MicrosoftWindows Deprecated
Agentless Windows host management over WinRM. Deprecated. Use Ansible Microsoft Windows (from the Ansible Microsoft Windows pack) instead.
IT Services · Ansible Powered Integrations (Deprecated)
Details
| ID | MicrosoftWindows |
|---|---|
| Provider | Microsoft |
| Category | IT Services |
| From Version | 6.0.0 |
| Docker Image | demisto/ansible-runner:1.0.0.3456168 |
| Supported Modules | Agentix |
Configuration parameters
creds— Username (required)port— Default WinRM Port (required)concurrency— Concurrecy Factor (required)
Commands (104)
-
win-aclSet file/directory/registry permissions for a system user or group.
-
win-acl-inheritanceChange ACL inheritance.
-
win-audit-policy-systemUsed to make changes to the system wide Audit Policy.
-
win-audit-ruleAdds an audit rule to files, folders, or registry keys.
-
win-certificate-storeManages the certificate store.
-
win-chocolateyManage packages using chocolatey.
-
win-chocolatey-configManages Chocolatey config settings.
-
win-chocolatey-factsCreate a facts collection for Chocolatey.
-
win-chocolatey-featureManages Chocolatey features.
-
win-chocolatey-sourceManages Chocolatey sources.
-
win-copyCopies files to remote locations on windows hosts.
-
win-credentialManages Windows Credentials in the Credential Manager.
-
win-defragConsolidate fragmented files on local volumes.
-
win-disk-factsShow the attached disks and disk information of the target host.
-
win-disk-imageManage ISO/VHD/VHDX mounts on Windows hosts.
-
win-dns-clientConfigures DNS lookup on Windows hosts.
-
win-dns-recordManage Windows Server DNS records.
-
win-domainEnsures the existence of a Windows domain.
-
win-domain-computerManage computers in Active Directory.
-
win-domain-controllerManage domain controller/member server state for a Windows host.
-
win-domain-groupCreates, modifies or removes domain groups.
-
win-domain-group-membershipManage Windows domain group membership.
-
win-domain-membershipManage domain/workgroup membership for a Windows host.
-
win-domain-userManages Windows Active Directory user accounts.
-
win-dotnet-ngenRuns ngen to recompile DLLs after .NET updates.
-
win-dscInvokes a PowerShell DSC configuration.
-
win-environmentModify environment variables on windows hosts.
-
win-eventlogManage Windows event logs.
-
win-eventlog-entryWrite entries to Windows event logs.
-
win-featureInstalls and uninstalls Windows Features on Windows Server.
-
win-fileCreates, touches or removes files or directories.
-
win-file-versionGet DLL or EXE file build version.
-
win-findReturn a list of files based on specific criteria.
-
win-firewallEnable or disable the Windows Firewall.
-
win-firewall-ruleWindows firewall automation.
-
win-formatFormats an existing volume or a new volume on an existing partition on Windows.
-
win-gather-factsGathers facts about remote hosts.
-
win-get-urlDownloads file from HTTP, HTTPS, or FTP to node.
-
win-groupAdd and remove local groups.
-
win-group-membershipManage Windows local group membership.
-
win-hostnameManages local Windows computer name.
-
win-hostsManages hosts file entries on Windows.
-
win-hotfixInstall and uninstalls Windows hotfixes.
-
win-http-proxyManages proxy settings for WinHTTP.
-
win-iis-virtualdirectoryConfigures a virtual directory in IIS.
-
win-iis-webapplicationConfigures IIS web applications.
-
win-iis-webapppoolConfigure IIS Web Application Pools.
-
win-iis-webbindingConfigures a IIS Web site binding.
-
win-iis-websiteConfigures a IIS Web site.
-
win-inet-proxyManages proxy settings for WinINet and Internet Explorer.
-
win-lineinfileEnsure a particular line is in a file, or replace an existing line using a back-referenced regular expression.
-
win-mapped-driveMap network drives for users.
-
win-msgSends a message to logged in users on Windows hosts.
-
win-netbiosManage NetBIOS over TCP/IP settings on Windows.
-
win-nssmInstall a service using NSSM.
-
win-optional-featureManage optional Windows features.
-
win-ownerSet owner.
