Read-only directory tools#
Search/read users, computers, groups, group membership and OUs, plus health. AD enabled/disabled is an account state, not live endpoint connectivity. Use real provider inventory for live endpoint state.
Identity is separate#
The AD authentication provider supports local/AD login paths independently of this module's read-only tools. First-login provisioning does not grant all roles. AD unavailable does not silently authenticate an AD identity as local.
Exact registered tools#
ad.healthad.health.read
Check native Active Directory/RSAT connectivity. Use only when connectivity is explicitly requested or AD access is failing.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [],
"additionalProperties": false,
"properties": {
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
}
}
}ad.search_usersad.users.read
Search or list AD users. Omit query (or use '*') to list all users. With query, search by name, sAMAccountName, UPN, mail, department, title, description or DN. enabled_only filters the AD account Enabled flag.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [],
"additionalProperties": false,
"properties": {
"query": {
"type": [
"string",
"null"
],
"description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
},
"enabled_only": {
"type": [
"boolean",
"null"
]
},
"max_items": {
"type": "integer",
"minimum": 1,
"maximum": 5000,
"description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
}
}
}ad.get_userad.users.read
Read detailed AD user properties for an exact identity. Use targets.resolve provider='ad' first when the human name is ambiguous.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [
"identity"
],
"additionalProperties": false,
"properties": {
"identity": {
"type": "string",
"minLength": 1,
"description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
}
}
}ad.search_computersad.computers.read
Search or list AD computer objects. Omit query (or use '*') to list all computers. With query, search by name, DNS name, IP, OS, description or DN. Enabled means the AD computer account is enabled; it does NOT mean the PC is online.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [],
"additionalProperties": false,
"properties": {
"query": {
"type": [
"string",
"null"
],
"description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
},
"enabled_only": {
"type": [
"boolean",
"null"
]
},
"max_items": {
"type": "integer",
"minimum": 1,
"maximum": 5000,
"description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
}
}
}ad.get_computerad.computers.read
Read detailed properties of one exact AD computer object. This does not provide live Connected/Disconnected state.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [
"identity"
],
"additionalProperties": false,
"properties": {
"identity": {
"type": "string",
"minLength": 1,
"description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
}
}
}ad.search_groupsad.groups.read
Search or list Active Directory groups. Omit query (or use '*') to list all groups. With query, search by name, sAMAccountName, description or DN.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [],
"additionalProperties": false,
"properties": {
"query": {
"type": [
"string",
"null"
],
"description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
},
"max_items": {
"type": "integer",
"minimum": 1,
"maximum": 5000,
"description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
}
}
}ad.get_groupad.groups.read
Read one exact AD group's category, scope, description and DN.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [
"identity"
],
"additionalProperties": false,
"properties": {
"identity": {
"type": "string",
"minLength": 1,
"description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
}
}
}ad.get_group_membersad.groups.read
List members of an exact AD group. recursive=true expands nested groups. Returns users, computers and nested groups with their object_class.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [
"identity"
],
"additionalProperties": false,
"properties": {
"identity": {
"type": "string",
"minLength": 1,
"description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
},
"recursive": {
"type": "boolean",
"default": false
},
"max_items": {
"type": "integer",
"minimum": 1,
"maximum": 5000,
"default": 500
}
}
}ad.get_user_groupsad.users.read
List AD groups for one exact user identity.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [
"identity"
],
"additionalProperties": false,
"properties": {
"identity": {
"type": "string",
"minLength": 1,
"description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
},
"max_items": {
"type": "integer",
"minimum": 1,
"maximum": 5000,
"default": 500
}
}
}ad.search_ousad.ous.read
Search or list Active Directory organizational units (OU). Omit query (or use '*') to list all OUs. With query, search by name, description or distinguished name.
Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled
ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [],
"additionalProperties": false,
"properties": {
"query": {
"type": [
"string",
"null"
],
"description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
},
"profile": {
"type": "string",
"minLength": 1,
"description": "Optional AD profile id; omit to search all configured profiles."
},
"max_items": {
"type": "integer",
"minimum": 1,
"maximum": 5000,
"description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
}
}
}