User-based management
For domain-joined computers, starting with BigFix Platform version 11.0.7, BigFix is able to periodically retrieve computer data from Microsoft Entra ID and Active Directory, such as the User associated with the computer and the User Groups to which that User belongs, as well as the Computer Groups to which the computer itself belongs, and more.
This data is made available as computer properties, allowing BigFix operators to achieve user-centric endpoint management, advanced dynamic targeting, and reporting.
Reserved Properties
To enable out-of-the-box dynamic targeting and global reporting within the BigFix Console and WebUI, the framework implements a set of core Server Reserved Properties. These properties abstract provider-specific details (Active Directory vs. Microsoft Entra ID) by evaluating native relevance expressions that automatically query and map the correct identity attributes.
When an endpoint cannot be correlated with a directory identity, or if specific attributes are unpopulated, these properties gracefully fall back to returning "N/A".
| Property Name | Source Object | Retrieved identity attribute | Default Fallback |
| IDP User Principal Name | Managing User | Returns the user principal name associated with the computer. | "N/A" |
| IDP User Display Name | Managing User | Returns the user display name associated with the computer. | "N/A" |
| IDP Computer Groups | Computer Object | Returns the list of groups to which the computer belongs. | "N/A" |
| IDP User Groups | Managing User | Returns the list of groups to which the user associated with the computer belongs. | "N/A" |
| IDP User Department | Managing User | Returns the department to which the user associated with the computer belongs. | "N/A" |
| IDP User Location | Managing User | Returns the office location of the user associated with the computer. | "N/A" |
| IDP User Site | Managing User | Returns the aggregated data about the worksite address of the user associated with the computer. | "N/A" |
Architectural Overview
The identity integration relies on an automated, asynchronous dual-component flow (Server-Side and Client-Side) to map users and groups to computers.
Identity Aggregation Service
A scheduled task on the BigFix Server maintains a cache of directory objects from all configured Identity Providers. This ensures fast lookups and high performance without repeatedly querying external directory systems. At administrator-defined intervals, the server performs a data refresh. It iterates through all configured IdPs, querying cloud sources via the Microsoft Graph API and on-premises sources using standard LDAP queries. After each polling cycle, for each domain-joined computer, relevant updated directory data is packaged and delivered to the endpoint only if changes are detected (e.g., changes in group membership or office location), reducing network overhead.
Identity Discovery
The BigFix Client automatically discovers the local system's directory state during initialization. In hybrid scenarios where an endpoint is simultaneously joined to a traditional Active Directory domain and Microsoft Entra ID, the client always gives precedence to Entra ID (Azure AD) information to align with modern cloud-first standards. The discovered identity state is transmitted to the BigFix Server during every client registration request.