产品服务

以人为核心的零信任业务安全防护体系

首页 > 产品方案 > 企业身份管理平台(EnIAM) > 可信目录产品(TD)

可信目录产品(TD)

芯盾时代操作系统用户身份与访问管理产品Operating system Identity and Access Management(OIAM),将操作系统用户管理与认证纳入IAM统一管理范畴,实现安全便捷的操作系统账号与认证管理。兼容Windows Server 2008 R2 AD DC规格,支持Windows系统用户加域、账号认证、组策略管理功能;支持统信UOS、麒麟KylinOS、Ubuntu、CentOS、RedHat等Linux系统账号管理与认证功能,满足国家信创合规要求。并可对接企业IAM产品,实现业务域与办公域统一身份管理。

可信目录产品Trust Directory(TD),是芯盾时代推出的企业级目录服务系统‌,用于集中管理企业用户、计算机、权限和网络资源,广泛应用于企业身份认证与终端管控。TD支持LDAP目录协议,支持Windows、 KylinOS、UOS、MacOS、HarmonyOS等计算机加域管理,具备平滑替换微软AD能力,满足国家信创合规要求。

产品功能

TD核心组件 LDAP目录、KDC密钥分发中心、DNS域名解析服务、GPO组策略引擎。

TD管理系统 提供Web控制台(管理用户、计算机、组策略、域名解析、域服务、运维中心),兼容微软RSAT管理工具。

终端加域组件 提供信创终端一键加域插件,兼容Windows终端加域机制。

LDAP认证 支持LDAP认证协议,提供LDAP认证协议代理,满足应用设备安全认证需求。

应用场景

  • 微软AD替换

    平滑替换微软AD,自动迁移AD数据,纳管Windows终端,接管应用设备LDAP认证。

  • 信创终端管理

    支持麒麟、统信等信创OS终端加域管理,支持用户域认证和计算机管理。

  • LDAP认证

    针对支持LDAP认证协议的网络设备、应用等,提供账号管理与认证功能。

产品特色

信创合规

基于全国产化组件和环境构建,满足国家信创合规要求。

兼容微软AD

支持平滑迁移替换微软AD,用户无感。

终端覆盖全

支持Windows、 KylinOS、UOS、MacOS、HarmonyOS、Linux等计算机加域管理,统一企业计算机终端管理。

信创策略全

针对麒麟、统信等信创终端,提供完备的、差异化的终端组策略管理能力。

强大运维能力

提供全Web化的用户、计算机、组策略、域名、运维管理平台,支持产品一键部署与终端一键加域。

IAM深度融合

IAM与TD双向深度融合,支持数据双向同步、密码双向同步、互信登录。

Products & Services

Human-Centered Zero Trust Business Security Protection System

Trust Directory(TD)

Trust Directory (TD), developed by Trusfort, is an enterprise-grade directory service system designed to centrally manage enterprise users, computers, permissions, and network resources. It is widely utilized in enterprise identity authentication and endpoint control. TD supports the LDAP directory protocol and provides domain-joining management for computers running Windows, KylinOS, UOS, macOS, HarmonyOS, and more. TD is designed to seamlessly replace Microsoft Active Directory (AD), ensuring full compliance with national Xinchuang (Information Technology Application Innovation) standards.

Functions

TD Core Components TD Core Components includes LDAP Directory, Key Distribution Center (KDC), DNS (Domain Name System) Resolution Service, and GPO (Group Policy Object) Engine.

TD Management System It provides a web console for managing users, computers, group policies, DNS resolution, domain services, and the O&M center. It is fully compatible with Microsoft RSAT.

Endpoint Domain-Joining Components It provides a one-click domain-joining plugin for Xinchuang endpoints and is fully compatible with Windows endpoint domain-joining mechanisms.

LDAP Authentication It supports the LDAP authentication protocol and offers an LDAP Authentication Proxy to satisfy the secure authentication requirements of various applications and hardware devices.

Scenarios

  • Microsoft AD Replacement

    It can seamlessly replace Microsoft AD with automated AD data migration, bring Windows endpoints under management, and take over LDAP authentication for applications and network devices.

  • Xinchuang Endpoint Management

    It supports domain-joining management for Xinchuang OS endpoints (including KylinOS and UnionTech UOS), providing comprehensive support for user domain authentication and computer management.

  • LDAP Authentication

    It provides centralized account management and authentication services for network devices and applications that support the LDAP authentication protocol.

Features

Xinchuang Compliance

It is built upon a fully localized technology stack, ensuring complete alignment with China's national IT application innovation standards and regulatory mandates.

Microsoft AD Compatibility

It facilitates seamless migration and replacement of Microsoft AD, ensuring a seamless experience for end-users.

Comprehensive Endpoint Coverage

It supports domain-joining management across a full spectrum of operating systems, including Windows, KylinOS, UOS, macOS, HarmonyOS, and Linux, achieving unified management of all enterprise computer endpoints.

Full-Featured Xinchuang Policy Management

It delivers comprehensive and differentiated group policy management capabilities, tailored specifically for Xinchuang endpoints such as KylinOS and UnionTech UOS.

Powerful O&M Capabilities

It features a fully web-based management platform for users, computers, group policies, domains, and O&M. It facilitates one-click product deployment and one-click endpoint domain-joining, enhancing operational efficiency.

Deep IAM Integration

It achieves deep, bidirectional integration between IAM (Identity and Access Management) and TD, supporting bidirectional data synchronization, bidirectional password synchronization, and mutual trust login.