Skip to content
Security and identity / Data warehouse · Two-way sync platform

Active Directory and Materialize integration

Plan how Active Directory and Materialize should share data across your business. Work with Stacksync engineers on record mapping, system access, and the requirements for running the integration.

  • Scope your workflow with an integration engineer
  • Review the systems, records, and updates you need

Built for teams where self-serve, reliability and scale matter

Case study
Migrated from MuleSoft
Case study
Migrated from Celigo
Migrated from Heroku Connect
Migrated from Matillion
Case study
Migrated from Fivetran
Case study
Migrated from Celigo

Proposed workflow

Application user or identity reporting workflow

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Starting eventA change involving Active Directory Users or the proposed application user or identity table in Materialize needs a defined result in the other system.

  1. Start with Active Directory Users and the proposed application user or identity table in Materialize. Use the record-matching and field-ownership rules from your mapping worksheet.

  2. Resolve tenant and group references and establish a protected administrative-account policy.

  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

What to verifyTest a renamed login, disabled account, missing group, and a user existing in two tenants.

Review records and field ownership

Proposed record relationships

Records to connect

Use these examples to define record matching and field ownership for your technical review.

Download the mapping worksheet

CSV · No email required

Example record relationships between Active Directory and Materialize
Active Directory recordMaterialize recordRecord matchingField ownership
UsersProposed record; confirm Stacksync object support.Reporting datasetProposed application user or identity tableProposed table; choose its name and schema.Use the immutable user ID within the tenant or directory. Do not equate an application user with a CRM customer contact.Identity and application owners approve account lifecycle and access changes; synchronize only approved attributes.
GroupsProposed record; confirm Stacksync object support.Reporting datasetProposed group or membership tableProposed table; choose its name and schema.Keep group IDs and membership relationships separately from group names.The access owner controls membership; reporting a group is different from granting its permissions.

These relationships do not establish connector availability. Review the required connection and record operations with Stacksync.

Record coverage to review

Use documented coverage where available. Catalog record types are starting points for review and do not confirm Stacksync support.

Active Directory

Connection and object support require review

Record types to review with Stacksync

Record typesCoverage and requirements
  • Users
  • Groups
  • Group memberships
  • Devices
  • Directory roles
  • Service principals & applications
Confirm support for this record type and the direction you need.

Discuss Active Directory requirements

Materialize

Connection and object support require review

Record types to review with Stacksync

Record typesCoverage and requirements
  • Tables
  • Sources
  • Materialized Views
  • Sinks
  • Indexes
  • Clusters
Confirm support for this record type and the direction you need.

Discuss Materialize requirements

Connection essentials

Confirm Stacksync support and account requirements for undocumented connections. Interface information alone does not establish connector availability.

View setup requirements and limits
Connection requirementActive DirectoryMaterialize
Integration interfaceMicrosoft Graph REST API (Entra ID / cloud) and LDAP/LDAPS (on-premises AD DS)PostgreSQL wire protocol (SQL)
AuthenticationConfirm the credentials, API plan, and permissions required for Active Directory.Confirm the credentials, API plan, and permissions required for Materialize.
Change detectionConfirm how Stacksync detects changes for this connector and the objects you need.Confirm how Stacksync detects changes for this connector and the objects you need.
Read accessConfirm with StacksyncConfirm with Stacksync
Write accessConfirm with StacksyncConfirm with Stacksync

Enterprise controls

Security and control for your integrations

Explore security controls

Compliance and data transfers

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.

  • SOC 2 Type II
  • ISO 27001
  • HIPAA BAA
  • GDPR
  • CCPA
  • DPF US-EU-UK-CH

SSO & SCIM

Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.

Alerts

Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.

Secure connection options

Record-level recovery

Inspect sync errors and use retry and revert controls to resolve failed updates.

Read the recovery guide

Implementation

Technical reference

Review setup, record relationships, testing, and recovery for your implementation.

Authentication, permissions and API limits

Connection requirements and limits

Active Directory
Integration interface
Microsoft Graph REST API (Entra ID / cloud) and LDAP/LDAPS (on-premises AD DS)
Authentication
Confirm the credentials, API plan, and permissions required for Active Directory.
Change detection
Confirm how Stacksync detects changes for this connector and the objects you need.
Read access
Confirm with Stacksync
Write access
Confirm with Stacksync
Setup requirements
  • Identify the Active Directory account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for Active Directory, including read/write support, authentication, and initial-load limits.
Limitations to check
  • Confirm Stacksync support for Active Directory and the record types your workflow needs.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.
Materialize
Integration interface
PostgreSQL wire protocol (SQL)
Authentication
Confirm the credentials, API plan, and permissions required for Materialize.
Change detection
Confirm how Stacksync detects changes for this connector and the objects you need.
Read access
Confirm with Stacksync
Write access
Confirm with Stacksync
Setup requirements
  • Identify the Materialize account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for Materialize, including read/write support, authentication, and initial-load limits.
Limitations to check
  • Confirm Stacksync support for Materialize and the record types your workflow needs.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.

