Active Directory Query v2
The Active Directory Query integration enables you to access and manage Active Directory objects (users, contacts, and computers).
Authentication & Identity Management · Active Directory Query
Details
| ID | Active Directory Query v2 |
|---|---|
| Provider | Microsoft |
| Category | Authentication & Identity Management |
| From Version | 5.0.0 |
| Docker Image | demisto/ldap:2.9.1.9062583 |
| Supported Modules | Agentix Cloud Runtime Security Cloud Posture Security XSIAM EDR Cortex Cloud |
README
The Active Directory Query integration enables you to access and manage Active Directory objects (users, contacts, and computers).
This integration was integrated and tested with version 1.5.0 of Active Directory Query v2
Some changes have been made that might affect your existing content.
If you are upgrading from a previous version of this integration, see Breaking Changes.
Use Cases
Query for Active Directory objects
- Use the
!ad-searchcommand to run a query for Active Directory objects (users, contacts, computers, and so on). This command enables you to determine which data fields should be returned for the objects.
Manage users and contacts
- The integration enables you to create, update, and delete users and contacts in Active Directory using the following commands:
ad-create-userad-create-contactad-update-userad-update-contactad-delete-user(to delete both users and contacts)
- Add or remove users from groups using the following commands:
ad-add-to-groupad-remove-from-group
- Enable or disable a user account using the following commands:
ad-enable-accountad-disable-user-account
Manage Computers
- Modify a computer organizational unit using the ‘ad-modify-computer-ou’ command.
- Add or remove a computer from a group using the following commands:
ad-add-to-groupad-remove-from-group
IAM premium pack uses
- Create or modify Active Directory users.
- Manage user accounts and their status
Configure Active Directory Query v2 in Cortex
| Parameter | Description | Required |
|---|---|---|
| Server IP address (for example, 192.168.0.1) | The Server IP that should be used to access Active Directory. | True |
| Port | Server port. If not specified, the default port is 389 for LDAP, 636 for LDAPS, or 3268 for global catalog servers. | False |
| Credentials | User credentials. | True |
| Password | True | |
| NTLM authentication | Indicates whether to use NTLM authentication. | False |
| Base DN (for example “dc=company,dc=com”) | The basic hierarchical path of objects in the active directory. | True |
| Page size | The number of results to be returned, per page (page - response content from AD server), from a query. This may effect query run time. | True |
| Secure Connection | Use SSL or Start TLS for secure connection or ‘None’ for communication over clear-text. | True |
| SSL Version | The SSL\TLS version to use in SSL or Start TLS connections types. It is recommended to select the TLS_CLIENT option, which auto-negotiate the highest protocol version that both the client and server support, and configure the context client-side connections. For more information please see: ssl.PROTOCOLS). | False |
| Trust any certificate (not secure) | Select to avoid server certification validation. You may want to do this in case Cortex XSOAR cannot validate the integration server certificate (due to a missing CA certificate) | False |
| Incoming Mapper | Used in the IAM commands. | True |
| Outgoing Mapper | Used in the IAM commands. | True |
| Group CN for terminated employees | False | |
| Create user if does not exist | If true, the user is created if the user profile doesn’t exist in AD. Used in IAM commands only. | False |
Note: For queries and operations across multiple domains within an Active Directory forest the server port should be 3268. This port is used for queries specifically targeted for the global catalog. LDAP requests sent to port 3268 can be used to search for objects in the entire Active Directory forest. For more information on global catalog see the Microsoft documentation.
Identity Lifecycle Management premium pack configuration
The premium ILM content pack introduces new functionality that uses both an incoming and an outgoing mapper.
- Configure the “Incoming Mapper” with the name of the incoming mapper that you’re using. ILM’s default mapper is “User Profile - Active Directory (Incoming)”.
- Configure the “Outgoing Mapper” with the name of the outgoing mapper that you’re using. ILM’s default mapper is “User Profile - Active Directory (Outgoing)”.
Note: As part of the configuration of the mapper, you must map a value to the OU (organizational unit) required field. To do this, create a transformer that maps a user attribute of your choice to an OU value.
To allow the integration to access the mapper from within the code, as required by the ILM pack, both mappers have to be configured in their proper respective fields and not in the “Mapper (outgoing)” dropdown list selector.
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
ad-expire-password
Expires the password of an Active Directory user.
Base Command
ad-expire-password
Required Permissions
Requires Reset user passwords and force password change at next logon permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username (samAccountName) of the user to modify. | Required |
| base-dn | Root (for example, DC=domain,DC=com). | Optional |
Context Output
There is no context output for this command.
ad-modify-password-never-expire
Modifies the AD account attribute “Password Never Expire”.
Base Command
ad-modify-password-never-expire
Required Permissions
Requires Read userAccountControl and write userAccountControl permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The sAMAccountName of the user to modify. | Required |
| value | Value to set “Password Never Expire”. Possible values are: true, false. | Required |
Context Output
There is no context output for this command.
Command Example
!ad-modify-password-never-expire username=jack value=true
Human Readable Output
AD account jack has set "password never expire" attribute. Value is set to True
ad-create-user
Creates an Active Directory user. This command requires a secure connection (SSL,TLS).
Base Command
ad-create-user
Required Permissions
Requires Create, delete, and manage user accounts permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username (samAccountName) of the user to modify. | Required |
| password | The initial password to set for the user. The user is requested to change the password after login. | Required |
| user-dn | The user DN. | Required |
| display-name | The user display name. | Optional |
| description | A short description of the user. | Optional |
| The user email. | Optional | |
| telephone-number | The user telephone number. | Optional |
| title | The user job title. | Optional |
| custom-attributes | Sets basic or custom attributes of the user object. For example, custom-attributes=”{"notes":"a note about the contact","company":"company name"}”. | Optional |
Context Output
There is no context output for this command.
Command Example
ad-create-user username="jack" password="1q2w3e4r!" user-dn="cn=jack,dc=demisto,dc=int" display-name="Samurai Jack"
Human Readable Output
Created user with DN: cn=jack,dc=demisto,dc=int
ad-search
Runs Active Directory queries.
For more information on the query syntax see the Microsoft documentation.
For more information on LDAP filters, see the LDAP documentation.
Base Command
ad-search
Required Permissions
Requires Read and Read and read all properties permissions in General permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| filter | Enables you to define search criteria in the Query Active Directory using Active Directory syntax. For example, the following query searches for all user objects except Andy: “(&(objectCategory=person)(objectClass=user)(!(cn=andy)))”. Note: If you have special characters such as “”,”(“,or “" the character must be preceded by two backslashes “\”. For example, to use “”, type “\*”. For more information about search filters, see syntax: https://docs.microsoft.com/en-us/windows/win32/adsi/search-filter-syntax. | Required |
| base-dn | Root. For example, DC=domain,DC=com). By default, the Base DN configured for the instance is used. | Optional |
| attributes | A CSV list of the object attributes to return. For example, “dn,memberOf”. To return all object attributes, specify ‘ALL’. | Optional |
| size-limit | The maximum number of records to return. Default is 50. | Optional |
| time-limit | The maximum time to pull records (in seconds). | Optional |
| context-output | Whether to output the search results to the context. Possible values are: yes, no. Default is yes. | Optional |
| page-size | The page size to query. The size-limit value will be ignored. | Optional |
| page-cookie | An opaque string received in a paged search, used for requesting subsequent entries. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ActiveDirectory.Search.dn | string | The distinguished names that match the query. |
| ActiveDirectory.Search | unknown | The result of the search. |
| ActiveDirectory.SearchPageCookie | string | An opaque string received in a paged search, used for requesting subsequent entries. |
Command Example
ad-search filter="(&(objectCategory=person)(objectClass=user)(!(cn=andy)))"
Context Example
{
"ActiveDirectory.Search": [
{
"dn": "CN=demistoadmin,CN=Users,DC=demisto,DC=int"
},
{
"dn": "CN=Guest,CN=Users,DC=demisto,DC=int"
}
]
}
Human Readable Output
Active Directory Search
dn CN=demistoadmin,CN=Users,DC=demisto,DC=int CN=Guest,CN=Users,DC=demisto,DC=int
ad-add-to-group
Adds an Active Directory user or computer to a group.