-
win-packageInstalls/uninstalls an installable package.
-
win-pagefileQuery or change pagefile configuration.
-
win-partitionCreates, changes and removes partitions on Windows Server.
-
win-pathManage Windows path environment variables.
-
win-pesterRun Pester tests on Windows hosts.
-
win-pingA windows version of the classic ping module.
-
win-power-planChanges the power plan of a Windows system.
-
win-product-factsProvides Windows product and license information.
-
win-psexecRuns commands (remotely) as another (privileged) user.
-
win-psmoduleAdds or removes a Windows PowerShell module.
-
win-psrepositoryAdds, removes or updates a Windows PowerShell repository.
-
win-rabbitmq-pluginManage RabbitMQ plugins.
-
win-rds-capManage Connection Authorization Policies (CAP) on a Remote Desktop Gateway server.
-
win-rds-rapManage Resource Authorization Policies (RAP) on a Remote Desktop Gateway server.
-
win-rds-settingsManage main settings of a Remote Desktop Gateway server.
-
win-rebootReboot a windows machine.
-
win-reg-statGet information about Windows registry keys.
-
win-regeditAdd, change, or remove registry keys and values.
-
win-regionSet the region and format settings.
-
win-regmergeMerges the contents of a registry file into the Windows registry.
-
win-robocopySynchronizes the contents of two directories using Robocopy.
-
win-routeAdd or remove a static route.
-
win-sayText to speech module for Windows to speak messages and optionally play sounds.
-
win-scheduled-taskManage scheduled tasks.
-
win-scheduled-task-statGet information about Windows Scheduled Tasks.
-
win-security-policyChange local security policy settings.
-
win-serviceManage and query Windows services.
-
win-shareManage Windows shares.
-
win-shortcutManage shortcuts on Windows.
-
win-snmpConfigures the Windows SNMP service.
-
win-statGet information about Windows files.
-
win-tempfileCreates temporary files and directories.
-
win-templateTemplate a file out to a remote server.
-
win-timezoneSets Windows machine timezone.
-
win-toastSends Toast windows notification to logged in users on Windows 10 or later hosts.
-
win-unzipUnzips compressed files and archives on the Windows node.
-
win-updatesDownload and install Windows updates.
-
win-uriInteracts with webservices.
-
win-userManages local Windows user accounts.
-
win-user-profileManages the Windows user profiles.
-
win-user-rightManage Windows User Rights.
-
win-wait-forWaits for a condition before continuing.
-
win-wait-for-processWaits for a process to exist or not exist before continuing.
-
win-wakeonlanSend a magic Wake-on-LAN (WoL) broadcast packet.
-
win-webpicmdInstalls packages using Web Platform Installer command-line.
-
win-whoamiGet information about the current user and process.
-
win-xmlManages XML file content on Windows hosts.
category: IT Services provider: Microsoft commonfields: id: MicrosoftWindows version: -1 configuration: - additionalinfo: The credentials to associate with the instance. display: Username name: creds required: true type: 9 - additionalinfo: The default port to use if one is not specified in the commands `host` argument. If 5985 is specified the HTTP transport method will be used. Otherwise HTTPS will be used for all other ports defaultvalue: "5985" display: Default WinRM Port name: port required: true type: 0 - additionalinfo: If multiple hosts are specified in a command, how many hosts should be interacted with concurrently. defaultvalue: "4" display: Concurrecy Factor name: concurrency required: true type: 0 description: Agentless Windows host management over WinRM. Deprecated. Use Ansible Microsoft Windows (from the Ansible Microsoft Windows pack) instead. display: Ansible Microsoft Windows (Deprecated) name: MicrosoftWindows script: commands: - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- A toggle that controls if the fact modules are executed in parallel or serially and in order. This can guarantee the merge order of module facts at the expense of performance. By default it will be true if more than one fact module is used. name: parallel description: Gathers facts about remote hosts. name: win-gather-facts - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The path to the file or directory. name: path required: true - description: User or Group to add specified rights to act on src file/folder or registry key. name: user required: true - auto: PREDEFINED defaultValue: present description: Specify whether to add `present` or remove `absent` the specified access rule. name: state predefined: - absent - present - auto: PREDEFINED description: Specify whether to allow or deny the rights specified. name: type predefined: - allow - deny required: true - description: |- The rights/permissions that are to be allowed/denied for the specified user or group for the item at `path`. If `path` is a file or directory, rights can be any right under MSDN FileSystemRights `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.filesystemrights.aspx`. If `path` is a registry key, rights can be any right under MSDN RegistryRights `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.registryrights.aspx`. name: rights required: true - auto: PREDEFINED description: |- Inherit flags on the ACL rules. Can be specified as a comma separated