Atlas project production

Student Active Directory Sync

Uses Aeries student data and local post-processing to keep student Active Directory state aligned to district roster and school-context changes.

Internal-only entry. Do not publish externally without review.
Type
System
Lifecycle
Active
Last touched
2026-03-24
Visibility
Internal

Purpose

Synchronize Aeries-derived student identity and school-context data into Active Directory for student account lifecycle readiness.

Current state

This Atlas record now represents the student-only Active Directory sync path. Current production evidence is strongest for the recurring Aeries-driven roster push and post-processing flow that keeps student AD state aligned, while staff lifecycle handling is now documented separately under Staff AD Account Management.

Next step

Publish the active scheduler inventory, service-account governance, and student-path exception-handling runbook.

Interfaces

Inputs
  • Aeries student data
  • directory sync configuration
Outputs
  • updated student Active Directory state
  • directory sync inputs
  • password initialization and related student account artifacts

Reality to Action trace

Reality Ingestion

Contributes in this stage.

Canonical Storage

Not in scope.

Automation Engines

Contributes in this stage.

Human Interfaces

Not in scope.

Operational Adoption

Contributes in this stage.

Core workflow

TBD. Document the 5-10 steps that define the core workflow.

Data integrity and contracts

Source of truth rules

  • Aeries is canonical for student identity and school context.
  • Active Directory is the managed target state for student account objects.

Safe handling

  • Protect directory credentials, snapshots, and generated exports.
  • Restrict student and staff identity logs to authorized administrators.

Operational notes

Reliability posture

Production evidence is strong across both Integr8r and Aether cron paths, but scheduler inventory and exception rules still need a formal runbook.

Observability

  • Integr8r logs
  • minimum-line and diff checks
  • PowerShell post-processing logs
  • cron-driven shell output

Security and privacy

Restricted staff and student identity data; internal only.

Dependencies

Upstream
  • Aeries
  • AD permissions
  • Linux and local runtime paths
Downstream
  • Active Directory
  • Google directory sync path
  • downstream student account state

Ownership

Owners

Technology Services

Users

Technology Services, district identity stakeholders, Josh Barton (owner)

Student Active Directory Sync

Operational Notes

  • Production evidence spans the recurring student roster path and local post-processing that apply Aeries-driven changes into Active Directory.
  • Staff lifecycle handling, preferred-name logic, non-HR intake, and onboarding notices now live under Staff AD Account Management.
  • Failure delays or corrupts directory state and pushes identity teams into manual correction work.

Registry Alignment

  • Mapped registry entry: INT-041
  • Registry clarified: this page is now the student AD sync only. Staff-side registry scope formerly blended here is now documented under Staff AD Account Management.
  • Validation gaps: document scheduler inventory, service-account governance, and exception-handling rules for the student path.