HILOP / Capabilities

A connected operating layer for hybrid identity.

HILOP combines first-party providers, customer-controlled automation, source-aware administration, reporting, and audit history without pretending every system exposes the same capabilities.

Platform capability

One operational model across different source systems.

Capability depends on runtime profile, provider health, provider permissions, object type, Microsoft service behavior, and workflow configuration.

AreaWhat HILOP providesPrimary sources
Runtime profilesProfile selection, cloud choice, provider setup, branding, ProgramData-backed configuration, and provider-specific tooltips.HILOP profile store
LicensingActivation state, installation tracking, unlicensed search-only behavior, and restricted tools or edits when unlicensed.Little Innovation Tech licensing service
User lookupUnified selected-user context across directory, Graph, Exchange, groups, direct reports, mailbox, authentication posture, and assigned devices.AD · Graph · Exchange
User administrationADUC-style editing, attribute editor, manager changes, direct report movement, group picker flows, and source-owned writes.AD · Graph · Exchange
AD ReportsSchema-backed attributes, object-type presets, saved custom reports, OU scoping, result viewing, and CSV export.AD · Directory Simulator
Mailbox operationsRecipient, forwarding, delegation, GAL, and distribution operations where Microsoft exposes supported management surfaces.Exchange Online / On-Prem PowerShell
DevicesCross-source search, assigned-device matching, Intune sync, LAPS rotation, secret reveal, retire, and source-specific deletion.AD · Graph · Intune
WorkflowsJSON-defined forms, validation, confirmation, actions, REST, email, browser launch, delay, approval, conditions, and PowerShell steps.Native providers · REST · PowerShell
UtilitiesHybrid Sync test-and-run workflow with remote PowerShell output displayed in the console.AD Connect environment
AuditDurable event log with actor, target, provider, before/after values, outcomes, metadata, warnings, errors, and readable detail view.Local audit journal

AD Reports

Directory reporting without exporting first and figuring it out later.

AD Reports gives operators a practical reporting workspace inside HILOP instead of forcing every directory question through ADUC exports, one-off scripts, or external reporting tools.

01 / Scope

Choose the object set

Run reports against users, devices, or groups across the configured directory root, or narrow the report to a specific OU when the question is limited to one part of the organization.

02 / Attributes

Use the live AD schema

Selectable report attributes are discovered from the current Active Directory schema, with grouped categories to make large schema sets easier to navigate.

03 / Output

View or export

Operators can review results directly in the AD Reports tab, export immediately to CSV, or save reusable custom report definitions under ProgramData.

Device Operations

Find the device from either side of the identity relationship.

HILOP combines Active Directory, Entra ID, and Intune device context so operators can move from a user to assigned devices or from a device back to its primary user.

01 / Search

Search without waiting

A new search replaces the active search. Shared user and device terms stay synchronized, and SAM-account searches can resolve the matching cloud identity for assigned-device discovery.

02 / Secrets

Reveal only on demand

BitLocker recovery keys and Windows LAPS passwords remain hidden until the operator chooses the corresponding reveal action and has the required Microsoft Graph permissions.

03 / Actions

Act at the owning source

Operators can request an Intune sync, rotate a Windows LAPS password, retire a managed device, or delete the selected record from Intune, Entra ID, Active Directory, or all applicable sources.

Workflow action model

Compose procedures from reusable building blocks.

Workflow definitions can combine identity-native operations with broader automation and explicit execution control.

Native identity actions

Operate through HILOP providers

  • Create or update AD users
  • Set managers and group membership
  • Enable remote mailboxes
  • Control supported Exchange attributes
  • Disable cloud or directory accounts
  • Revoke Graph sessions where permitted
Automation actions

Reach beyond first-party providers

  • Invoke REST APIs
  • Execute approved PowerShell
  • Send email
  • Launch browser destinations
  • Delay or wait between steps
  • Capture structured results
Workflow control

Keep procedures understandable

  • Required form validation
  • Confirmation pages
  • Approval gates
  • Conditional branches
  • Computed variables and mappings
  • Continue-on-error behavior when explicitly configured

Operational status

Capability is governed by the selected runtime profile.

HILOP does not bypass tenant, directory, Exchange, Intune, workstation, or service permissions. It centralizes the experience and routes work through the configured provider path.

See the experience

Follow these capabilities through the working interface.

Open the Product Tour