list, e.g. `ContainerInherit`, `ObjectInherit`. For more information on the choices see MSDN InheritanceFlags enumeration at `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.inheritanceflags.aspx`. Defaults to `ContainerInherit, ObjectInherit` for Directories. name: inherit predefined: - ContainerInherit - ObjectInherit - auto: PREDEFINED defaultValue: None description: |- Propagation flag on the ACL rules. For more information on the choices see MSDN PropagationFlags enumeration at `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.propagationflags.aspx`. name: propagation predefined: - InheritOnly - None - NoPropagateInherit description: Set file/directory/registry permissions for a system user or group. name: win-acl - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Path to be used for changing inheritance. name: path required: true - auto: PREDEFINED defaultValue: absent description: Specify whether to enable `present` or disable `absent` ACL inheritance. name: state predefined: - absent - present - defaultValue: "False" description: |- For P(state) = `absent`, indicates if the inherited ACE's should be copied from the parent directory. This is necessary (in combination with removal) for a simple ACL instead of using multiple ACE deny entries. For P(state) = `present`, indicates if the inherited ACE's should be deduplicated compared to the parent directory. This removes complexity of the ACL structure. name: reorganize description: Change ACL inheritance. name: win-acl-inheritance - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Single string value for the category you would like to adjust the policy on. Cannot be used with `subcategory`. You must define one or the other. Changing this setting causes all subcategories to be adjusted to the defined `audit_type`. name: category - description: |- Single string value for the subcategory you would like to adjust the policy on. Cannot be used with `category`. You must define one or the other. name: subcategory - auto: PREDEFINED description: |- The type of event you would like to audit for. Accepts a list. See examples. isArray: true name: audit_type predefined: - failure - none - success required: true description: Used to make changes to the system wide Audit Policy. name: win-audit-policy-system - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Path to the file, folder, or registry key. Registry paths should be in Powershell format, beginning with an abbreviation for the root such as, `HKLM:\Software`. name: path required: true - description: The user or group to adjust rules for. name: user required: true - description: |- Comma separated list of the rights desired. Only required for adding a rule. If `path` is a file or directory, rights can be any right under MSDN FileSystemRights `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.filesystemrights.aspx`. If `path` is a registry key, rights can be any right under MSDN RegistryRights `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.registryrights.aspx`. isArray: true name: rights required: true - auto: PREDEFINED defaultValue: ContainerInherit,ObjectInherit description: |- Defines what objects inside of a folder or registry key will inherit the settings. If you are setting a rule on a file, this value has to be changed to `none`. For more information on the choices see MSDN PropagationFlags enumeration at `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.inheritanceflags.aspx`. isArray: true name: inheritance_flags predefined: - ContainerInherit - ObjectInherit - auto: PREDEFINED defaultValue: None description: |- Propagation flag on the audit rules. This value is ignored when the path type is a file. For more information on the choices see MSDN PropagationFlags enumeration at `https://msdn.microsoft.com/en-us/library/system.security.accesscontrol.propagationflags.aspx`. name: propagation_flags predefined: - None - InherityOnly - NoPropagateInherit - auto: PREDEFINED description: |- Defines whether to log on failure, success, or both. To log both define as comma separated list "Success, Failure". isArray: true name: audit_flags predefined: - Failure - Success required: true - auto: PREDEFINED defaultValue: present description: |- Whether the rule should be `present` or `absent`. For absent, only `path`, `user`, and `state` are required. Specifying `absent` will remove all rules matching the defined `user`. name: state predefined: - absent - present description: Adds an audit rule to files, folders, or registry keys. name: win-audit-rule - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - auto: PREDEFINED defaultValue: present description: |- If `present`, will ensure that the certificate at `path` is imported into the certificate store specified. If `absent`, will ensure that the certificate specified by `thumbprint` or the thumbprint of the cert at `path` is removed from the store specified. If `exported`, will ensure the file at `path` is a certificate specified by `thumbprint`. When exporting a certificate, if `path` is a directory then the module will fail, otherwise the file will be replaced if needed. name: state predefined: - absent - exported - present - description: |- The path to a certificate file. This is required when `state` is `present` or `exported`. When `state` is `absent` and `thumbprint` is not specified, the thumbprint is derived from the certificate at this path. name: path - description: |- The thumbprint as a hex string to either export or remove. See the examples for how to specify the thumbprint. name: thumbprint - auto: PREDEFINED defaultValue: My description: |- The store name to use when importing a certificate or searching for a certificate. `AddressBook`: The X.509 certificate store for other users `AuthRoot`: The X.509 certificate store for third-party certificate authorities (CAs) `CertificateAuthority`: The X.509 certificate store for intermediate certificate authorities (CAs) `Disallowed`: The X.509 certificate store for revoked certificates `My`: The X.509 certificate store for personal certificates `Root`: The X.509 certificate store for trusted root certificate authorities (CAs) `TrustedPeople`: The X.509 certificate store for directly trusted people and resources `TrustedPublisher`: The X.509 certificate store for directly trusted publishers. name: store_name predefined: - AddressBook - AuthRoot - CertificateAuthority - Disallowed - My - Root - TrustedPeople - TrustedPublisher - auto: PREDEFINED defaultValue: LocalMachine description: The store location to use when importing a certificate or searching for a certificate. name: store_location predefined: - CurrentUser - LocalMachine - description: |- The password of the pkcs12 certificate key. This is used when reading a pkcs12 certificate file or the password to set when `state=exported` and `file_type=pkcs12`. If the pkcs12 file has no password set or no password should be set on the exported file, do not set this option. name: password - defaultValue: "True" description: |- Whether to allow the private key to be exported. If `no`, then this module and other process will only be able to export the certificate and the private key cannot be exported. Used when `state=present` only. name: key_exportable - auto: PREDEFINED defaultValue: default description: |- Specifies where Windows will store the private key when it is imported. When set to `default`, the default option as set by Windows is used, typically `user`. When set to `machine`, the key is stored in a path accessible by various users. When set to `user`, the key is stored in a path only accessible by the current user. Used when `state=present` only and cannot be changed once imported. See `https://msdn.microsoft.com/en-us/library/system.security.cryptography.x509certificates.x509keystorageflags.aspx` for more details. name: key_storage predefined: - default - machine - user - auto: PREDEFINED defaultValue: der description: |- The file type to export the certificate as when `state=exported`. `der` is a binary ASN.1 encoded file. `pem` is a base64 encoded file of a der file in the OpenSSL form. `pkcs12` (also known as pfx) is a binary container that contains both the certificate and private key unlike the other options. When `pkcs12` is set and the private key is not exportable or accessible by the current user, it will throw an exception. name: file_type predefined: - der - pem - pkcs12 description: Manages the certificate store. name: win-certificate-store - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: "False" description: |- Allow empty checksums to be used for downloaded resource from non-secure locations. Use `win_chocolatey_feature` with the name `allowEmptyChecksums` to control this option globally. name: allow_empty_checksums - defaultValue: "False" description: |- Allow the installation of multiple packages when `version` is specified. Having multiple packages at different versions can cause issues if the package doesn't support this. Use at your own risk. name: allow_multiple - defaultValue: "False" description: |- Allow the installation of pre-release packages. If `state` is `latest`, the latest pre-release package will be installed. name: allow_prerelease - auto: PREDEFINED defaultValue: default description: |- Force Chocolatey to install the package of a specific process architecture. When setting `x86`, will ensure Chocolatey installs the x86 package even when on an x64 bit OS. name: architecture predefined: - default - x86 - defaultValue: "False" description: |- Forces the install of a package, even if it already is installed. Using `force` will cause Ansible to always report that a change was made. name: force - description: |- Arguments to pass to the native installer. These are arguments that are passed directly to the installer the Chocolatey package runs, this is generally an advanced option. name: install_args - defaultValue: "False" description: |- Ignore the checksums provided by the package. Use `win_chocolatey_feature` with the name `checksumFiles` to control this option globally. name: ignore_checksums - defaultValue: "False" description: Ignore dependencies, only install/upgrade the package itself. name: ignore_dependencies - description: |- Name of the package(s) to be installed. Set to `all` to run the action on all the installed packages. isArray: true name: name required: true - description: |- Parameters to pass to the package. These are parameters specific to the Chocolatey package and are generally documented by the package itself. Before Ansible 2.7, this option was just `params`. name: package_params - description: |- Whether to pin the Chocolatey package or not. If omitted then no checks on package pins are done. Will pin/unpin the specific version if `version` is set. Will pin the latest version of a package if `yes`, `version` is not set and and no pin already exists. Will unpin all versions of a package if `no` and `version` is not set. This is ignored when `state=absent`. name: pinned - description: |- Proxy URL used to install chocolatey and the package. Use `win-chocolatey-config` with the name `proxy` to control this option globally. name: proxy_url - description: |- Proxy username used to install Chocolatey and the package. Before Ansible 2.7, users with double quote characters `"` would need to be escaped with `\` beforehand. This is no longer necessary. Use `win-chocolatey-config` with the name `proxyUser` to control this option globally. name: proxy_username - description: |- Proxy password used to install Chocolatey and the package. This value is exposed as a command argument and any privileged account can see this value when the module is running Chocolatey, define the password on the global config level with `win-chocolatey-config` with name `proxyPassword` to avoid this. name: proxy_password - defaultValue: "False" description: Do not run `chocolateyInstall.ps1` or `chocolateyUninstall.ps1` scripts when installing a package. name: skip_scripts - description: |- Specify the source to retrieve the package from. Use `win_chocolatey_source` to manage global sources. This value can either be the URL to a Chocolatey feed, a path to a folder containing `.nupkg` packages or the name of a source defined by `win_chocolatey_source`. This value is also used when Chocolatey is not installed as the location of the install.ps1 script and only supports URLs for this case. name: source - description: |- A username to use with `source` when accessing a feed that requires authentication. It is recommended you define the credentials on a source with `win_chocolatey_source` instead of passing it per task. name: source_username - description: |- The password for `source_username`. This value is exposed as a command argument and any privileged account can see this value when the module is running Chocolatey, define the credentials with a source with `win_chocolatey_source` to avoid this. name: source_password - auto: PREDEFINED defaultValue: present description: |- State of the package on the system. When `absent`, will ensure the package is not installed. When `present`, will ensure the package is installed. When `downgrade`, will allow Chocolatey to downgrade a package if `version` is older than the installed version. When `latest`, will ensure the package is installed to the latest available version. When `reinstalled`, will uninstall and reinstall the package. name: state predefined: - absent - downgrade - latest - present - reinstalled - defaultValue: "2700" description: The time to allow chocolatey to finish before timing out. name: timeout - defaultValue: "True" description: |- Used when downloading the Chocolatey install script if Chocolatey is not already installed, this does not affect the Chocolatey package install process. When `no`, no SSL certificates will be validated. This should only be used on personally controlled sites using self-signed certificate. name: validate_certs - description: |- Specific version of the package to be installed. When `state` is set to `absent`, will uninstall the specific version otherwise all versions of that package will be removed. If a different version of package is installed, `state` must be `latest` or `force` set to `yes` to install the desired version. Provide as a string (e.g. `'6.1'`), otherwise it is considered to be a floating-point number and depending on the locale could become `6,1`, which will cause a failure. If `name` is set to `chocolatey` and Chocolatey is not installed on the host, this will be the version of Chocolatey that is installed. You can also set the `chocolateyVersion` environment var. name: version description: Manage packages using chocolatey. name: win-chocolatey - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The name of the config setting to manage. See `https://chocolatey.org/docs/chocolatey-configuration` for a list of valid configuration settings that can be changed. Any config values that contain encrypted values like a password are not idempotent as the plaintext value cannot be read. name: name required: true - auto: PREDEFINED defaultValue: present description: |- When `absent`, it will ensure the setting is unset or blank. When `present`, it will ensure the setting is set to the value of `value`. name: state predefined: - absent - present - description: |- Used when `state=present` that contains the value to set for the config setting. Cannot be null or an empty string, use `state=absent` to unset a config value instead. name: value description: Manages Chocolatey config settings. name: win-chocolatey-config - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true description: Create a facts collection for Chocolatey. name: win-chocolatey-facts outputs: - contextPath: MicrosoftWindows.ansible_facts.ansible_chocolatey description: Detailed information about the Chocolatey installation. - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The