---
title: "Prerequisites for Active Directory"
canonical: "https://docs.infoblox.com/space/UniversalAssetInsights/1836023843/Prerequisites%20for%20Active%20Directory"
format: markdown
---
Complete the following prerequisite configuration for Active Directory.

## Configuring Windows Event Collector

To leverage the full functionality of Active Directory discovery, configure Windows Event Collector. For more information, see *[Prerequisites for WEC](https://infoblox-docs.atlassian.net/wiki/spaces/UniversalAssetInsights/pages/1835925539)*.

## Creating Microsoft Active Directory Credentials

Before configuring network discovery, create credentials for Active Directory. For more information, see <u>*[Creating Microsoft Active Directory Credentials](https://infoblox-docs.atlassian.net/wiki/spaces/UniversalAssetInsights/pages/1693876284)*</u>.

## Configuring Network Discovery for Active Directory

After configuring the Windows Event Collector, and creating Active Directory credentials, you can configure network discovery for Active Directory. For more information, see *[Discovering Active Directory](https://infoblox-docs.atlassian.net/wiki/spaces/UniversalAssetInsights/pages/1710228375)*. 

## Cataloging Domain Assets and Enriching Asset Insights and Threat Defense with User Data  


Modern network environments require enhanced visibility into user-based DNS activity to improve security monitoring, incident investigation, and asset tracking. By integrating Microsoft Active Directory discovery with event log forwarding and DNS Forwarding Proxy (DFP) configuration in Threat Defense, administrators can map DNS queries to specific users and devices. The following workflow outlines the prerequisites and setup steps required to enable this functionality, from creating domain user accounts to configuring WEC, discovery jobs, and NIOS-X forwarding. Once complete, DNS activity can be monitored centrally and filtered per user, providing deeper insight into network behavior and potential threats.

1. Create a domain user and add the user to the following builtin user groups:
  - Domain Users
2. Configure a Windows Event Collector (WEC). For information on how to configure WEC, see *[Prerequisites for WEC](https://infoblox-docs.atlassian.net/wiki/spaces/UniversalAssetInsights/pages/1835925539)*.
3. Create a Microsoft Active Directory Discovery Job.
4. Create a Microsoft Event Log Discovery Job.
5. Configure a NIOS-X Server and enable DNS Forwarding proxy (DFP) on this server. Configure the NIOS-X Server as follows:
  - Add DFP as alternative DNS server on all the clients**.**
  - This DFP will forward all the DNS queries to cloud and can be viewed under **Monitor > Reports > Security > DNS** activity reports.
  - Once users and computers are discovered, DNS activity reports can be filtered based on the user.