TWADThe Walkers Directory
Sign in Get started free

Active Directory, without the domain.

TWAD is a self-hosted directory that manages your Windows PCs, signs your people in to them, and does it over the internet — no domain controller to reach, no VPN to keep up. You run it. Nobody else holds your users.

Free for 15 users and 1 node. No card, no expiry, no countdown.

It replaces three things

A directory for your users and groups. Group Policy for your settings. An RMM for your software, scripts and remote support. One product, one console, one licence.

It works anywhere

An AD-joined laptop needs to reach a domain controller. A TWAD laptop reaches your appliance over the internet and behaves identically in the office, at home, or in a hotel — with no VPN.

You host it

A Linux appliance you install, on your hardware or your hypervisor. Your directory never leaves your control, and there is no per-seat cloud bill growing behind you.

What you actually get on day one

A sign-in tile on every PC

People log into Windows with their directory account, get their own profile, on any enrolled machine. Offline too, for a while, and it says so.

Policy that explains itself

Every machine shows its effective policy: what applies, which policy won, and what it overrode. "Why is this PC like this" has an answer.

Remote control and a terminal

See the screen, take the keyboard, open a shell, browse the registry and files — through the agent's own outbound tunnel. Ctrl+Alt+Del included.

Software and scripts

Deploy an MSI to an org unit, run a saved script on demand, or put it on a timer. Verified by hash before anything runs.

Single sign-on

Standard OIDC for your web applications, and a read-only LDAP front end for the NAS boxes that only speak LDAP.

High availability

Add a second appliance and it replicates. Hand the primary role over for maintenance, or promote a survivor when one dies.

Honest about what it is not

TWAD does not do Kerberos, and it is not a domain. Where AD would issue a ticket, TWAD keeps a local Windows account on each PC whose password it keeps in step with the directory — which is why file shares and RDP work normally, and why an old on-premises app that demands Kerberos will not single-sign-on to it.

If that is a hard requirement, AD is still the right answer. We would rather say so here than after you have installed it.