This connector is for Tenacy Global Pilots and Administrators in charge of monitoring the security of the Active Directory. It analyzes the JSON result file produced by ORADAD / ADS to generate indicators on the security level of the AD and synchronize the vulnerabilities from the report as gaps in Tenacy.
Tenacy offers the ADS - Oradad connector.
This connector pulls several types of information:
Indicators on the AD: number of users, machines, domain controllers, and administrator accounts.
Indicators on the security level of the AD: overall ADS score, number of alerts, warnings, and information (global and by ADS level), overall progress and by ADS level.
Vulnerabilities as Gaps in Tenacy: vulnerability name, criticality (based on the ADS Grade, the criticality scale defined by the ADS tool), description, and recommendation.
Adding and configuring the connector
To add this connector, go to Catalog > Connectors > ADS Oradad > Add a connector.
After adding it, you need to configure:
Operator perimeter: the perimeter that operates and dictates the AD hardening rules, to which the indicators and metrics will be attached by default.
Frequency: the import frequency of ADS JSON files and the frequency of indicators. We recommend a monthly frequency, since ADS reports are produced monthly by ANSSI.
⚠️ When instantiating this connector, the Identity Management measure (TE039) will automatically be applied to the operator perimeter if it hasn't been applied already.
After creation, you can add:
the gap register in which your gaps will be created during the JSON file execution;
the maximum number of gaps to process during the connector's execution.
You can also add consumer perimeters for the connector.
💡 However, we recommend having one connector per perimeter.
⚠️ Maximum number of gaps: only fill this in if you want to limit gap creation to a certain number (this value cannot exceed 100). If left empty, Tenacy synchronizes the 100 (or fewer) most critical vulnerabilities identified by ADS as gaps, above the chosen threshold.
Running your first test
Once the connector is properly configured, test the integration by running the first execution.
Go to ⚙️ > Connectors > Click on the ADS connector > Run now:
💡 Feel free to contact Tenacy support if you have any questions about this.
How the connector works
In the JSON file, the analysis_date field (or summary > date > v for older files) is used to attach the indicators to their correct production period, regardless of the import date.
For example, for a report produced in November with a monthly frequency, the extracted indicators will be attached to the previous full period, meaning October.
⚠️ If reports are imported out of chronological order (for example, the October report imported after the November one), the status of the gaps (open/closed) is not guaranteed. This is because gap imports rely on the connector's execution date rather than the date contained in the JSON report.
Frequently asked questions
What happens if the "maximum number of gaps" field is left empty?
Tenacy automatically synchronizes the 100 most critical vulnerabilities identified by ADS (or fewer if there are less than 100), above the chosen threshold.
Can I use a single connector for several perimeters?
Technically yes, by adding several consumer perimeters, but Tenacy recommends having one dedicated connector per perimeter for clearer management.
What happens if I import my ADS reports out of chronological order?
Gap statuses are no longer guaranteed, since Tenacy relies on the connector's execution date, not the actual report date, to determine the order of gaps.
Is the Identity Management measure (TE039) mandatory to use this connector?
You don't need to do anything: it's automatically applied to the relevant perimeter as soon as the connector is instantiated, if it isn't already.




