# Architecture

* FSProtect works completely on-premise.
* FSProtect is installed only one Microsoft Windows server, it doesn't require any agent deployment to servers, clients or domain controllers.
* FSProtect works with unprivileged user to scan entire Active Directory.
* In **hybrid environments**, identities are synchronized from **on-premise Active Directory to Microsoft Entra ID (Azure)**.
* Azure/Entra ID integration is **optional** and does not require direct scanning or agent deployment in the cloud.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2FgHNe7wOVbk7utus6gkzl%2Fimage.png?alt=media&#x26;token=dba9f2f0-d637-463e-9f9f-a5ed4558efd0" alt=""><figcaption></figcaption></figure>