name of the feature to manage. Run `choco.exe feature list` to get a list of features that can be managed. name: name required: true - auto: PREDEFINED defaultValue: enabled description: |- When `disabled` then the feature will be disabled. When `enabled` then the feature will be enabled. name: state predefined: - disabled - enabled description: Manages Chocolatey features. name: win-chocolatey-feature - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Makes the source visible to Administrators only. Requires Chocolatey >= 0.10.8. When creating a new source, this defaults to `no`. name: admin_only - description: |- Allow the source to be used with self-service Requires Chocolatey >= 0.10.4. When creating a new source, this defaults to `no`. name: allow_self_service - description: |- Bypass the proxy when using this source. Requires Chocolatey >= 0.10.4. When creating a new source, this defaults to `no`. name: bypass_proxy - description: |- The path to a .pfx file to use for X509 authenticated feeds. Requires Chocolatey >= 0.9.10. name: certificate - description: |- The password for `certificate` if required. Requires Chocolatey >= 0.9.10. name: certificate_password - description: The name of the source to configure. name: name required: true - description: |- The priority order of this source compared to other sources, lower is better. All priorities above `0` will be evaluated first, then zero-based values will be evaluated in config file order. Requires Chocolatey >= 0.9.9.9. When creating a new source, this defaults to `0`. name: priority - description: |- The file/folder/url of the source. Required when `state` is `present` or `disabled` and the source does not already exist. name: source - description: The username used to access `source`. name: source_username - description: |- The password for `source_username`. Required if `source_username` is set. name: source_password - auto: PREDEFINED defaultValue: present description: |- When `absent`, will remove the source. When `disabled`, will ensure the source exists but is disabled. When `present`, will ensure the source exists and is enabled. name: state predefined: - absent - disabled - present - auto: PREDEFINED defaultValue: always description: |- When `always`, the module will always set the password and report a change if `certificate_password` or `source_password` is set. When `on_create`, the module will only set the password if the source is being created. name: update_password predefined: - always - on_create description: Manages Chocolatey sources. name: win-chocolatey-source - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- When used instead of `src`, sets the contents of a file directly to the specified value. This is for simple values, for anything complex or with formatting please switch to the `template` module. name: content - defaultValue: "True" description: This option controls the autodecryption of source files using vault. name: decrypt - description: |- Remote absolute path where the file should be copied to. If `src` is a directory, this must be a directory too. Use \ for path separators or \\ when in "double quotes". If `dest` ends with \ then source or the contents of source will be copied to the directory without renaming. If `dest` is a nonexistent path, it will only be created if `dest` ends with "/" or "\", or `src` is a directory. If `src` and `dest` are files and if the parent directory of `dest` doesn't exist, then the task will fail. name: dest required: true - defaultValue: "False" description: |- Determine whether a backup should be created. When set to `yes`, create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly. No backup is taken when `remote_src=False` and multiple files are being copied. name: backup - defaultValue: "True" description: |- If set to `yes`, the file will only be transferred if the content is different than destination. If set to `no`, the file will only be transferred if the destination does not exist. If set to `no`, no checksuming of the content is performed which can help improve performance on larger files. name: force - defaultValue: "True" description: This flag indicates that filesystem links in the source tree, if they exist, should be followed. name: local_follow - defaultValue: "False" description: |- If `no`, it will search for src at originating/master machine. If `yes`, it will go to the remote/target machine for the src. name: remote_src - description: |- Local path to a file to copy to the remote server; can be absolute or relative. If path is a directory, it is copied (including the source folder name) recursively to `dest`. If path is a directory and ends with "/", only the inside contents of that directory are copied to the destination. Otherwise, if it does not end with "/", the directory itself with all contents is copied. If path is a file and dest ends with "\", the file is copied to the folder with the same filename. Required unless using `content`. name: src description: Copies files to remote locations on windows hosts. name: win-copy - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Adds an alias for the credential. Typically this is the NetBIOS name of a host if `name` is set to the DNS name. name: alias - description: |- A list of dicts that set