Deploy the passive identity agent
Deploy the passive identity agent software on any machine that is part of a Microsoft Active Directory (AD) domain that you want to use for user awareness and control.
Installation locations and agent types
You can install the passive identity agent software on any of the following machines:
-
The Microsoft Active Directory server
-
A domain controller
-
A client connected to the network that is neither the directory server nor a domain controller
Any particular passive identity agent can monitor one or several Active Directory domain controllers in the same domain.
The machine on which the passive identity agent is installed must communicate with the Cloud-Delivered Firewall Management Center using the TLS/SSL protocol. For more information, see Internet access requirements for the passive identity agent.
You can configure the following types of agents on the Microsoft AD directory server, domain controller, or on any client connected to the domain:
-
Standalone agent: One agent that can monitor one or several Active Directory domain controllers in the same domain.
-
Primary agent and secondary agent: Both can monitor one or several AD domain controllers in the same domain. To provide redundancy, you can install a primary agent and a secondary agent on different machines. The primary agent is responsible for communicating with the Cloud-Delivered Firewall Management Center. If communication fails, the secondary agent takes over.