Prepare Active Directory and Materialize access

Set up both accounts before testing the mapping. Use test records where available, and identify the account administrator who can approve access and help resolve setup errors.

Active Directory setup checklist
  • Identify the Active Directory account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for Active Directory, including read/write support, authentication, and initial-load limits.
Materialize setup checklist
  • Identify the Materialize account, edition, environment, and business objects the integration must access.
  • Confirm a Stacksync connector or implementation path for Materialize, including read/write support, authentication, and initial-load limits.
Prepare to go live

Record the fields each system can update, the first-load cutoff, both record IDs, the expected update delay, and who handles errors. Complete the tests before production before expanding to more records.

Use the Active Directory and Materialize planning worksheet to capture these decisions. Record the access owner in the worksheet and enter credentials only in the connection setup.

Talk to an engineer · Review current pricing

Record identity and field ownership

Use these data-model references to describe the records your connection needs. They are planning examples; connector availability and supported operations must be established before implementation.

Download the mapping worksheet · CSV, no email required

Reporting dataset

Users / Proposed application user or identity table in Materialize (choose its name)

Plan a application user or identity dataset while preserving its source meaning.

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Active Directory
Object support to establish
Materialize
Your database schema
Record identity
Use the immutable user ID within the tenant or directory. Do not equate an application user with a CRM customer contact.
Field ownership
Identity and application owners approve account lifecycle and access changes; synchronize only approved attributes.

Fields to include

  • Source user ID
  • Tenant reference
  • Account status
  • Group references
Record dependencies
Resolve tenant and group references and establish a protected administrative-account policy.
Validation
Test a renamed login, disabled account, missing group, and a user existing in two tenants.
Recovery
Review access impact before retrying a lifecycle change; reconcile current identity state and retain an approval trail.

Reporting dataset

Groups / Proposed group or membership table in Materialize (choose its name)

Plan a group or membership dataset while preserving its source meaning.

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Active Directory
Object support to establish
Materialize
Your database schema
Record identity
Keep group IDs and membership relationships separately from group names.
Field ownership
The access owner controls membership; reporting a group is different from granting its permissions.

Fields to include

  • Source group ID
  • Member references
  • Tenant reference
  • Group type
Record dependencies
Resolve user and tenant identities before membership changes.
Validation
Test removed membership, nested groups, and equal group names in different tenants.
Recovery
Recompute the approved membership delta before retrying; do not replay an outdated access grant.

Compare integration approaches

Choose a method around one example record and the update your business needs. Use Users / Proposed application user or identity table in Materialize (choose its name) to review record matching and confirm Stacksync support for the required operations. Compare ongoing sync, a custom workflow, and a scheduled export against that requirement.

Stacksync managed sync

Best fit
Review compatibility with a Stacksync engineer using an example of the records and updates you need.
Operating responsibility
Fits ongoing record synchronization when the required operations are supported. Add workflow steps for approvals or business actions that go beyond copying fields.
Before you choose
Check record matching: Use the immutable user ID within the tenant or directory. Do not equate an application user with a CRM customer contact. Verify field coverage, deletion handling, and how changes are detected.

Native vendor integration

Best fit
A vendor-built integration may fit if it supports your Active Directory and Materialize record types.
Operating responsibility
Can reduce setup for a supported workflow. You may need another method for records or business steps it does not cover.
Before you choose
First check whether either vendor offers this integration. If available, verify Users / Proposed application user or identity table in Materialize (choose its name), update direction, account tier, and related-record handling.

Custom API or workflow

Best fit
Consider when Active Directory and Materialize need a transformation, approval, or action outside a direct record sync.
Operating responsibility
Provides control over business steps; the team owns credentials, version changes, error queues, and reconciliation.
Before you choose
Verify endpoint permissions, pagination, quotas, duplicate detection, and failure recovery. Separate reading history from actions that send messages, grant access, or post transactions.

File or scheduled snapshot

Best fit
Consider for a one-time Active Directory / Materialize migration or a reporting need with an explicit freshness window.
Operating responsibility
Can simplify a bounded transfer; later changes and deletion history require another extraction or a separately designed incremental process.
Before you choose
Record the extraction cutoff, source IDs, encoding, date/number formats, and reconciliation totals.

Workflow scenarios and expected results

Application user or identity reporting workflow

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Starting event: A change to the selected Users or Proposed application user or identity table in Materialize (choose its name) record needs a defined result in the other system.

  1. Start with Active Directory Users and Materialize Proposed application user or identity table in Materialize (choose its name). Use the record-matching and field-ownership rules from your mapping worksheet.
  2. Resolve tenant and group references and establish a protected administrative-account policy.
  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

Expected result: Test a renamed login, disabled account, missing group, and a user existing in two tenants.

