How it works

Built on top of the directory you already run.

Tenorr connects to your existing Active Directory and becomes the place your team works — while AD stays firmly in control. Every change is reversible, logged, and provable.

1

Connect to your existing AD

Tenorr reads from and writes to your current Active Directory over a mutually authenticated TLS connection, covered in detail further down. Your team signs in with Microsoft, with no new identities to provision and no directory to stand up.

Microsoft sign-in · mTLS to AD
2

Work through a modern interface

Search users and groups, make edits, run bulk actions, and build rule-based Smart Groups — all from a clean web app. No PowerShell required for the everyday work that used to demand it.

users · groups · smart groups · bulk actions
3

Every change syncs back to AD

Operations flow bidirectionally to Active Directory, so Tenorr and your directory stay consistent. AD remains the single source of truth — Tenorr is the interface, not a replacement.

bidirectional sync · AD = source of truth

Undo anything — and prove what happened

Every action is recorded in a searchable audit trail. If something's wrong, reverse it in one click and the rollback syncs straight back to AD. When an auditor asks who changed what, the answer is one search away.

one-click undo · searchable audit trail
Architecture, briefly

Three layers, one source of truth.

Tenorr is designed so the directory is never at the mercy of the tool. AD holds the truth; Tenorr makes it safe and pleasant to operate.

LAYER 01 · INTERFACE

The web app

Where your team manages users, groups, roles, and Smart Groups — with undo and a live activity log.

LAYER 02 · SYNC

Bidirectional engine

Keeps Tenorr and AD in step, applying changes to the directory and reflecting directory changes back.

LAYER 03 · TRUTH

Your Active Directory

Unchanged in its role. Every authoritative record still lives in AD, exactly where it does today.

Security & Audit

Built so a mistake never becomes an incident.

Tenorr’s job is to reduce the operational and access risk that lives in everyday AD management — and to give you the evidence trail when someone asks.

Reversible by design

Routine changes made in Tenorr can be undone in one click, with the rollback synced back to AD. The blast radius of a human error shrinks from "incident" to "non-event."

A searchable audit trail

Every action is logged in plain language — who did what, and when — and filterable in seconds. Compliance reviews stop being a scramble through fragmented event logs.

Least-privilege delegation

Hierarchical roles control exactly what each operator can do. Give the help desk what they need without handing over the keys to the directory.

Access visibility

See how access is distributed across users, groups, and permissions, and surface the anomalies — stale memberships, over-broad groups — that quietly create risk.

When the auditor asks

"Who changed this — and when?"

With native AD logging, answering that means stitching together fragmented events across controllers. With Tenorr, it's a search box.

Filter by user, object, action, or date. Export what you need. The trail is human-readable, because the people reading it during an audit aren't always the people who made the change.

Tenorr Activities audit view — searchable log of directory changes with action, status, time, and the user who made each change
The connection to your directory

The link to Active Directory is locked at both ends.

Tenorr talks to your directory over a mutually authenticated TLS (mTLS) channel. Both sides present and verify certificates before any data moves — so the connection isn't just encrypted, it's proven on both ends.

  • Both ends authenticateStandard TLS only verifies the server. With mTLS, Tenorr and your AD connector each prove their identity with a certificate.
  • Encrypted in transitEvery request and every change synced back to AD travels inside the encrypted channel — never exposed on the wire.
  • No anonymous clientsA valid client certificate is required to connect, so a stolen URL or leaked credential alone can't open a session.
  • Rotatable certificatesCertificates can be rotated or revoked, so access to the directory connection stays under your control over time.

Questions IT leaders ask first

Do we have to migrate off Active Directory?
No. That's the core of the design. AD stays the source of truth and Tenorr layers on top of it. There's no new directory to adopt and nothing to migrate away from.
What exactly can be undone?
Actions performed through Tenorr — like group membership changes, attribute edits, and enabling or disabling accounts — are tracked and reversible, with the rollback synced back to AD. We'll walk through the exact scope for your environment on a demo.
How is this different from disaster-recovery tools?
Forest-recovery products are built for catastrophe — restoring AD after an outage or attack. Tenorr is built for everyday operations: making the routine changes safe, reversible, and auditable so small mistakes never become big incidents.
Does it work with hybrid environments?
Tenorr is built for on-prem and hybrid Active Directory. The best way to confirm fit for your specific setup is a short demo against an environment like yours.

See it run against a real directory.

Bring the architecture and security questions — we'll answer them directly. Book a 30-minute demo.

Request a demo