Requirements
For SpyCloud Active Directory Guardian.
This page outlines the software, hardware, permissions, and network configurations required to run Active Directory Guardian (ADG) 7.3 in your environment.
💻 Platform & Browser Compatibility
| Component | Requirement | 
|---|---|
| Supported OS | Windows 10 (workstation) Windows Server 2012 and later | 
| Browser | ✅ Google Chrome (v89+) ✅ Microsoft Edge (v91+) ❌ Internet Explorer is not supported | 
| .NET Framework | 4.8 or higher (required) | 
👤 Required Permissions
| Permission Type | Details | 
|---|---|
| Local (for install) | • Install software | 
| Active Directory | • Reset user passwords | 
Best practice: Assign these permissions to a group via Delegate Control, then assign your service account to that group.
Note: If group policy overrides group permissions, grant them directly to the service account.
🧮 Hardware Specifications
| Component | Minimum Spec | Notes | 
|---|---|---|
| Memory | 8 GB RAM | More is better for large banned password lists or fuzzy scans | 
| Storage | 20 GB | For logs and hash cache | 
| CPU | 2 GHz+ (multi-core) | More cores = faster scanning. ADG uses one thread per core | 
If access to the domain controller or SpyCloud API is slow, ADG will limit to one CPU core for processing.
Definition of “Slow”:
When fetching one account from the DC takes longer than scanning it locally.
🌐 Network Access & Ports
ADG communicates with internal infrastructure and external APIs using specific ports. The following sections outline the necessary access requirements.
🔄 Internet Connectivity
- Port 443 (HTTPS) is required for outbound access to the SpyCloud API
- Make sure *.spycloud.comis reachable from the ADG host
🖥️ Active Directory Communication
ADG requires internal network access to your domain controllers on the following ports:
- Port 389: LDAP
- Port 135: MS-DRSR (Active Directory replication)
🧱 Proxy Environments
If your environment uses a proxy for outbound traffic:
- Open your proxy's specific port for outbound HTTPS
- Allow access to *.spycloud.com
- Ensure DNS resolution is available for external domains
✉️ SMTP Configuration (If Using Email Alerts)
| Use Case | Common Ports | 
|---|---|
| SMTP outbound | 25,465,587,2525 | 
| Admin Notes | Check with your SMTP administrator to confirm which port is used | 
👇ACTIVE DIRECTORY GUARDIAN

Updated 2 months ago