Base Command
ad-add-to-group
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username of the user to add to the group. If this argument is not specified, the computer name argument must be specified.\n Supports single or comma delimited list of usernames. | Optional |
| computer-name | The name of the computer to add to the group. If this argument is not specified, the username argument must be specified. | Optional |
| group-cn | The name of the group to add the user to. | Required |
| base-dn | Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. | Optional |
| nested_group_cn | The name of the group to add as a member of the group specified group-cn. | Optional |
Context Output
There is no context output for this command.
ad-remove-from-group
Removes an Active Directory user or computer from a group.
Base Command
ad-remove-from-group
Required Permissions
Requires Create, delete, and manage groups permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The name of the user to remove from the group. If this argument is not specified, the computer name argument must be specified. | Optional |
| computer-name | The name of the computer to remove from the group. If this argument is not specified, the username argument must be specified. | Optional |
| group-cn | The name of the group to remove the user from. | Required |
| base-dn | Root. For example, DC=domain,DC=com). By default, the Base DN configured for the instance is used. | Optional |
Context Output
There is no context output for this command.
Command Example
ad-remove-from-group username="jack" group-cn="Users"
Human Readable Output
Object with dn CN=jack,DC=demisto,DC=int removed from group Users
ad-update-user
Updates attributes of an existing Active Directory user.
Base Command
ad-update-user
Required Permissions
Requires Write All Properties and Read All Properties permission from User objects.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username of the account to update (sAMAccountName). | Required |
| attribute-name | The name of the attribute to modify. For example, sn, displayName, mail, and so on. | Required |
| attribute-value | The value to change the attribute to. When attribute-type is “byte”, provide a comma-separated list of decimal integers (0-255), e.g. “0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0” for logonHours. | Required |
| attribute-type | The type of the attribute value. Set to “byte” for binary/Octet String attributes such as logonHours, objectSID, or objectGUID. When set, attribute-value must be a comma-separated list of decimal integers (0-255). Possible values are: byte. | Optional |
| base-dn | Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. | Optional |
Context Output
There is no context output for this command.
Command Example
!ad-update-user attribute-name=description attribute-value=Samurai username=jack
Human Readable Output
Updated user's description to Samurai
ad-delete-user
Deletes an Active Directory user.
Base Command
ad-delete-user
Required Permissions
Requires Create, delete, and manage user accounts permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| user-dn | The DN of the user to delete. | Required |
Context Output
There is no context output for this command.
Command Example
!ad-delete-user user-dn="cn=jack,dc=demisto,dc=int"
Human Readable Output
Deleted object with dn cn=jack,dc=demisto,dc=int
ad-create-contact
Creates an Active Directory contact.
Base Command
ad-create-contact
Required Permissions
Requires full control permission from Contact objects.
Input
| Argument Name | Description | Required |
|---|---|---|
| contact-dn | The contact DN. | Required |
| display-name | The contact display name. | Optional |
| description | The short description of the contact. | Optional |
| The email address of the contact. | Optional | |
| telephone-number | The contact telephone number. | Optional |
| custom-attributes | Sets basic or custom attributes of the contact object. For example, custom-attributes=”{"notes":"some note about the contact","company":"some company"}.”. | Optional |
| title | The contact job title. | Optional |
Context Output
There is no context output for this command.
Command Example
!ad-create-contact contact-dn="cn=jack,dc=demisto,dc=int" description="Samurai" email=jack@company.com
Human Readable Output
Created contact with DN: cn=jack,dc=demisto,dc=int
ad-update-contact
Updates attributes of an existing Active Directory contact.
Base Command
ad-update-contact
Required Permissions
Requires Write All Properties and Read All Properties permission from Contact objects.
Input
| Argument Name | Description | Required |
|---|---|---|
| contact-dn | The contact DN. | Required |
| attribute-name | The attribute name to update. | Required |
| attribute-value | The attribute value to update. When attribute-type is “byte”, provide a comma-separated list of decimal integers (0-255). | Required |
| attribute-type | The type of the attribute value. Set to “byte” for binary/Octet String attributes. When set, attribute-value must be a comma-separated list of decimal integers (0-255). Possible values are: byte. | Optional |
Context Output
There is no context output for this command.
Command Example
ad-update-contact contact-dn="cn=Jack,dc=demisto,dc=int" attribute-name="displayName" attribute-value="Jack H."
Human Readable Output
Updated contact’s displayName to: Jack H.
ad-disable-account
Disables an Active Directory user account.
Base Command
ad-disable-account
Required Permissions
Requires Read userAccountControl and write userAccountControl permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username of the account to disable (sAMAccountName). | Required |
| base-dn | Root (e.g., DC=domain,DC=com). By default, the Base DN configured for the instance is used. | Optional |
Context Output
There is no context output for this command.
Command Example
ad-disable-account username="jack"
Human Readable Output
User “CN=jack,DC=demisto,DC=int” has been disabledUser jack was disabled
ad-enable-account
Enables a previously disabled Active Directory account.
Base Command
ad-enable-account
Required Permissions
Requires Read userAccountControl and write userAccountControl permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username of the account to enable (sAMAccountName). | Required |
| base-dn | Root. For example, DC=domain,DC=com). By default, the Base DN configured for the instance is used. | Optional |
| restore_user | If true, the command will enable the user with his restored options. Possible values are: true, false. | Optional |
Context Output
There is no context output for this command.
Command Example
ad-enable-account username="jack"
Human Readable Output
User jack was enabledUser “CN=jack,DC=demisto,DC=int” has been enabled
ad-unlock-account
Unlocks a previously locked Active Directory user account.
Base Command
ad-unlock-account
Required Permissions
Requires Read lockoutTime and write lockoutTime permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username of the account to unlock (sAMAccountName). | Required |
| base-dn | Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. | Optional |
Context Output
There is no context output for this command.
Command Example
!ad-unlock-account username=mooncake
Human Readable Output
User "CN=mooncake,CN=Users,DC=demisto,DC=int" has been unlocked
ad-set-new-password
Sets a new password for an Active Directory user. This command requires a secure connection (SSL,TLS).
Base Command
ad-set-new-password
Required Permissions
Requires Reset password permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| username | The username of the account to disable (sAMAccountName). | Required |
| password | The password to set for the user. | Required |
| base-dn | Root. For example, DC=domain,DC=com. Base DN configured for the instance is used as default. | Optional |
Context Output
There is no context output for this command.
Command Example
!ad-set-new-password username="NoaCo" password="noni1q2w3e!"
Human Readable Output
User password successfully set
ad-modify-computer-ou
Modifies the computer organizational unit within a domain.
Base Command
ad-modify-computer-ou
Required Permissions
Requires Write All Properties permission from Computer objects.
Input
| Argument Name | Description | Required |
|---|---|---|
| computer-name | The name of the computer to modify. | Required |
| full-superior-dn | Superior DN. For example, OU=computers,DC=domain,DC=com (the specified domain must be the same as the current computer domain). | Optional |
Context Output
There is no context output for this command.
Command Example
!ad-modify-computer-ou computer-name=mike full-superior-dn=OU=Sarah,DC=demisto,DC=int
Human Readable Output
"mike" was successfully moved to "OU=Sarah,DC=demisto,DC=int"
ad-modify-user-ou
Modifies the user organizational unit within a domain.
Base Command
ad-modify-user-ou
Required Permissions
Requires Write All Properties permission from Computer objects.
Input
| Argument Name | Description | Required |
|---|---|---|
| user-name | The name of the user to modify. | Required |
| full-superior-dn | Superior DN. For example, OU=users,DC=domain,DC=com (the specified domain must be the same as the current user domain). | Optional |
Context Output
There is no context output for this command.
Command Example
!ad-modify-user-ou user-name=username full-superior-dn=OU=users,DC=demisto,DC=int
Human Readable Output
"username" was successfully moved to "OU=users,DC=demisto,DC=int"
ad-get-user
Retrieves detailed information about a user account. The user can be specified by name, email address, or as an Active Directory Distinguished Name (DN). If no filter is specified, all users are returned.
