Active Directory
Nova provisions user accounts and group memberships directly in Active Directory, from creating a new hire's first account to revoking every entitlement when someone leaves.
What Nova does with Active Directory
- Creates user accounts with configurable naming rules for UPN and email address, including a live preview; accounts can start out disabled as pre-staged accounts
- Assigns and removes AD group memberships; groups are tracked by objectGUID and stale references are repaired automatically
- Resolves nested groups so recertification shows inherited permissions, not just direct memberships
- Disables and enables accounts via the userAccountControl flag; passwords are set exclusively over LDAPS, optionally forcing a password change at first logon
- Journals every write with before-and-after state and can roll changes back, including restoring deleted accounts; each revert is checked against the live directory first
- Imports existing users and groups through background jobs and reads last-logon timestamps for inactivity checks
Technical integration
Nova connects over LDAP/LDAPS using the Active Directory profile of its LDAP connector; password operations (unicodePwd) require LDAPS. Objects are referenced by objectGUID, so renames and moves do not break assignments.
In the identity lifecycle
Joiners get their AD account created automatically through lifecycle routines, movers have attributes and groups adjusted, and leavers are disabled. Approved access requests are provisioned as group memberships, and recertification compares the desired state against what is actually in the directory.
All product names, logos and brands mentioned are property of their respective owners. They are referenced solely to describe compatibility and do not imply any partnership or endorsement.