> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/introduction/architecture.md).

# Architecture

Forestall ISPM Deploymeny Architecture

* Forestall works completely on-premise.
* Forestall is installed only one Microsoft Windows server, it doesn't require any agent deployment to servers, clients or domain controllers.
* Forestall works with unprivileged user to scan entire Active Directory.
* In **hybrid environments**, identities are synchronized from **on-premise Active Directory to Microsoft Entra ID (Azure)**.
* Azure/Entra ID integration is **optional** and does not require direct scanning or agent deployment in the cloud.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-9bd39306754623a758cdae00cb272b0a682b8002%2Fintroduction-architecture-image-1.png?alt=media" alt=""><figcaption></figcaption></figure>
