About the AD Connector and Logon Events
For each end-user on the AD domains, the AD Connector forwards the logon events to the deployed VAs. The AD Connector can read logon events for users from the AD domain controllers at the site or a centralized Windows Event Log Collector. You can use an existing deployment of a centralized Windows Event Log Collector where domain controllers forward logon events for multiple AD domains or AD forests. For more information, see Support for Multiple AD Domains and AD Forests.
The domain controller or centralized Windows Event Log Collector record logon events by end users. The user's IP and username are made available through the AD Connector to the VA. The VA is a conditional DNS forwarder. The VA forwards DNS requests to the Secure Access DNS resolvers or, if bypass domains have been configured, forwards DNS requests to the organization's internal DNS servers. Secure Access applies the access rules in the policy to the DNS traffic and displays the end user identity information with the request in the reports and logs.
Note: You must deploy the VA, AD Connector, and domain controllers or centralized Windows Event Log Collector at the same Site registered with Secure Access. For information about Sites, see Manage Sites.