Base Command
ad-get-user
Required Permissions
Requires Read all user information permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| dn | The Distinguished Name of the user in which to return information. | Optional |
| name | The name of the user to return information. | Optional |
| attributes | Adds AD attributes of the resulting objects to the default attributes. | Optional |
| attributes-to-exclude | Removes AD attributes of the resulting objects from the attributes. | Optional |
| custom-field-type | Queries users by custom field type. | Optional |
| custom-field-data | Queries users by custom field data (relevant only if the custom-field-type argument is provided). |
Optional |
| username | Queries users by the samAccountName attribute. | Optional |
| sAMAccountName | Queries users by the samAccountName attribute. | Optional |
| limit | The maximum number of objects to return. Default is 20. | Optional |
| Queries by the user’s email address. | Optional | |
| user-account-control-out | Whether to include verbose translation for UserAccountControl flags. Default is false. Possible values are: true, false. Default is false. | Optional |
| page-size | The page size to query. The limit value will be ignored. | Optional |
| page-cookie | An opaque string received in a paged search, used for requesting subsequent entries. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ActiveDirectory.Users.dn | string | The user distinguished name. |
| ActiveDirectory.Users.displayName | string | The user display name. |
| ActiveDirectory.Users.name | string | The user common name. |
| ActiveDirectory.Users.sAMAccountName | string | The user sAMAccountName. |
| ActiveDirectory.Users.userAccountControl | number | The user account control flag. |
| ActiveDirectory.Users.mail | string | The user email address. |
| ActiveDirectory.Users.manager | string | The manager of the user. |
| ActiveDirectory.Users.memberOf | string | Groups in which the user is a member. |
| ActiveDirectory.Users.userAccountControlFields.SCRIPT | bool | Whether the login script is run. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.ACCOUNTDISABLE | bool | Whether the user account is disabled. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.HOMEDIR_REQUIRED | bool | Whether the home folder is required. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.LOCKOUT | bool | Whether the user is locked out. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.PASSWD_NOTREQD | bool | Whether the password is required. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.PASSWD_CANT_CHANGE | bool | Whether the user can change the password. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.ENCRYPTED_TEXT_PWD_ALLOWED | bool | Whether the user can send an encrypted password. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.TEMP_DUPLICATE_ACCOUNT | bool | Whether this is an account for users whose primary account is in another domain. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.NORMAL_ACCOUNT | bool | Whether this is a default account type that represents a typical user. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.INTERDOMAIN_TRUST_ACCOUNT | bool | Whether the account is permitted to trust a system domain that trusts other domains. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.WORKSTATION_TRUST_ACCOUNT | bool | Whether this is a computer account for a computer running Microsoft Windows NT 4.0 Workstation, Microsoft Windows NT 4.0 Server, Microsoft Windows 2000 Professional, or Windows 2000 Server and is a member of this domain. |
| ActiveDirectory.Users.userAccountControlFields.SERVER_TRUST_ACCOUNT | bool | Whether this is a computer account for a domain controller that is a member of this domain. Works for *Windows Server 2012 R2*. |
| ActiveDirectory.Users.userAccountControlFields.DONT_EXPIRE_PASSWORD | bool | Whether to never expire the password on the account. |
| ActiveDirectory.Users.userAccountControlFields.MNS_LOGON_ACCOUNT | bool | Whether this is an MNS login account. |
| ActiveDirectory.Users.userAccountControlFields.SMARTCARD_REQUIRED | bool | Whether to force the user to log in by using a smart card. |
| ActiveDirectory.Users.userAccountControlFields.TRUSTED_FOR_DELEGATION | bool | Whether the service account (the user or computer account) under which a service runs is trusted for Kerberos delegation. |
| ActiveDirectory.Users.userAccountControlFields.NOT_DELEGATED | bool | Whether the security context of the user isn’t delegated to a service even if the service account is set as trusted for Kerberos delegation. |
| ActiveDirectory.Users.userAccountControlFields.USE_DES_KEY_ONLY | bool | Whether to restrict this principal to use only Data Encryption Standard (DES) encryption types for keys. |
| ActiveDirectory.Users.userAccountControlFields.DONT_REQ_PREAUTH | bool | Whether this account require Kerberos pre-authentication for logging on. |
| ActiveDirectory.Users.userAccountControlFields.PASSWORD_EXPIRED | bool | Whether the user password expired. |
| ActiveDirectory.Users.userAccountControlFields.TRUSTED_TO_AUTH_FOR_DELEGATION | bool | Whether the account is enabled for delegation. |
| ActiveDirectory.Users.userAccountControlFields.PARTIAL_SECRETS_ACCOUNT | bool | Whether the account is a read-only domain controller (RODC). |
| ActiveDirectory.UsersPageCookie | string | An opaque string received in a paged search, used for requesting subsequent entries. |
| Account.DisplayName | string | The user display name. |
| Account.Groups | string | Groups for which the user is a member. |
| Account.Manager | string | The user manager. |
| Account.ID | string | The user distinguished name. |
| Account.Username | string | The user samAccountName. |
| Account.Email | string | The user email address. |
Command Example
!ad-get-user name=*
Human Readable Output
Active Directory - Get Users
dn displayName manager memberOf name sAMAccountName userAccountControl CN=demistoadmin,CN=Users,DC=demisto,DC=int demistoadmin demistoadmin@demisto.int CN=Discovery Management,OU=Microsoft Exchange Security Groups,DC=demisto,DC=int,CN=Organization Management,OU=Microsoft Exchange Security Groups,DC=demisto,DC=int,CN=Group Policy Creator Owners,CN=Users,DC=demisto,DC=int,CN=Domain Admins,CN=Users,DC=demisto,DC=int,CN=Enterprise Admins,CN=Users,DC=demisto,DC=int,CN=Schema Admins,CN=Users,DC=demisto,DC=int,CN=Administrators,CN=Builtin,DC=demisto,DC=int demistoadmin demistoadmin 66048 CN=Guest,CN=Users,DC=demisto,DC=int CN=Guests,CN=Builtin,DC=demisto,DC=int Guest Guest 66082
ad-get-computer
Retrieves detailed information about a computer account. The computer can be specified by name, email address, or as an Active Directory Distinguished Name (DN). If no filters are provided, all computers are returned.
Base Command
ad-get-computer
Required Permissions
Requires Read and Read and read all properties permissions from Computer objects.
Input
| Argument Name | Description | Required |
|---|---|---|
| dn | The computer’s DN. | Optional |
| name | The name of the computer to return information about. | Optional |
| attributes | Adds AD attributes of the resulting objects to the default attributes. | Optional |
| custom-field-data | Search computers by custom field data (relevant only if the customFieldType argument is provided). |
Optional |
| custom-field-type | Search the computer by custom field type. | Optional |
| limit | The maximum number of records to return. | Optional |
| page-size | The page size to query. The value limit will be ignored. | Optional |
| page-cookie | An opaque string received in a paged search, used for requesting subsequent entries. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ActiveDirectory.Computers.dn | unknown | The computer distinguished name. |
| ActiveDirectory.Computers.memberOf | unknown | Groups for which the computer is listed. |
| ActiveDirectory.Computers.name | unknown | The computer name. |
| Endpoint.ID | unknown | The computer DN. |
| Endpoint.Hostname | unknown | The computer host name. |
| Endpoint.Groups | unknown | Groups for which the computer is listed as a member. |
| ActiveDirectory.ComputersPageCookie | string | An opaque string received in a paged search, used for requesting subsequent entries. |
Command Example
ad-get-computer name=noapc
Context Example
{
"ActiveDirectory.Computers":
[ { "dn": "CN=noapc,OU=Shani,DC=demisto,DC=int",
"memberOf": [ "CN=Exchange Servers,OU=Microsoft Exchange Security Groups,DC=demisto,DC=int" ],
"name": [ "noapc" ] } ],
"Endpoint": [ { "Hostname": [ "noapc" ],
"Type": "AD", "ID": "CN=noapc,OU=Shani,DC=demisto,DC=int",
"Groups": [ "CN=Exchange Servers,OU=Microsoft Exchange Security Groups,DC=demisto,DC=int" ]
} ]
}
Human Readable Output
Active Directory - Get Computers
dn memberOf name CN=noapc,OU=Shani,DC=demisto,DC=int CN=Exchange Servers,OU=Microsoft Exchange Security Groups,DC=demisto,DC=int noapc
ad-get-group-members
Retrieves the list of users or computers that are members of the specified group.