If it fails: Review access impact before retrying a lifecycle change; reconcile current identity state and retain an approval trail.

Group or membership reporting workflow

Planning example. Stacksync support for the required connection and record operations needs a technical review.

Starting event: A change to the selected Groups or Proposed group or membership table in Materialize (choose its name) record needs a defined result in the other system.

  1. Start with Active Directory Groups and Materialize Proposed group or membership table in Materialize (choose its name). Use the record-matching and field-ownership rules from your mapping worksheet.
  2. Resolve user and tenant identities before membership changes.
  3. Test a normal update and one failed or repeated update in the supported direction. Keep both record IDs with the test results.

Expected result: Test removed membership, nested groups, and equal group names in different tenants.

If it fails: Recompute the approved membership delta before retrying; do not replay an outdated access grant.

Manage approved account changes across Active Directory and Materialize

This is an evaluation scenario; connector and operation support require confirmation.

Starting event: An approved identity change in Active Directory needs to be reflected in the Materialize process.

  1. Identify the tenant and immutable user ID in Active Directory; determine whether a selected destination dataset has a legitimate relationship to that user.
  2. Separate reporting identity context from actions that create users, grant access, or deactivate accounts. Document the approval and effective date before any action.
  3. Keep identity attributes separate from customer contacts and exclude attributes unnecessary for the process.

Expected result: A rename preserves identity; an unapproved access change is withheld; a future-dated change waits until its approved time.

If it fails: Review current permissions and approval before retrying. A stale event must not restore access that has since been removed.

Initial load and acceptance testing

Keep both record IDs with the expected and actual result. Reconcile the same filters and time window in each system.

Users / Proposed application user or identity table in Materialize (choose its name)

Test case

Test a renamed login, disabled account, missing group, and a user existing in two tenants.

Expected result

The expected application user or identity relationship is preserved with no duplicate action or unintended write.

Groups / Proposed group or membership table in Materialize (choose its name)

Test case

Test removed membership, nested groups, and equal group names in different tenants.

Expected result

The expected group or membership relationship is preserved with no duplicate action or unintended write.

Direction and permissions

Test case

Bring an example source record and the intended destination operation to the compatibility review. Confirm the supported route before granting write access.

Expected result

Only an approved, supported direction and permitted fields are written.

Freshness and reconciliation

Test case

Measure source and destination times for the selected records under normal load and a burst. Reconcile IDs and values using the same filters and cutoff.

Expected result

The process meets its agreed freshness target and reconciliation has no unexplained differences.

Failed updates, retries and recovery

Start with the failed record and the destination error, then inspect the source value, field requirements, and access.

Rejected or repeated application user or identity change

Investigate

Inspect Active Directory Users and Materialize Proposed application user or identity table in Materialize (choose its name), their IDs, and the destination error.

Next action

Review access impact before retrying a lifecycle change; reconcile current identity state and retain an approval trail.

Rejected or repeated group or membership change

Investigate

Inspect Active Directory Groups and Materialize Proposed group or membership table in Materialize (choose its name), their IDs, and the destination error.

Next action

Recompute the approved membership delta before retrying; do not replay an outdated access grant.

A record type or update is unavailable

Investigate

Check the Active Directory and Materialize connector guides, account permissions, and any operations marked On Request.

Next action

Ask the integration team to confirm a supported way to handle that record. Verify whether it needs connector configuration or a separate workflow step.

Source and destination disagree after a retry

Investigate

Compare current source values, destination validation, identity mappings, and any side effects already completed.

Next action

Stacksync issue retry reads the current source state. Decide the intended state before retrying or reverting; reconcile downstream effects separately.

Read the Stacksync issues dashboard guide for retry and revert behavior.

Change detection and update delivery

How updates move between Active Directory and Materialize

See how each system detects changes and which updates the other system can receive. Each direction has its own permissions and record requirements.

Active Directory Materialize Direction requires confirmation

Detect changesConfirm how Stacksync detects changes for this connector and the objects you need.

Apply updatesConfirm that Stacksync can create or update the records you need in Materialize.

Materialize Active Directory Direction requires confirmation

Detect changesConfirm how Stacksync detects changes for this connector and the objects you need.

Apply updatesConfirm that Stacksync can create or update the records you need in Active Directory.

Update timing and record limits
  • Measure initial-load and ongoing-change latency separately. Source detection, selected objects, account limits, and destination validation determine the observed delay.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.
  • Review write-back, deletion handling, update timing, and account limits with the integration team.
FAQ

Active Directory and Materialize integration FAQ

Next step

Plan your integration with an engineer

Walk through your Active Directory and Materialize records, field mappings, and requirements with an integration engineer.