AD360 Identity Security For The NHS
Others deliver and disappear. We stay - to govern, harden, monitor, and evolve - turning frameworks into action, not just checklists.


The network edge stopped being the front line some time ago. Most breaches now involve a valid identity: a phished credential, an over-privileged account, an orphaned login nobody closed.
Verizon's 2025 Data Breach Investigations Report put credential abuse as the initial access vector in 22% of breaches across a dataset of more than 12,000 confirmed incidents. When the attacker is holding a real account, keeping them out is no longer the question. The question is whether you can see, secure and govern identity well enough to notice misuse and act on it. That is a security discipline, but in most organisations identity is still run as an administrative one, split between a service desk process, a directory team and whoever owns the HR system.
ManageEngine AD360 is a unified identity platform assembled from seven components, each of which ManageEngine also sells separately: ADManager Plus for management and reporting across Active Directory, Microsoft 365, Exchange and Google Workspace; ADSelfService Plus for MFA, single sign-on and self-service password reset; ADAudit Plus for auditing across Active Directory and the Windows Server environment; M365 Manager Plus for Microsoft 365 governance; Exchange Reporter Plus for hybrid Exchange reporting; RecoveryManager Plus for directory backup and recovery; and SharePoint Manager Plus for SharePoint reporting and auditing.
The platform is modular, so you take the components you need rather than all seven. Architecturally it acts as an integration and presentation layer, making REST API calls to the component products to fetch reports and pushing administration changes back out to keep settings synchronised. That explains something people notice on day one: AD360 is a console over a set of products rather than a single monolithic application, and the components retain their own interfaces. It is a strength for phased adoption and a point of confusion if nobody has explained it.
This is written for the person who has to run it rather than the person who signs for it, and everything here traces back to ManageEngine's own documentation, linked as we go. McCormickCo Security is the UK's first ManageEngine Gold Partner and delivers AD360 end to end for the NHS and the wider regulated sector.
Joiners Movers And Leavers
Every orphaned account is an unlocked door nobody is watching. Lifecycle work, onboarding, role changes and above all deprovisioning, is too often split across systems and teams, and that split is how stale accounts accumulate.
AD360 closes the gap with templates and workflows that automate identity actions and apply uniform policy across every connected environment. A new starter or a leaver recorded in the HR system flows through to the identity infrastructure automatically, keeping status and access rights aligned across Active Directory, Microsoft 365, Google Workspace and more. Its integration ecosystem reaches more than 100 systems, with custom connectors where no out of the box integration exists, so a change made in one place is reflected everywhere rather than leaving separate islands of administration to drift apart between reviews.
Third party and contractor access runs through the same mechanism, which in an NHS estate with a long supplier tail is often where the worst of the drift sits. Bank and agency staff are the other recurring case: high turnover, urgent onboarding, and a leaver process that depends on somebody remembering.
Automation only holds the line going forward, though. Access already granted keeps accumulating, because people change roles, cover for absences and join projects, and permissions follow them without ever being taken away. AD360 supports access certification campaigns for bulk entitlement review, with justification validation and role alignment built into the process rather than tracked alongside it in a spreadsheet. Machine learning access recommendations analyse attributes including department, role and manager to suggest least privilege group memberships at the point of provisioning, and peer group usage to identify entitlements that no longer match the job.
That reduces over-provisioning at source, which is considerably cheaper than correcting it at the next review. For a trust facing an access review requirement it also changes who can run it: a structured campaign with recommendations can be completed by line managers, where a raw entitlement extract cannot.
Authentication That Adapts To Risk
The login is the control your users touch most often, which means it has to be both strong and bearable. Security that people work around is not security.
AD360 supports context aware MFA and single sign-on that evaluate each sign-in against configurable conditions such as address range, device type, time of access and behavioural signals, so additional authentication is enforced when risk indicators warrant it rather than applying identical friction to everyone. The platform supports more than twenty authentication methods, including phishing-resistant FIDO2 passkeys for Windows, macOS and Linux logins, biometrics, and offline MFA for disconnected environments.
The capability most relevant to an NHS estate is MFA for local Windows accounts. It extends multi-factor verification to local logins, workstation unlocks, User Account Control prompts and RDP connections, on both stand-alone and domain-joined machines. Local accounts on shared clinical workstations, standalone analyser PCs and equipment-attached workstations are a well known weak point, and they are precisely the accounts most identity products leave uncovered. Where a device cannot be domain-joined for clinical or supplier reasons, this is one of the few controls that reaches it.