Base Command
ad-get-group-members
Required Permissions
Requires Read members permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| group-dn | The Distinguished Name of the Group’s Active Directory. | Required |
| member-type | The type of members to search. Can be: “Person”, or “computer”. Default is person. Possible values are: person, computer, group. Default is person. | Required |
| attributes | CSV list of attributes to include in the results, in addition to the default attributes. | Optional |
| time_limit | Time limit (in seconds) for the search to run. Default is 180. | Optional |
| disable-nested-search | Whether to disable recursive retrieval of group memberships of a user. Possible values are: false, true. Default is false. | Optional |
| sAMAccountName | Queries results by the samAccountName attribute. Default is *. | Optional |
| limit | The maximum number of records to return. | Optional |
| page-size | The page size to query. The limit value will be ignored. | Optional |
| page-cookie | An opaque string received in a paged search, used for requesting subsequent entries. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ActiveDirectory.Groups.dn | string | The group DN. |
| ActiveDirectory.Groups.members.dn | string | The group member DN. |
| ActiveDirectory.Groups.members.category | string | The group members category. |
| ActiveDirectory.GroupsPageCookie | string | An opaque string received in a paged search, used for requesting subsequent entries. |
Command Example
!ad-get-group-members group-dn="CN=Group124,OU=DemistoMng,DC=demisto,DC=int"
Context Example
{ "Account":
[ { "DisplayName": [ "User 671 User 671" ],
"Email": null,
"Groups": [ "CN=Group124,OU=DemistoMng,DC=demisto,DC=int", "CN=Group2,OU=DemistoMng,DC=demisto,DC=int" ],
"ID": "CN=User 671 User 671,OU=DemistoMng,DC=demisto,DC=int",
"Managr": [],
"Type": "AD",
"Username": null } ],
"ActiveDirectory":
{ "Groups": { "dn": "CN=Group124,OU=DemistoMng,DC=demisto,DC=int",
"members": [ { "category": "person", "dn": "CN=User 671 User 671,OU=DemistoMng,DC=demisto,DC=int" } ] },
"Users": { "displayName": [ "User 671 User 671" ],
"dn": "CN=User 671 User 671,OU=DemistoMng,DC=demisto,DC=int",
"mail": [ "test@demisto.int" ],
"manager": [],
"memberOf": [ "CN=Group124,OU=DemistoMng,DC=demisto,DC=int",
"CN=Group2,OU=DemistoMng,DC=demisto,DC=int" ],
"name": [ "User 671 User 671" ],
"sAMAccountName": [ "User 671User 671" ],
"userAccountControl": [ 514 ] }
}
}
Human Readable Output
###Active Directory - Get Group Members
dn displayName manager memberOf name sAMAccountName userAccountControl CN=User 671 User User 671 test@demisto.int CN=Group124,OU=DemistoMng,DC=demisto,DC=int User 671 User 671User 671 514 671,OU=DemistoMng,DC=demisto,DC=int User 671 CN=Group2,OU=DemistoMng,DC=demisto,DC=int User 671 User 671User 671 514
ad-create-group
Creates a new security or distribution Active Directory group.
Base Command
ad-create-group
Required Permissions
Requires Create, delete, and manage groups permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| name | The Active Directory name of the group. | Required |
| group-type | The type of group. Can be: “security”, or “distribution”. Possible values are: security, distribution. | Required |
| dn | The Full Distinguished Name (DN) of the group. Use double quotes (“”) rather than single quotes (‘’) when initializing this command. | Required |
| members | The Full DN Of users or groups that will be members of the newly created group. | Optional |
Context Output
There is no context output for this command.
ad-delete-group
Deletes an existing Active Directory security or distribution group.
Base Command
ad-delete-group
Required Permissions
Requires Create, delete, and manage groups permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| dn | The Active Directory Distinguished Name (DN) of the group. | Required |
Context Output
There is no context output for this command.
ad-update-group
Updates attributes of an existing Active Directory group.
Base Command
ad-update-group
Required Permissions
Requires Create, delete, and manage groups permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| groupname | The group name of the group to update (sAMAccountName). | Optional |
| attributename | The name of the attribute to modify. For example, Description and displayName. | Required |
| attributevalue | The value of the attribute to change. When attribute-type is “byte”, provide a comma-separated list of decimal integers (0-255). | Required |
| attribute-type | The type of the attribute value. Set to “byte” for binary/Octet String attributes. When set, attributevalue must be a comma-separated list of decimal integers (0-255). Possible values are: byte. | Optional |
| basedn | Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. | Optional |
Context Output
There is no context output for this command.
ad-test-credentials
Test given credentials.
Base Command
ad-test-credentials
Input
| Argument Name | Description | Required |
|---|---|---|
| username | Username to test. By itself or formatted as SERVER_IP\USERNAME | Required |
| password | Password to test. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| ActiveDirectory.ValidCredentials | Unknown | List of usernames that successfully logged in. |
iam-create-user
Creates an Active Directory user. This command requires a secure connection (SSL,TLS).
Used in the IAM premium pack.
Base Command
iam-create-user
Required Permissions
Requires Create, delete, and manage user accounts permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | A User Profile indicator that contains user information, such as name, email address, etc. | Required |
| allow-enable | When set to true, after the command execution the status of the user in the 3rd-party integration will be active. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.UserProfile | Unknown | The user profile. |
| IAM.Vendor.active | Boolean | If true, the employee status is active. |
| IAM.Vendor.brand | String | The integration name. |
| IAM.Vendor.details | Unknown | Tells the user if the API was successful, otherwise provides error information. |
| IAM.Vendor.email | String | The employee email address. |
| IAM.Vendor.errorCode | Number | The HTTP error response code. |
| IAM.Vendor.errorMessage | String | The reason the API failed. |
| IAM.Vendor.id | String | The employee user ID in the app. |
| IAM.Vendor.instanceName | Unknown | The name of the integration instance. |
| IAM.Vendor.success | Boolean | If true, the command executed successfully. |
| IAM.Vendor.username | String | The employee username in the app. |
| IAM.Vendor.action | String | The command name. |
Command Example
!iam-create-user user-profile={\"email\":\"testdemisto2@paloaltonetworks.com\", \"lastname\":\"Test\",\"firstname\":\"Demisto\"}
Human Readable Output
Create User Results
| brand | instanceName | success | active | id | username | details | |
|---|---|---|---|---|---|---|---|
| Active Directory Query | IAM_instance_1 | true | true | testdemisto2 | testdemisto2@paloaltonetworks.com | status: PROVISIONED created: 2020-10-18T17:54:30.000Z activated: 2020-10-18T17:54:30.000Z statusChanged: 2020-10-18T17:54:30.000Z lastLogin: null lastUpdated: 2020-10-18T17:54:30.000Z passwordChanged: null type: {“id”: “oty8zfz6plq7b0r830h7”} profile: {“firstName”: “Demisto”, “lastName”: “Test”, “mobilePhone”: null, “secondEmail”: null, “login”: “testdemisto2@paloaltonetworks.com”, “email”: “testdemisto44@paloaltonetworks.com”} credentials: {“provider”: {“type”: “Active Directory Query”, “name”: “Active Directory Query”}}} |
iam-get-user
Retrieves a single user resource.
Used in the IAM premium pack.
