NIS2 · French ReCyF · Directories

NIS2 and the French ReCyF: secure Active Directory and LDAP directories

Directories hold part of the accounts, groups, policies and rights used by information systems. Their security does not automatically follow from IAM governance.

This page applies the practical cases in the French ANSSI guidance to the NIS2 identity and access use case.

  • Intended outcome

    Coherent accounts and groups, protected exchanges, limited delegations and usable events.

  • How to industrialise it

    Let IAM govern decisions, execute changes in the directory and apply controls specific to AD or LDAP.

Structure accounts, groups and exchanges

Rights should be assigned to functional groups rather than systematically to individual users. Directory exchanges should be limited and encrypted, including LDAPS where relevant, and internal environments logically separated from exposed ones.

Default secrets must be changed, password policies enforced in the directory, and connections, group changes, creations and deletions logged. Coherence must be checked across the directory, federation, SSO and IAM.

Control administration and exceptions

Administrative delegations must be restricted. Emergency or break-glass accounts need a procedure, approval, strong protection and traces. Regular account and group reviews complement controlled creation, deactivation and documented naming.

IAM governs and orchestrates; the directory executes and holds part of the accounts and groups. Reducing attack paths, protecting administration tiers and restoring service also require controls specific to Active Directory or LDAP.

Evidence to retain

  • Naming rules, functional groups and owners
  • Secure exchange settings and environment separation
  • Logs of connections, group changes and lifecycle events
  • Reviews of accounts, groups, delegations and emergency access

Relevant capabilities and content

Related controls

Sources and guidance

Turn the control into a process

Frame responsibilities, events and evidence before selecting the mechanisms to deploy.