HYBRID ENVIRONMENTS & OUTPOSTS

Connect existing systems and locations without fragmenting the identity lifecycle.

SYNRION Outposts bring directory, CA and policy functions closer to separated environments. Users, computers, security keys and external systems remain part of one controlled x.ID model.

VALUE IN 30 SECONDS

Distributed components. One visible lifecycle.

01

Use existing identity sources

Active Directory and Microsoft Entra ID use separate target-specific connector paths instead of being copied into a new directory silo.

02

Reach separated environments

Outposts provide defined connector functions for networks, tiers or sites that should not expose their infrastructure directly.

03

Keep communication authenticated

Outpost communication uses mTLS and service identities that can be operated through gMSA and hardware-protected keys.

FROM ONE SERVER TO DISTRIBUTED CONTROL

How does x.ID grow across directories, CAs and network boundaries?

Growth does not require every system to move into one network or directory. It requires clear connector roles, authenticated communication and one consistent identity and policy model.

  1. 01

    Connect identity sources natively

    Connect on-premises Active Directory through the LDAP Connector and Microsoft Entra ID directly through the native Azure Connector so users, computers and assigned credentials can be controlled together.

  2. 02

    Publish the certificate and strong mapping

    After successful issue, establish the target state not only in x.ID but also in the intended Microsoft identity systems.

  3. 03

    Place connector roles deliberately

    Deploy Outposts where CA, directory or policy functions need a controlled local connection across a trust or network boundary.

  4. 04

    Authenticate every Outpost path

    Use mutually authenticated TLS so both ends of the connection are known and the transport remains encrypted.

  5. 05

    Connect multiple certification authorities

    Add existing internal or public CA paths without creating a separate identity lifecycle for each issuing system.

  6. 06

    Integrate clients and external systems

    Use connected clients where local discovery or action is required and APIs where another platform needs to provide or consume lifecycle data.

  7. 07

    Expand topology without losing oversight

    Arrange Outposts in the topology the environment requires and retain central visibility of identities, hardware, policies and lifecycle state.

THE ARCHITECTURE AT A GLANCE

AD DS and Microsoft Entra ID remain distinct target systems: the LDAP Connector maintains the local certificate and strong mapping, while the Azure Connector addresses Entra natively.

Hybrid x.ID architecture connecting on-premises Active Directory through the LDAP Connector, Microsoft Entra ID through the native Azure Connector, multiple CAs, sites and security keys through mTLS-authenticated Outposts.
AD DS and Microsoft Entra ID remain distinct target systems: the LDAP Connector maintains the local certificate and strong mapping, while the Azure Connector addresses Entra natively.

TECHNICAL DEPTH

The connector roles stay explicit.

An Outpost is not a generic tunnel. Each role has a defined responsibility and should receive only the access required for that function.

CA Connector
Connects x.ID lifecycle actions to a certification authority in the relevant trust or network zone. The CA remains the issuer; x.ID controls identity, policy and process context.
LDAP Connector
Reads the required AD identity context and can update userCertificate and altSecurityIdentities with X509: after enrolment. The gMSA service account receives only the required attribute rights in the intended OUs.
Azure Connector
Addresses Microsoft Entra ID natively through Microsoft Graph. Cloud identity, FIDO2/passkey preregistration and, for Entra CBA, SKI-based certificateUserIds can therefore join the lifecycle without passing through the LDAP Connector.
Policy Enforcement
Evaluates independent rules close to the controlled environment so trust does not depend only on a target application or a single directory attribute.
mTLS and gMSA
mTLS authenticates both connection endpoints. A gMSA can provide a managed Windows service account, while hardware protection can strengthen the private key used by privileged services.
Bidirectional APIs
External systems can be connected to SYNRION, and SYNRION data or decisions can be consumed by other platforms through controlled API integrations.

EVIDENCE & BOUNDARIES

What remains visible across the hybrid environment.

The architecture separates technical reach from trust authority. A connector can perform its task without becoming an uncontrolled master of the whole identity environment.

Available

Users and computers across sources

On-premises AD domains, Microsoft Entra ID and systems outside a traditional AD join remain visible through their respective connector paths.

Available

Consistent Microsoft target state

Certificates, X509 SKI mappings, Entra CBA and FIDO2 registrations can be updated deliberately during issue, renewal and trust removal.

Available

Multiple CAs in one policy model

Issuing systems can differ while identity, approval and lifecycle context remain consistent.

Available

Authenticated connector communication

Outpost paths use mTLS and explicit service identities instead of anonymous infrastructure access.

THE NEXT CONTROLLED STEP

Draw the connector path before opening the network path.

We will map identity sources, CAs, segments and required actions to the smallest set of Outpost roles and authenticated connections.

Discuss the architecture