Base Command
iam-get-user
Required Permissions
Requires Read all user information permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | A User Profile indicator that contains user information, such as name and email address. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.UserProfile | Unknown | The user profile. |
| IAM.Vendor.active | Boolean | If true the employee status is active. |
| IAM.Vendor.brand | String | The integration name. |
| IAM.Vendor.details | Unknown | Tells the user if the API was successful, otherwise provides error information. |
| IAM.Vendor.email | String | The employee email address. |
| IAM.Vendor.errorCode | Number | The HTTP error response code. |
| IAM.Vendor.errorMessage | String | The reason the API failed. |
| IAM.Vendor.id | String | The employee user ID in the app. |
| IAM.Vendor.instanceName | Unknown | The integration instance name. |
| IAM.Vendor.success | Boolean | If true, the command was executed successfully. |
| IAM.Vendor.username | String | The employee username in the app. |
| IAM.Vendor.action | String | The command name. |
Command Example
!iam-get-user user-profile={\"email\":\"testdemisto2@paloaltonetworks.com\"}
Human Readable Output
Get User Results
| brand | instanceName | success | active | id | username | details | |
|---|---|---|---|---|---|---|---|
| Active Directory Query | IAM_instance_1 | true | true | testdemisto2 | testdemisto2@paloaltonetworks.com | status: PROVISIONED created: 2020-10-18T17:54:30.000Z activated: 2020-10-18T17:54:30.000Z statusChanged: 2020-10-18T17:54:30.000Z lastLogin: null lastUpdated: 2020-10-18T17:54:30.000Z passwordChanged: null type: {“id”: “oty8zfz6plq7b0r830h7”} profile: {“firstName”: “Demisto”, “lastName”: “Test”, “mobilePhone”: null, “secondEmail”: null, “login”: “testdemisto2@paloaltonetworks.com”, “email”: “testdemisto44@paloaltonetworks.com”} credentials: {“provider”: {“type”: “Active Directory Query”, “name”: “Active Directory Query”}}} |
iam-update-user
Updates an existing user with the data in the User Profile indicator that is passed in the user-profile argument.
Used in the IAM premium pack.
Base Command
iam-update-user
Required Permissions
Requires Create, delete, and manage user accounts permissions.
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | A User Profile indicator that contains user information, such as name and email address. | Required |
| allow-enable | When set to true, after the command executes the user status in the 3rd-party integration is active. Possible values are: true, false. Default is true. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.UserProfile | Unknown | The user profile |
| IAM.Vendor.active | Boolean | Gives the active status of user. Can be true or false. |
| IAM.Vendor.brand | String | The integration name. |
| IAM.Vendor.details | Unknown | Tells the user if the API was successful, otherwise provides error information. |
| IAM.Vendor.email | String | The employee email address. |
| IAM.Vendor.errorCode | Number | The HTTP error response code. |
| IAM.Vendor.errorMessage | String | The reason the API failed. |
| IAM.Vendor.id | String | The employee user ID in the app. |
| IAM.Vendor.instanceName | Unknown | The integration instance name. |
| IAM.Vendor.success | Boolean | If true, the command executed successfully. |
| IAM.Vendor.username | String | The employee username in the app. |
| IAM.Vendor.action | String | The command name. |
Command Example
!iam-update-user user-profile={\"email\":\"testdemisto22@paloaltonetworks.com\", \"name\":\"testdemisto2\"}
Human Readable Output
Update User Results
| brand | instanceName | success | active | id | username | details | |
|---|---|---|---|---|---|---|---|
| Active Directory Query | IAM_instance_1 | true | true | testdemisto2 | testdemisto22@paloaltonetworks.com | status: PROVISIONED created: 2020-10-18T17:54:30.000Z activated: 2020-10-18T17:54:30.000Z statusChanged: 2020-10-18T17:54:30.000Z lastLogin: null lastUpdated: 2020-10-18T17:54:30.000Z passwordChanged: null type: {“id”: “oty8zfz6plq7b0r830h7”} profile: {“firstName”: “Demisto”, “lastName”: “Test”, “mobilePhone”: null, “secondEmail”: null, “login”: “testdemisto2@paloaltonetworks.com”, “email”: “testdemisto44@paloaltonetworks.com”} credentials: {“provider”: {“type”: “Active Directory Query”, “name”: “Active Directory Query”}}} |
iam-disable-user
Disables a user.
Used in the IAM premium pack.
Base Command
iam-disable-user
Required Permissions
Requires Read userAccountControl and write userAccountControl permissions.
Input
iam-disable-user
Disables a user.
Base Command
iam-disable-user
Input
| Argument Name | Description | Required |
|---|---|---|
| user-profile | A User Profile indicator that contains user information, such as name and email address. | Required |
Context Output
| Path | Type | Description |
|---|---|---|
| IAM.UserProfile | Unknown | The user profile. |
| IAM.Vendor.active | Boolean | Gives the active status of user. Can be true or false. |
| IAM.Vendor.brand | String | The integration name. |
| IAM.Vendor.details | Unknown | Tells the user if the API was successful, otherwise provides error information. |
| IAM.Vendor.email | String | The employee email address. |
| IAM.Vendor.errorCode | Number | The HTTP error response code. |
| IAM.Vendor.errorMessage | String | The reason the API failed. |
| IAM.Vendor.id | String | The employee user ID in the app. |
| IAM.Vendor.instanceName | Unknown | The integration instance name. |
| IAM.Vendor.success | Boolean | If true, the command was executed successfully. |
| IAM.Vendor.username | String | The employee username in the app. |
| IAM.Vendor.action | String | The command name. |
There are no input arguments for this command.
Context Output
There is no context output for this command.
Incident Mirroring
You can enable incident mirroring between Cortex XSOAR incidents and Active Directory Query v2 corresponding events (available from Cortex XSOAR version 6.0.0).
To set up the mirroring, enable Fetching incidents in your instance configuration.
Newly fetched incidents will be mirrored in the chosen direction. However, this selection does not affect existing incidents.
Important Note: To ensure the mirroring works as expected, mappers are required, both for incoming and outgoing, to map the expected fields in Cortex XSOAR and Active Directory Query v2.
Breaking changes from the previous version of this integration - Active Directory Query v2
The following sections list the changes in this version.
Arguments
The following arguments were added in this version
In the ad-get-user command:
- attributes-to-exclude
get-mapping-fields
Retrieves a User Profile schema which holds all of the user fields in the application. Used for outgoing mapping through the Get Schema option.
Base Command
get-mapping-fields
Input
| Argument Name | Description | Required |
| — | — | — |
Context Output
There is no context output for this command.
Configuration parameters
server_ip— Server IP address (for example, 192.168.0.1) (required)port— Server port. If not specified, the default port is 389 for LDAP, 636 for LDAPS, or 3268 for global catalog servers.credentials— Username (required)ntlm— NTLM authenticationbase_dn— Base DN (for example "dc=company,dc=com") (required)page_size— Page sizesecure_connection— Secure Connection (required)ssl_version— SSL Versionunsecure— Trust any certificate (not secure)verify_base_dn— Verify base DN on every commandmapper-in— Incoming Mapper (required)mapper-out— Outgoing Mapper (required)group-cn— Group CN for terminated employeescreate-if-not-exists— Create user if does not existdefault_base_query— Default base query to use in the ad-get-user command
Commands (28)
-
ad-add-to-groupAdds an Active Directory user or computer to a group.
-
ad-create-contactCreates an Active Directory contact.
-
ad-create-groupCreates a new security or distribution Active Directory group.
-
ad-create-userCreates an Active Directory user. This command requires a secure connection (SSL,TLS).
-
ad-delete-groupDeletes an existing Active Directory security or distribution group.
-
ad-delete-userDeletes an Active Directory user.
-
ad-disable-accountDisables an Active Directory user account.
-
ad-enable-accountEnables a previously disabled Active Directory account.
-
ad-expire-passwordExpires the password of an Active Directory user.
-
ad-get-computerRetrieves detailed information about a computer account. The computer can be specified by name, email address, or as an Active Directory Distinguished Name (DN). If no filters are provided, all computers are returned.
-
ad-get-group-membersRetrieves the list of users or computers that are members of the specified group.
-
ad-get-userRetrieves detailed information about a user account. The user can be specified by name, email address, or as an Active Directory Distinguished Name (DN). If no filter is specified, all users are returned.
-
ad-modify-computer-ouModifies the computer organizational unit within a domain.
-
ad-modify-password-never-expireModifies the AD account attribute "Password Never Expire".
-
ad-modify-user-ouModifies the user organizational unit within a domain.
-
ad-remove-from-groupRemoves an Active Directory user or computer from a group.
-
ad-searchRuns Active Directory queries.
-
ad-set-new-passwordSets a new password for an Active Directory user. This command requires a secure connection (SSL,TLS).
-
ad-test-credentialsTest given credentials.
-
ad-unlock-accountUnlocks a previously locked Active Directory user account.
-
ad-update-contactUpdates attributes of an existing Active Directory contact.
-
ad-update-groupUpdates attributes of an existing Active Directory group.
-
ad-update-userUpdates attributes of an existing Active Directory user.
