> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/configuration-center/ad-configurations.md).

# AD Configurations

This section allows you to configure Active Directory connection and authentication settings. Use this configuration to securely connect to and scan Active Directory environments.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-3b41ddce1e05706c66bb4c7bd5e801e856a70791%2Fad-configuration.png?alt=media" alt=""><figcaption></figcaption></figure>

### Fields

**Forest**: The Fully Qualified Domain Name (FQDN) of the forest that is going to be analyzed. Forestall ISPM automatically analyzes the submitted FQDN of the forest and includes the parent and child domains/forests in the Active Directory environment to this new scan.

**Domain Controller IP Address**: IP Address of the domain controller that belongs the to submitted forest. If the related domain or forest contains more than one domain controller, any domain controller IP address which is accessible over the network from the Forestall machine is accepted.

**Username**: Name of the user account that is created for scanning the environment during the Forestall Requirements and Installation phase. As this user requires specific permissions and settings, If you are unsure about whether it satisfies these prerequisites, please check the Requirements and Installation document.

**Password**: Password that belongs the submitted username.

### Authentication Type

The **Authentication Type** field determines how the Active Directory credentials are provided. Two authentication methods are available.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-1f08b33725046eda3629f910d97bf317b715f145%2Fauth-type.png?alt=media" alt=""><figcaption></figcaption></figure>

When **CyberArk** is selected, credentials are retrieved using the selected **CyberArk Configuration**.

Select an existing **CyberArk Configuration** from the drop-down list.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-5fee2bd58f43e7017dabf46d8138b6017d6ab933%2Fad-conf-cyberark.png?alt=media" alt=""><figcaption></figcaption></figure>

If no suitable configuration exists, click the **+** button next to the drop-down list to create a new CyberArk Configuration without leaving the page.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-489910c4860813fa842ac3a5d86f3e365ec6c423%2Fcreate-cyberark-conf-ad.png?alt=media" alt=""><figcaption></figcaption></figure>

After the configuration is successfully verified and saved, it becomes available for selection in the **CyberArk Configuration** drop-down list.