At the other end of the scale sits the quiet tax on the service desk. ADSelfService Plus lets users reset passwords and unlock accounts themselves under strict authentication controls, which removes a large share of routine tickets and the downtime of a user sitting idle waiting for a callback. It is usually the capability that pays for the deployment in visible terms, which makes it a reasonable place to start a phased rollout even though it is not the part that improves security most.
Two things to plan for. Enrolment needs a communications push rather than an email. And high availability for ADSelfService Plus is an add-on rather than a base entitlement, which catches people out: once staff rely on self-service, an outage becomes a service desk surge.
Seeing The Privilege Paths
Privilege misuse rarely traces back to one bad setting. It comes from permissions that chain together over time.
AD360's identity risk exposure management uses a graph engine that models directory objects as nodes and privilege inheritance as the connections between them. It maps lateral movement and privilege escalation paths through Active Directory, prioritises the risky configurations automatically, and recommends remediation steps. In practice it surfaces privilege creep, nested group memberships, delegated rights and exposure links, and presents them as a picture of how an attacker would escalate rather than as a list of settings. Alongside it, the Attack Surface Analyzer highlights insecure configurations that enable credential abuse, privilege escalation or lateral movement.
That visibility is what lets you prioritise. Not every risky relationship matters equally, and knowing which ones lead somewhere is the difference between a remediation plan and a list. In a directory that has accumulated twenty years of delegation, a list is not actionable and a prioritised graph is.
Mapping the paths is preventive. Watching them being used is the other half. AD360 approaches identity threat detection and response as a continuous cycle: discovery of risks, preventive and visibility controls, ongoing monitoring of identity activity, and sustained posture management across hybrid environments. User behaviour analytics establish what normal looks like for accounts and applications, then flag deviations such as unusual login locations and abnormal access patterns.
Detection only counts if it leads to action, and this is where the platform boundary matters. AD360 integrates with Log360 so that identity anomalies can trigger remediation directly from the SIEM workflow: accounts disabled, credentials reset, entitlements modified, without switching tools mid-incident. If you are running or considering both, design for that integration at the outset, because retrofitting the workflow is more work than configuring it.
Evidence That Holds Up
When an auditor asks who changed something, the useful answer arrives in seconds rather than days.
AD360 provides real-time auditing across Active Directory and the Microsoft 365 environment, including Entra ID, Exchange, SharePoint, Teams and OneDrive, capturing changes to accounts, groups, permissions and policy as they happen, with historical audit reports retained for the periods an assessment will ask about. Its capabilities support NIST SP 800-207 on Zero Trust architecture, align with PCI DSS version 4.0 Requirement 8, and facilitate SOX, HIPAA and GDPR controls. For NHS organisations that includes the identity evidence a DSPT assessor will ask for.
It is worth being precise about what that means, because vendors are often not. A product does not make an organisation compliant with GDPR, which is a legal obligation on the organisation rather than on any tool. What it does is generate the evidence that demonstrates the controls are working, which is the part that is otherwise assembled by hand under time pressure in the fortnight before a submission.
Evidence of control is only half of what an assessor wants, though. The other half is evidence you could put the directory back. AD360 brings backup and recovery into the same platform through RecoveryManager Plus, so a mis-deletion, a bad change or an attack on the directory becomes something you can roll back rather than something you can only audit afterwards. Note that directory and mailbox backup are licensed as add-ons rather than included by default.
For a trust whose clinical systems authenticate against Active Directory, directory recovery time is a clinical continuity figure rather than an IT one. It belongs in the business continuity plan with a tested number against it, and in our experience that number has usually never been measured.
See It On Your Own Directory
Every directory carries its own history, and the interesting findings are usually the ones that have been there for years. Nobody ever budgeted to clean up delegation from 2011.
We can show you AD360 in action: a live demonstration, or a proof of concept in your own directory. As the UK's first ManageEngine Gold Partner, we handle design, component selection, licensing, deployment, integration and ongoing operation, with the compliance mapping regulated organisations need alongside it.
If you'd like to see what AD360 could do for your identity estate, we'd welcome the conversation.
Contact | McCormickCo Security. Our team can talk through architecture, component selection, licensing and DSPT evidence mapping, and help you assess how this fits your environment.