-
get-mapping-fieldsRetrieves a User Profile schema which holds all of the user fields in the application. Used for outgoing mapping through the Get Schema option.
-
iam-create-userCreates an Active Directory user. This command requires a secure connection (SSL,TLS).
-
iam-disable-userDisables a user.
-
iam-get-userRetrieves a single user resource.
-
iam-update-userUpdates an existing user with the data in the User Profile indicator that is passed in the user-profile argument.
commonfields: id: Active Directory Query v2 version: -1 sectionorder: - Connect - Collect name: Active Directory Query v2 display: Active Directory Query v2 category: Authentication & Identity Management provider: Microsoft description: The Active Directory Query integration enables you to access and manage Active Directory objects (users, contacts, and computers). configuration: - display: Server IP address (for example, 192.168.0.1) name: server_ip type: 0 required: true section: Connect - display: Server port. If not specified, the default port is 389 for LDAP, 636 for LDAPS, or 3268 for global catalog servers. name: port type: 0 section: Connect advanced: true required: false - display: Username name: credentials type: 9 required: true section: Connect displaypassword: Password - display: NTLM authentication name: ntlm type: 8 section: Connect advanced: true required: false - display: Base DN (for example "dc=company,dc=com") name: base_dn type: 0 required: true section: Connect - display: Page size name: page_size defaultvalue: "500" type: 0 required: false section: Collect - display: Secure Connection name: secure_connection defaultvalue: SSL type: 15 required: true options: - None - SSL - TLS - Start TLS section: Connect - additionalinfo: 'The SSL\TLS version to use in SSL or Start TLS connections types. Default is None. It is recommended to select the TLS_CLIENT option, which auto-negotiate the highest protocol version that both the client and server support, and configure the context client-side connections.' defaultvalue: None display: SSL Version name: ssl_version options: - None - TLS - TLSv1 - TLSv1_1 - TLSv1_2 - TLS_CLIENT type: 15 section: Connect advanced: true required: false - display: Trust any certificate (not secure) name: unsecure type: 8 section: Connect advanced: true required: false - name: verify_base_dn display: Verify base DN on every command defaultvalue: 'true' type: 8 required: false section: Connect advanced: true - additionalinfo: Used in the IAM commands. defaultvalue: User Profile - Active Directory (Incoming) display: Incoming Mapper name: mapper-in required: true type: 0 section: Connect - additionalinfo: Used in the IAM commands. defaultvalue: User Profile - Active Directory (Outgoing) display: Outgoing Mapper name: mapper-out required: true type: 0 section: Connect - display: Group CN for terminated employees name: group-cn type: 0 section: Connect required: false - additionalinfo: If true, the user is created if the user profile doesn't exist in AD. Used in IAM commands only. defaultvalue: 'true' display: Create user if does not exist name: create-if-not-exists type: 8 section: Connect advanced: true required: false - display: Default base query to use in the ad-get-user command additionalinfo: This value will only be used when no arguments were given to the ad-get-user command. name: default_base_query type: 0 section: Connect advanced: true required: false defaultvalue: '(&(objectClass=User)(objectCategory=person))' script: script: '' type: python subtype: python3 commands: - name: ad-expire-password prettyname: Force Password Reset [ActiveDirectory] quickaction: false quickaction:platform: true arguments: - name: username required: true description: The username (samAccountName) of the user to modify. prettyname: username - name: base-dn prettyname: Base DN description: Root (for example, DC=domain,DC=com). description: Expires the password of an Active Directory user. compliantpolicies: - User Soft Remediation - name: ad-create-user arguments: - name: username required: true description: The username (samAccountName) of the user to modify. - name: password required: true description: 'The initial password to set for the user. The user is requested to change the password after login.' - name: user-dn required: true description: The user DN. - name: display-name description: The user display name. - name: description description: A short description of the user. - name: email description: The user email. - name: telephone-number description: The user telephone number. - name: title description: The user job title. - name: custom-attributes description: Sets basic or custom attributes of the user object. For example, custom-attributes="{\"notes\":\"a note about the contact\",\"company\":\"company name\"}". description: Creates an Active Directory user. This command requires a secure connection (SSL,TLS). - name: ad-search arguments: - name: filter required: true description: 'Enables you to define search criteria in the Query Active Directory using Active Directory syntax. For example, the following query searches for all user objects except Andy: "(&(objectCategory=person)(objectClass=user)(!(cn=andy)))". Note: If you have special characters such as "*","(",or "\" the character must be preceded by two backslashes "\\". For example, to use "*", type "\\*". For more information about search filters, see syntax: https://docs.microsoft.com/en-us/windows/win32/adsi/search-filter-syntax' - name: base-dn description: Root. For example, DC=domain,DC=com). By default, the Base DN configured for the instance is used. - name: attributes description: A CSV list of the object attributes to return. For example, "dn,memberOf". To return all object attributes, specify 'ALL'. - name: size-limit description: The maximum number of records to return. defaultValue: "50" - name: time-limit description: The maximum time to pull records (in seconds). - name: context-output auto: PREDEFINED predefined: - "yes" - "no" defaultValue: "yes" description: Whether to output the search results to the context. - name: page-size description: The page size to query. The size-limit value will be ignored. - name: page-cookie description: An opaque string received in a paged search, used for requesting subsequent entries. outputs: - contextPath: 'ActiveDirectory.Search.dn' description: The distinguished names that match the query. type: string - contextPath: 'ActiveDirectory.Search' description: The result of the search. type: unknown - contextPath: ActiveDirectory.SearchPageCookie description: An opaque string received in a paged search, used for requesting subsequent entries. type: string description: Runs Active Directory queries. - name: ad-add-to-group arguments: - name: username description: "The username of the user to add to the group. If this argument is not specified, the computer name argument must be specified.\\n Supports single or comma delimited list of usernames." - name: computer-name description: The name of the computer to add to the group. If this argument is not specified, the username argument must be specified. - name: group-cn required: true description: The name of the group to add the user to. - name: base-dn description: Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. - description: The name of the group to add as a member of the group specified group-cn. name: nested_group_cn description: Adds an Active Directory user or computer to a group. - name: ad-remove-from-group arguments: - name: username description: "The name of the user to remove from the group. If this argument is not specified, the computer name argument must be specified." - name: computer-name description: The name of the computer to remove from the group. If this argument is not specified, the username argument must be specified. - name: group-cn required: true description: "The name of the group to remove the user from." - name: base-dn description: Root. For example, DC=domain,DC=com). By default, the Base DN configured for the instance is used. description: Removes an Active Directory user or computer from a group. - name: ad-update-user arguments: - name: username required: true description: "The username of the account to update (sAMAccountName)." - name: attribute-name required: true description: The name of the attribute to modify. For example, sn, displayName, mail, and so on. - name: attribute-value required: true description: The value to change the attribute to. When attribute-type is "byte", provide a comma-separated list of decimal integers (0-255), e.g. "0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0" for logonHours. - name: attribute-type description: The type of the attribute value. Set to "byte" for binary/Octet String attributes such as logonHours, objectSID, or objectGUID. When set, attribute-value must be a comma-separated list of decimal integers (0-255). auto: PREDEFINED predefined: - byte - name: base-dn description: Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. description: Updates attributes of an existing Active Directory user. compliantpolicies: - User Hard Remediation - name: ad-delete-user arguments: - name: user-dn required: true description: The DN of the user to delete. description: Deletes an Active Directory user. compliantpolicies: - User Hard Remediation - name: ad-create-contact arguments: - name: contact-dn required: true description: "The contact DN." - name: display-name description: "The contact display name." - name: description description: The short description of the contact. - name: email description: The email address of the contact. - name: telephone-number description: The contact telephone number. - name: custom-attributes description: Sets basic or custom attributes of the contact object. For example, custom-attributes="{\"notes\":\"some note about the contact\",\"company\":\"some company\"}". - name: title description: The contact job title. description: Creates an Active Directory contact. - name: ad-update-contact arguments: - name: contact-dn required: true description: "The contact DN." - name: attribute-name required: true description: "The attribute name to update." - name: attribute-value required: true description: "The attribute value to update. When attribute-type is \"byte\", provide a comma-separated list of decimal integers (0-255)." - name: attribute-type description: The type of the attribute value. Set to "byte" for binary/Octet String attributes. When set, attribute-value must be a comma-separated list of decimal integers (0-255). auto: PREDEFINED predefined: - byte description: Updates attributes of an existing Active Directory