user on-boarding, access management and employee and resource de-boarding
  • User Life Cycle Management
  • Workflow and attestations
  • Delegation
  • Simplified permission management, reporting and audit
  • File share management and permission reporting
  • And much more…

Need help reducing remote worker risk?

Find Out How

About

  • Our Company
  • Press
  • Awards
  • facebook
  • twitter
  • instagram
  • linkedin
  • youtube

Products

  • AD Guardian
  • AD Guardian (+)
  • AD Guardian Cloud – Azure – AAD, EntraID, Office 365 security
  • ADSploit

Blog

  • Azure Active Directory (AAD) Audit: Step-by-Step GuideMay 8, 2025 - 1:41 pm
  • Top Active Directory Security Solutions to Protect Your NetworkFebruary 24, 2025 - 12:23 pm

6640 185th Ave NE, Redmond,
WA-98052.

Phone: 1-425-605-5325

sales@cionsystems.com

Copyright © Cionsystems. All Rights Reserved.
Scroll to top

Winner
of Global Infosec Awards
2021

Cyber Defense Magazine

    Note: By submitting this form you agree to allow CionSystems, Inc. to contact you via email or optionally via the telephone.