Loading_
Loading_
Delegated AD administration for helpdesk and HR without handing anyone Domain Admin.
Measured outcomes
−76%
Directory tickets to platform team
43
Delegated operations exposed
100%
Changes attributed to a human
18k
Objects managed
Routine directory tasks — unlocking accounts, updating attributes, managing group membership — required either elevated rights or a ticket to the platform team. Both options were wrong.
The portal exposes precisely-scoped operations to delegated roles, executes them under a single service identity, and records every change with the human who requested it.
Headline result
0
new Domain Admins
Tags
Five capabilities that define the system. Each one exists because something specific was broken.
Permissions are granted per operation and per OU scope, not per AD right.
CSV-driven bulk updates with dry-run preview and per-row result reporting.
Field-level rules enforce format, uniqueness and downstream sync compatibility.
Automated identification and staged disable/delete of dormant accounts and computers.
The service account performs the write; the audit record names the requester.
A permission model that lives in the application, executed through one tightly-scoped directory identity.
3 components
Every exposed operation is an explicit, reviewable entry.
3 components
Runspaces are pooled and recycled; no long-lived elevated sessions.
3 components
Snapshots make every change reversible.
No mystery components. Everything below is either open source or a platform you already own.
Interactive mock-ups of the shipped interface. The live environment is available during a demo session.
Scoped directory browse with inline actions
The running environment is available during a booked session — including a sandbox tenant you can drive yourself.
The real sequence, in order. Steps with a command are copy-pasteable.
gMSA with delegated rights over the target OUs only.
$New-ADServiceAccount -Name gmsa-adportal -DNSHostName adportal.corp.localIIS site plus the runspace host service on a domain-joined member server.
Map helpdesk, HR and platform roles to operations and OU scopes.
Ship the change ledger to the SIEM and validate ingestion.
Published rather than hidden behind a call. Volume and multi-year terms move these numbers.
Platform
$0.70per managed object / month
Implementation
from $34kone-time
Need this scoped against your estate? We will size it properly, in writing, within a week.
Request a quoteWe will walk you through the architecture, the trade-offs we made, and what would change for your environment.