contact. - name: ad-disable-account quickaction: false quickaction:platform: true prettyname: Disable User Account [ActiveDirectory] arguments: - description: "The username of the account to disable (sAMAccountName)." name: username required: true prettyname: username - name: base-dn prettyname: Base DN description: Root (e.g., DC=domain,DC=com). By default, the Base DN configured for the instance is used. description: Disables an Active Directory user account. compliantpolicies: - User Hard Remediation - name: ad-enable-account quickaction: false quickaction:platform: true prettyname: Enable User Account [ActiveDirectory] arguments: - name: username prettyname: username required: true description: "The username of the account to enable (sAMAccountName)." - name: base-dn prettyname: Base DN description: Root. For example, DC=domain,DC=com). By default, the Base DN configured for the instance is used. - name: restore_user auto: PREDEFINED predefined: - 'true' - 'false' description: "If true, the command will enable the user with his restored options." description: Enables a previously disabled Active Directory account. compliantpolicies: - User Hard Remediation - name: ad-unlock-account arguments: - name: username required: true description: "The username of the account to unlock (sAMAccountName)." - name: base-dn description: Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. description: Unlocks a previously locked Active Directory user account. compliantpolicies: - User Soft Remediation - name: ad-set-new-password arguments: - name: username required: true description: "The username whose password will be changed." - name: password secret: true required: true description: "The password to set for the user." - name: base-dn description: Root. For example, DC=domain,DC=com. Base DN configured for the instance is used as default. description: Sets a new password for an Active Directory user. This command requires a secure connection (SSL,TLS). compliantpolicies: - User Soft Remediation - name: ad-modify-computer-ou arguments: - name: computer-name required: true description: "The name of the computer to modify." - name: full-superior-dn description: Superior DN. For example, OU=computers,DC=domain,DC=com (the specified domain must be the same as the current computer domain). description: Modifies the computer organizational unit within a domain. - name: ad-modify-user-ou arguments: - name: user-name required: true description: "The name of the user to modify." - name: full-superior-dn description: Superior DN. For example, OU=users,DC=domain,DC=com (the specified domain must be the same as the current user domain). description: Modifies the user organizational unit within a domain. compliantpolicies: - User Hard Remediation - name: ad-get-user arguments: - name: dn default: true description: The Distinguished Name of the user in which to return information. - name: name description: The name of the user to return information. - name: attributes description: Adds AD attributes of the resulting objects to the default attributes. - name: attributes-to-exclude description: Removes AD attributes of the resulting objects from the attributes. - name: custom-field-type description: Queries users by custom field type. - name: custom-field-data description: Queries users by custom field data (relevant only if the `custom-field-type` argument is provided). - name: username description: Queries users by the samAccountName attribute. - name: sAMAccountName description: Queries users by the samAccountName attribute. - name: email description: Queries by the user's email address. - name: user-account-control-out auto: PREDEFINED predefined: - "true" - "false" description: Whether to include verbose translation for UserAccountControl flags. Default is false. defaultValue: "false" - name: limit description: The maximum number of objects to return. defaultValue: "20" - name: page-size description: The page size to query. The limit value will be ignored. - name: page-cookie description: An opaque string received in a paged search, used for requesting subsequent entries. outputs: - contextPath: 'ActiveDirectory.Users.dn' description: The user distinguished name. type: string - contextPath: 'ActiveDirectory.Users.displayName' description: The user display name. type: string - contextPath: 'ActiveDirectory.Users.name' description: The user common name. type: string - contextPath: 'ActiveDirectory.Users.sAMAccountName' description: The user sAMAccountName. type: string - contextPath: 'ActiveDirectory.Users.userAccountControl' description: The user account control flag. type: number - contextPath: 'ActiveDirectory.Users.mail' description: The user email address. type: string - contextPath: 'ActiveDirectory.Users.manager' description: The manager of the user. type: string - contextPath: 'ActiveDirectory.Users.memberOf' description: Groups in which the user is a member. type: string - contextPath: ActiveDirectory.Users.userAccountControlFields.SCRIPT description: Whether the login script is run. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.ACCOUNTDISABLE description: Whether the user account is disabled. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.HOMEDIR_REQUIRED description: Whether the home folder is required. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.LOCKOUT description: Whether the user is locked out. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.PASSWD_NOTREQD description: Whether the password is required. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.PASSWD_CANT_CHANGE description: Whether the user can change the password. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.ENCRYPTED_TEXT_PWD_ALLOWED description: Whether the user can send an encrypted password. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.TEMP_DUPLICATE_ACCOUNT description: Whether this is an account for users whose primary account is in another domain. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.NORMAL_ACCOUNT description: Whether this is a default account type that represents a typical user. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.INTERDOMAIN_TRUST_ACCOUNT description: Whether the account is permitted to trust a system domain that trusts other domains. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.WORKSTATION_TRUST_ACCOUNT description: Whether this is a computer account for a computer running Microsoft Windows NT 4.0 Workstation, Microsoft Windows NT 4.0 Server, Microsoft Windows 2000 Professional, or Windows 2000 Server and is a member of this domain. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.SERVER_TRUST_ACCOUNT description: Whether this is a computer account for a domain controller that is a member of this domain. Works for *Windows Server 2012 R2*. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.DONT_EXPIRE_PASSWORD description: Whether to never expire the password on the account. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.MNS_LOGON_ACCOUNT description: Whether this is an MNS login account. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.SMARTCARD_REQUIRED description: Whether to force the user to log in by using a smart card. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.TRUSTED_FOR_DELEGATION description: Whether the service account (the user or computer account) under which a service runs is trusted for Kerberos delegation. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.NOT_DELEGATED description: Whether the security context of the user isn't delegated to a service even if the service account is set as trusted for Kerberos delegation. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.USE_DES_KEY_ONLY description: Whether to restrict this principal to use only Data Encryption Standard (DES) encryption types for keys. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.DONT_REQ_PREAUTH description: Whether this account require Kerberos pre-authentication for logging on. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.PASSWORD_EXPIRED description: Whether the user password expired. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.TRUSTED_TO_AUTH_FOR_DELEGATION description: Whether the account is enabled for delegation. type: bool - contextPath: ActiveDirectory.Users.userAccountControlFields.PARTIAL_SECRETS_ACCOUNT description: Whether the account is a read-only domain controller (RODC). type: bool - contextPath: 'ActiveDirectory.UsersPageCookie' description: An opaque string received in a paged search, used for requesting subsequent entries. type: string - contextPath: 'Account.DisplayName' description: The user display name. type: string - contextPath: 'Account.Groups' description: "Groups for which the user is a member." type: string - contextPath: 'Account.Manager' description: "The user manager." type: string - contextPath: 'Account.ID' description: The user distinguished name. type: string - contextPath: 'Account.Username' description: The user samAccountName. type: string - contextPath: 'Account.Email' description: The user email address. type: string description: Retrieves detailed information about a user account. The user can be specified by name, email address, or as an Active Directory Distinguished Name (DN). If no filter is specified, all users are returned. - name: ad-get-computer arguments: - name: dn description: The computer's DN. - name: name description: The name of the computer to return information about. - name: attributes description: Adds AD attributes of the resulting objects to the default attributes. - name: custom-field-data description: Search computers by custom field data (relevant only if the `customFieldType` argument is provided). - name: custom-field-type description: Search the computer by custom field type. - name: limit description: The maximum number of records to return. - name: page-size description: The page size to query. The limit value will be ignored. - name: page-cookie description: An opaque string received in a paged search, used for requesting subsequent entries. outputs: - contextPath: 'ActiveDirectory.Computers.dn' description: The computer distinguished name. - contextPath: 'ActiveDirectory.Computers.memberOf' description: Groups for which the computer is listed. - contextPath: 'ActiveDirectory.Computers.name' description: The computer name. - contextPath: 'Endpoint.ID' description: The computer DN. - contextPath: 'Endpoint.Hostname' description: The computer host name. - contextPath: 'Endpoint.Groups' description: Groups for which the computer is listed as a member. - contextPath: ActiveDirectory.ComputersPageCookie description: An opaque string received in a