Connect Your Entire
Identity Estate
IdentityFirst reads from your existing systems — no agents, no schema changes, no writes. Beta connectors are production-ready; Experimental connectors are available to early adopters under SLA.
- Read-only by default — no write access required
- Polly-backed retry and circuit-breaker on every connector
- Normalised to CanonicalIdentity model
- Supports push (webhook) and pull (scheduled) modes
- New connectors released every sprint
Two Connector Tiers
We are transparent about maturity. Every connector is labelled so you know exactly what to expect.
Production-Ready
Beta connectors have been tested against live tenants, have unit and integration test coverage, and are covered by our standard SLA. They are safe to use in production assessments.
- Covered by standard SLA
- Integration-tested against live systems
- Full error handling and Polly retry policies
- Documented in connector reference
Early Adopter
Experimental connectors are functional but may have edge cases under certain tenant configurations. Available to early adopters who can provide real-world feedback. Not covered by standard SLA.
- Functional but not fully hardened
- Available on request to early adopters
- Actively promoted to Beta based on feedback
- Direct engineering support during onboarding
Connects to the vendors you already use
Beta Connectors
Production-ready integrations included in all plans.
Active Directory
DirectoryFull AD forest enumeration, privileged group analysis, and password policy assessment.
Microsoft Entra ID
Cloud IdPEntra ID users, groups, conditional access, PIM roles, and access reviews.
AWS IAM
CloudIAM users, roles, policies, and CloudTrail identity events.
Google Workspace
SaaSGoogle Workspace users, admin activity, and OAuth application inventory.
Okta
FederationOkta users, groups, applications, MFA factors, and system log events.
CyberArk PAS
PAMPrivileged account inventory, safe membership, and session activity.
BeyondTrust
PAMPassword Safe and Privilege Management event collection.
SailPoint IdentityNow
IGAIdentity lifecycle events, certifications, and entitlement data.
Workday
HRHR user data as authoritative identity source with lifecycle signals.
GCP IAM
CloudGCP IAM bindings, Audit Logs, and service account inventory.
Windows Event Log
DirectoryWEF push receiver for authentication events (4624, 4720, 4726, 4672).
CrowdStrike Identity
SecurityCrowdStrike identity protection events via webhook receiver.
Splunk
SIEMOutbound SIEM forwarding — push fabric events to Splunk HEC.
Azure Sentinel
SIEMSign-in log ingestion and outbound event forwarding to Sentinel workspace.
Experimental Connectors
35+ connectors available to early adopters. Contact us to enable any of the following.
HashiCorp Vault
Delinea Secret Server
Saviynt EIC
SailPoint IIQ
ForgeRock
Ping Identity
Jamf MDM
ServiceNow
Datadog
OpenLDAP
FreeIPA
GitHub Enterprise
GitLab
Salesforce
Jira / Confluence
Okta System Logs
HiBob
BambooHR
Personio
QRadar
Microsoft Defender
Duo Security
Kubernetes RBAC
One Identity
Micro Focus NetIQ
RSA SecurID
Beta Systems IAM
Azure Key Vault
AWS CloudTrail
Syslog / CEF
Terraform Cloud
1Password Business
JumpCloud
Bitwarden Enterprise
Samba AD
Don't see your system? We prioritise connector development based on customer demand.
Request a ConnectorHow the Connector Framework Works
All connectors share the same normalisation pipeline — data from every source flows through CanonicalIdentity before reaching any analysis engine.
1. Connect
Supply read-only credentials (API key, service principal, or service account). IdentityFirst never requires admin rights. Principle of least privilege enforced.
2. Normalise
The DataNormalisation engine maps each source record to the CanonicalIdentity model. Built-in rules handle name casing, email deduplication, and attribute trimming.
3. Graph
Normalised records flow into the TemporalIdentityGraph. Identities from multiple sources are correlated, deduped, and enriched with risk scores and drift signals.
Ready to Connect Your Identity Estate?
Book a 30-minute technical call. We'll confirm connector compatibility with your environment before you commit to anything.