How does KYDSO work?
In KYDSO, accounts are managed automatically on the basis of changes to your employees.
To do this, your employees are created and maintained as persons in KYDSO.
The required accounts are created in KYDSO 's assets and assigned to the person using the account, making it possible to manage all of an employee's accounts centrally and transparently.
When changes are made to a person, the corresponding account in KYDSO is updated. Active Directory accounts are synchronized with your company's Active Directory.

Internal employees continue to be managed in your company's HR system. The current employee base is regularly transferred to KYDSO via a csv interface and...
new employees are automatically created in KYDSO,
changes to the personal data are transferred to KYDSO,
External employees are created and maintained directly in KYDSO by authorized persons in your company.
Employees who have left the company are initially deactivated in KYDSO and then permanently deleted after a defined retention period.
KYDSO automatically creates the corresponding Active Directory account for all new employees.
You can define privileged accounts in KYDSO and order dedicated accounts for individual employees.
For all employees who have left the company, the corresponding Active Directory accounts are first automatically deactivated and then permanently deleted from the Active Directory after a defined retention period.
Any existing memberships in AD groups are then also deleted.
The Active Directory accounts used are managed in KYDSO by authorized persons in your company.
The Active Directory accounts are reconciled with your company's Active Directory via an AD connector.
![]() |
The accounts of your employees in external systems (e.g. SAP) can be managed in KYDSO by authorized persons in your company:
A third-party system account is ordered for an employee in KYDSO and then created in their assets.
You can define which third-party system accounts are automatically ordered when an employee joins the company (basic equipment).
A third-party system account that is no longer required is terminated and then automatically undergoes a deactivation process.
For all employees who have left the company, the associated third-party system accounts are automatically terminated.