paged search, used for requesting subsequent entries. type: string description: 'Retrieves detailed information about a computer account. The computer can be specified by name, email address, or as an Active Directory Distinguished Name (DN). If no filters are provided, all computers are returned.' - name: ad-get-group-members arguments: - name: group-dn required: true description: "The Distinguished Name of the Group's Active Directory." - name: member-type required: true auto: PREDEFINED predefined: - person - computer - group description: 'The type of members to search. Can be: "Person", or "computer". Default is person.' defaultValue: person - name: attributes description: CSV list of attributes to include in the results, in addition to the default attributes. - defaultValue: '180' description: Time limit (in seconds) for the search to run. name: time_limit - auto: PREDEFINED defaultValue: 'false' description: Whether to disable recursive retrieval of group memberships of a user. name: disable-nested-search predefined: - 'false' - 'true' - name: sAMAccountName description: Queries results by the samAccountName attribute. defaultValue: '*' - name: limit description: The maximum number of records to return. - name: page-size description: The page size to query. The limit value will be ignored. - name: page-cookie description: An opaque string received in a paged search, used for requesting subsequent entries. outputs: - contextPath: 'ActiveDirectory.Groups.dn' description: The group DN. type: string - contextPath: 'ActiveDirectory.Groups.members.dn' description: The group member DN. type: string - contextPath: 'ActiveDirectory.Groups.members.category' description: The group members category. type: string - contextPath: ActiveDirectory.GroupsPageCookie description: An opaque string received in a paged search, used for requesting subsequent entries. type: string description: Retrieves the list of users or computers that are members of the specified group. - name: ad-create-group arguments: - name: name description: The Active Directory name of the group. required: true - name: group-type description: 'The type of group. Can be: "security", or "distribution".' required: true auto: PREDEFINED predefined: - security - distribution - name: dn required: true description: The Full Distinguished Name (DN) of the group. Use double quotes ("") rather than single quotes ('') when initializing this command. - name: members description: The Full DN Of users or groups that will be members of the newly created group. isArray: true description: Creates a new security or distribution Active Directory group. execution: true - name: ad-delete-group arguments: - name: dn description: The Active Directory Distinguished Name (DN) of the group. required: true description: Deletes an existing Active Directory security or distribution group. execution: true - arguments: - name: user-profile required: true description: A User Profile indicator that contains user information, such as name, email address, etc. - auto: PREDEFINED defaultValue: 'true' description: When set to true, after the command execution the status of the user in the 3rd-party integration will be active. name: allow-enable predefined: - 'true' - 'false' description: Creates an Active Directory user. This command requires a secure connection (SSL,TLS). name: iam-create-user outputs: - contextPath: IAM.UserProfile description: The user profile. type: Unknown - contextPath: IAM.Vendor.active description: If true, the employee status is active. type: Boolean - contextPath: IAM.Vendor.brand description: The integration name. type: String - contextPath: IAM.Vendor.details description: Tells the user if the API was successful, otherwise provides error information. type: Unknown - contextPath: IAM.Vendor.email description: The employee email address. type: String - contextPath: IAM.Vendor.errorCode description: The HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: The reason the API failed. type: String - contextPath: IAM.Vendor.id description: The employee user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: The name of the integration instance. type: Unknown - contextPath: IAM.Vendor.success description: If true, the command executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee username in the app. type: String - contextPath: IAM.Vendor.action description: The command name. type: String - arguments: - name: user-profile required: true description: A User Profile indicator that contains user information, such as name and email address. description: "Retrieves a single user resource." name: iam-get-user outputs: - contextPath: IAM.UserProfile description: The user profile. type: Unknown - contextPath: IAM.Vendor.active description: If true the employee status is active. type: Boolean - contextPath: IAM.Vendor.brand description: The integration name. type: String - contextPath: IAM.Vendor.details description: Tells the user if the API was successful, otherwise provides error information. type: Unknown - contextPath: IAM.Vendor.email description: The employee email address. type: String - contextPath: IAM.Vendor.errorCode description: The HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: The reason the API failed. type: String - contextPath: IAM.Vendor.id description: The employee user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: The integration instance name. type: Unknown - contextPath: IAM.Vendor.success description: If true, the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee username in the app. type: String - contextPath: IAM.Vendor.action description: The command name. type: String - arguments: - name: user-profile required: true description: A User Profile indicator that contains user information, such as name and email address. - auto: PREDEFINED defaultValue: 'true' description: When set to true, after the command executes the user status in the 3rd-party integration is active. name: allow-enable predefined: - 'true' - 'false' description: 'Updates an existing user with the data in the User Profile indicator that is passed in the user-profile argument.' name: iam-update-user outputs: - contextPath: IAM.UserProfile description: The user profile. type: Unknown - contextPath: IAM.Vendor.active description: Gives the active status of user. Can be true or false. type: Boolean - contextPath: IAM.Vendor.brand description: The integration name. type: String - contextPath: IAM.Vendor.details description: Tells the user if the API was successful, otherwise provides error information. type: Unknown - contextPath: IAM.Vendor.email description: The employee email address. type: String - contextPath: IAM.Vendor.errorCode description: The HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: The reason the API failed. type: String - contextPath: IAM.Vendor.id description: The employee user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: The integration instance name. type: Unknown - contextPath: IAM.Vendor.success description: If true, the command executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee username in the app. type: String - contextPath: IAM.Vendor.action description: The command name. type: String compliantpolicies: - User Hard Remediation - arguments: - name: user-profile required: true description: "A User Profile indicator that contains user information, such as name and email address." description: Disables a user. execution: true name: iam-disable-user outputs: - contextPath: IAM.UserProfile description: The user profile. type: Unknown - contextPath: IAM.Vendor.active description: Gives the active status of user. Can be true or false. type: Boolean - contextPath: IAM.Vendor.brand description: The integration name. type: String - contextPath: IAM.Vendor.details description: Tells the user if the API was successful, otherwise provides error information. type: Unknown - contextPath: IAM.Vendor.email description: The employee email address. type: String - contextPath: IAM.Vendor.errorCode description: The HTTP error response code. type: Number - contextPath: IAM.Vendor.errorMessage description: The reason the API failed. type: String - contextPath: IAM.Vendor.id description: The employee user ID in the app. type: String - contextPath: IAM.Vendor.instanceName description: The integration instance name. type: Unknown - contextPath: IAM.Vendor.success description: If true, the command was executed successfully. type: Boolean - contextPath: IAM.Vendor.username description: The employee username in the app. type: String - contextPath: IAM.Vendor.action description: The command name. type: String compliantpolicies: - User Hard Remediation - description: Retrieves a User Profile schema which holds all of the user fields in the application. Used for outgoing mapping through the Get Schema option. name: get-mapping-fields arguments: [] - arguments: - description: The group name of the group to update (sAMAccountName). name: groupname - description: The name of the attribute to modify. For example, Description and displayName. name: attributename required: true - description: The value of the attribute to change. When attribute-type is "byte", provide a comma-separated list of decimal integers (0-255). name: attributevalue required: true - description: The type of the attribute value. Set to "byte" for binary/Octet String attributes. When set, attributevalue must be a comma-separated list of decimal integers (0-255). name: attribute-type auto: PREDEFINED predefined: - byte - description: Root. For example, DC=domain,DC=com. By default, the Base DN configured for the instance is used. name: basedn description: Updates attributes of an existing Active Directory group. name: ad-update-group - name: ad-modify-password-never-expire arguments: - name: username required: true description: The sAMAccountName of the user to modify. - name: value required: true auto: PREDEFINED predefined: - 'true' - 'false' description: Value to set "Password Never Expire". description: 'Modifies the AD account attribute "Password Never Expire".' execution: true compliantpolicies: - User Soft Remediation - arguments: - description: Username to test. By itself or formatted like SERVER_IP\\USERNAME. name: username required: true - description: Password to test. name: password required: true description: Test given credentials. name: ad-test-credentials outputs: - contextPath: ActiveDirectory.ValidCredentials description: List of usernames that successfully logged in. dockerimage: demisto/ldap:2.9.1.9062583 ismappable: true isremotesyncout: true runonce: false supportsquickactions: true fromversion: 5.0.0 tests: - Active Directory Test