Skip to content
YAADMIN
Download

YAADMIN DOCUMENTATION

Active Directory

Read-only Active Directory users, computers, groups and organizational units.

VerifiedSource snapshot · 2026-10-02

Read-only directory tools#

Search/read users, computers, groups, group membership and OUs, plus health. AD enabled/disabled is an account state, not live endpoint connectivity. Use real provider inventory for live endpoint state.

Identity is separate#

The AD authentication provider supports local/AD login paths independently of this module's read-only tools. First-login provisioning does not grant all roles. AD unavailable does not silently authenticate an AD identity as local.

Exact registered tools#

ad.healthad.health.read

Check native Active Directory/RSAT connectivity. Use only when connectivity is explicitly requested or AD access is failing.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [],
    "additionalProperties": false,
    "properties": {
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        }
    }
}
ad.search_usersad.users.read

Search or list AD users. Omit query (or use '*') to list all users. With query, search by name, sAMAccountName, UPN, mail, department, title, description or DN. enabled_only filters the AD account Enabled flag.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [],
    "additionalProperties": false,
    "properties": {
        "query": {
            "type": [
                "string",
                "null"
            ],
            "description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        },
        "enabled_only": {
            "type": [
                "boolean",
                "null"
            ]
        },
        "max_items": {
            "type": "integer",
            "minimum": 1,
            "maximum": 5000,
            "description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
        }
    }
}
ad.get_userad.users.read

Read detailed AD user properties for an exact identity. Use targets.resolve provider='ad' first when the human name is ambiguous.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [
        "identity"
    ],
    "additionalProperties": false,
    "properties": {
        "identity": {
            "type": "string",
            "minLength": 1,
            "description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        }
    }
}
ad.search_computersad.computers.read

Search or list AD computer objects. Omit query (or use '*') to list all computers. With query, search by name, DNS name, IP, OS, description or DN. Enabled means the AD computer account is enabled; it does NOT mean the PC is online.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [],
    "additionalProperties": false,
    "properties": {
        "query": {
            "type": [
                "string",
                "null"
            ],
            "description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        },
        "enabled_only": {
            "type": [
                "boolean",
                "null"
            ]
        },
        "max_items": {
            "type": "integer",
            "minimum": 1,
            "maximum": 5000,
            "description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
        }
    }
}
ad.get_computerad.computers.read

Read detailed properties of one exact AD computer object. This does not provide live Connected/Disconnected state.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [
        "identity"
    ],
    "additionalProperties": false,
    "properties": {
        "identity": {
            "type": "string",
            "minLength": 1,
            "description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        }
    }
}
ad.search_groupsad.groups.read

Search or list Active Directory groups. Omit query (or use '*') to list all groups. With query, search by name, sAMAccountName, description or DN.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [],
    "additionalProperties": false,
    "properties": {
        "query": {
            "type": [
                "string",
                "null"
            ],
            "description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        },
        "max_items": {
            "type": "integer",
            "minimum": 1,
            "maximum": 5000,
            "description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
        }
    }
}
ad.get_groupad.groups.read

Read one exact AD group's category, scope, description and DN.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [
        "identity"
    ],
    "additionalProperties": false,
    "properties": {
        "identity": {
            "type": "string",
            "minLength": 1,
            "description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        }
    }
}
ad.get_group_membersad.groups.read

List members of an exact AD group. recursive=true expands nested groups. Returns users, computers and nested groups with their object_class.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [
        "identity"
    ],
    "additionalProperties": false,
    "properties": {
        "identity": {
            "type": "string",
            "minLength": 1,
            "description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        },
        "recursive": {
            "type": "boolean",
            "default": false
        },
        "max_items": {
            "type": "integer",
            "minimum": 1,
            "maximum": 5000,
            "default": 500
        }
    }
}
ad.get_user_groupsad.users.read

List AD groups for one exact user identity.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [
        "identity"
    ],
    "additionalProperties": false,
    "properties": {
        "identity": {
            "type": "string",
            "minLength": 1,
            "description": "Exact AD identity: sAMAccountName, DN, GUID or other identity accepted by Get-AD*."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        },
        "max_items": {
            "type": "integer",
            "minimum": 1,
            "maximum": 5000,
            "default": 500
        }
    }
}
ad.search_ousad.ous.read

Search or list Active Directory organizational units (OU). Omit query (or use '*') to list all OUs. With query, search by name, description or distinguished name.

Registration: RiskLevel.READ / ApprovalMode.NEVER · enabled

ExecutionRequest to the provider backend; ExecutionResult carries normalized data/error/status and provider metadata. Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.

Exact input schema

json
{
    "type": "object",
    "required": [],
    "additionalProperties": false,
    "properties": {
        "query": {
            "type": [
                "string",
                "null"
            ],
            "description": "Optional search text. Omit it (or use '*') to list all matching AD objects."
        },
        "profile": {
            "type": "string",
            "minLength": 1,
            "description": "Optional AD profile id; omit to search all configured profiles."
        },
        "max_items": {
            "type": "integer",
            "minimum": 1,
            "maximum": 5000,
            "description": "Optional result limit. Defaults to 50 for text search and 5000 when query is omitted/list-all."
        }
    }
}

Module metadata#

Module ID
ad
Version
1.0.2
Permissions
ad.health.read, ad.users.read, ad.computers.read, ad.groups.read, ad.ous.read
Declared runtime settings
CONTROLHUB_AD_ENABLED, CONTROLHUB_AD_PROFILES, CONTROLHUB_AD_SERVER, CONTROLHUB_AD_SEARCH_BASE, CONTROLHUB_AD_USERNAME, CONTROLHUB_AD_PASSWORD, CONTROLHUB_AD_POWERSHELL, CONTROLHUB_AD_TIMEOUT_SECONDS, CONTROLHUB_AD_HEALTH_TTL_SECONDS, CONTROLHUB_AD_BACKEND_PRIORITY
Dependencies
No declared Python dependencies
Entitlements
Free-tier metadata; runtime enforcement disabled.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.