Skip to main content
Sticky

Monthly Buzz - July - ADB

  • July 31, 2026
  • 0 replies
  • 24 views

Active Directory best practices

Before taking any actions with Active Directory, review these best practices carefully.
 

AD Bridge Cells provide a means of directly managing Unix identities in Active Directory. Best practices are to use Cells rather than Unprovisioned mode wherever possible.

This is so a user’s Unix group membership can be limited to less than 16 groups when required for NFS (or 32 groups for Solaris) without impacting normal Windows group membership management practices.
 

Directory Integrated mode

After installing the AD Bridge tools, the first determination that must be made regards Directory Integrated or ID Range. Directory Integrated Mode is strongly preferred.

This causes all lookups to use indexed attributes in AD, lowering the cost of each lookup against the AD domain controller (DC). Windows 2012 Forest Mode forests with Windows 2012 R2 domain controllers can be transitioned to Directory Integrated Mode without extending the AD Schema.
 

Cell design

AD Bridge Cells allows managing overlapping Unix identities within a single Active Directory organization for AD Bridge. There are two possible cell structures:

  • Named Cells store Unix identity information (uid, uidNumber, gidNumber, gecos, unixHomeDirectory, logonShell) in a subcontainer of an associated Organizational Unit (OU). Users can come from the local domain or a trusted domain, but their Unix identity data is always stored in the domain where the computer is joined.

  • Default Cell is a single, enterprise-wide cell that spans all trusted Microsoft Active Directory Global Catalogs. Individual AD domains opt in by creating a Default Cell object at their domain root. Unix identity information is stored alongside the user object it belongs to, enforcing one Unix identity per AD user across the enterprise. The Default Cell is the authoritative source for Unix identity information.

 Click HERE to continue reading.

 

Customer Case Study
ivision: How ivision Simplifies and Scales Identity Security with BeyondTrust  
 

Latest Available Versions
AD Bridge 26.1 - May 2026
AD Bridge 25.2 - November 2025
 

BeeKeepers Community

AD Bridge Agent Installation without restarting the server
“Hi community, I'm deploying AD Bridge in a production environment, and the client has a high-availability infrastructure where server restarts are not permitted. Is it possible to install the AD Bridge agent without requiring a server reboot after the installation?” 

Reply: “A reboot necessarily isn’t required for AD Bridge, and isn’t listed in the documentation. However, when testing, first install ADB, join the domain, and test logging in, etc. **before a reboot** to ensure that the connection works as expected. Reboots can validate everything continues to work as expected. 
That said, I always recommend checking in with our professional services teams if you are unsure in a Production environment to ensure migrations and any gotchas can be found early”.

Click here for the most popular articles In our Beekeepers Community

 

Upcoming and In Case You Missed It Webinars
 

Upcoming Road Map: Endpoint Privilege Management Unix & Linux and Active Directory Bridge – August 4, 2026

Blog: Top Vulnerability Trends from the BeyondTrust Microsoft Vulnerabilites Report
Tech Talk Tuesday:
Beyond the Endpoint: Where Privilege Went Next and How Entitle Works – August 4, 2026
Just-in-Time Access to Elevated Cloud Privileges – August 25, 2026

Podcast: The Adventures of Alice & Bob: Red teaming with Cats, Cheese and Drones
Webinars:
Why Zero Trust is Essential for Agentic AI Security – August 6, 2026
Microsoft Vulnerability Landscape 2026: Emerging Risks & Expert Perspectives – August 18, 2026

This topic has been closed for replies.