application specific attributes for a credential. When set, existing attributes will be compared to the list as a whole, any differences means all attributes will be replaced. name: attributes - description: A user defined comment for the credential. name: comment - description: |- The target that identifies the server or servers that the credential is to be used for. If the value can be a NetBIOS name, DNS server name, DNS host name suffix with a wildcard character (`*`), a NetBIOS of DNS domain name that contains a wildcard character sequence, or an asterisk. See `TargetName` in `https://docs.microsoft.com/en-us/windows/desktop/api/wincred/ns-wincred-_credentiala` for more details on what this value can be. This is used with `type` to produce a unique credential. name: name required: true - auto: PREDEFINED defaultValue: local description: |- Defines the persistence of the credential. If `local`, the credential will persist for all logons of the same user on the same host. `enterprise` is the same as `local` but the credential is visible to the same domain user when running on other hosts and not just localhost. name: persistence predefined: - enterprise - local - description: |- The secret for the credential. When omitted, then no secret is used for the credential if a new credentials is created. When `type` is a password type, this is the password for `username`. When `type` is a certificate type, this is the pin for the certificate. name: secret - auto: PREDEFINED defaultValue: text description: |- Controls the input type for `secret`. If `text`, `secret` is a text string that is UTF-16LE encoded to bytes. If `base64`, `secret` is a base64 string that is base64 decoded to bytes. name: secret_format predefined: - base64 - text - auto: PREDEFINED defaultValue: present description: |- When `absent`, the credential specified by `name` and `type` is removed. When `present`, the credential specified by `name` and `type` is removed. name: state predefined: - absent - present - auto: PREDEFINED description: |- The type of credential to store. This is used with `name` to produce a unique credential. When the type is a `domain` type, the credential is used by Microsoft authentication packages like Negotiate. When the type is a `generic` type, the credential is not used by any particular authentication package. It is recommended to use a `domain` type as only authentication providers can access the secret. name: type predefined: - domain_certificate - domain_password - generic_certificate - generic_password required: true - auto: PREDEFINED defaultValue: always description: |- When `always`, the secret will always be updated if they differ. When `on_create`, the secret will only be checked/updated when it is first created. If the secret cannot be retrieved and this is set to `always`, the module will always result in a change. name: update_secret predefined: - always - on_create - description: |- When `type` is a password type, then this is the username to store for the credential. When `type` is a credential type, then this is the thumbprint as a hex string of the certificate to use. When `type=domain_password`, this should be in the form of a Netlogon (DOMAIN\Username) or a UPN (username@DOMAIN). If using a certificate thumbprint, the certificate must exist in the `CurrentUser\My` certificate store for the executing user. name: username description: Manages Windows Credentials in the Credential Manager. name: win-credential - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- A list of drive letters or mount point paths of the volumes to be defragmented. If this parameter is omitted, all volumes (not excluded) will be fragmented. isArray: true name: include_volumes - description: A list of drive letters or mount point paths to exclude from defragmentation. isArray: true name: exclude_volumes - defaultValue: "False" description: Perform free space consolidation on the specified volumes. name: freespace_consolidation - auto: PREDEFINED defaultValue: low description: Run the operation at low or normal priority. name: priority predefined: - low - normal - defaultValue: "False" description: Run the operation on each volume in parallel in the background. name: parallel description: Consolidate fragmented files on local volumes. name: win-defrag - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true description: Show the attached disks and disk information of the target host. name: win-disk-facts outputs: - contextPath: MicrosoftWindows.ansible_facts.ansible_disks description: Detailed information about one particular disk. - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Path to an ISO, VHD, or VHDX image on the target Windows host (the file cannot reside on a network share). name: image_path required: true - auto: PREDEFINED defaultValue: present description: Whether the image should be present as a drive-letter mount or not. name: state predefined: - absent - present description: Manage ISO/VHD/VHDX mounts on Windows hosts. name: win-disk-image - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Adapter name or list of adapter names for which to manage DNS settings ('*' is supported as a wildcard value). The adapter name used is the connection caption in the Network Control Panel or via `Get-NetAdapter`, eg `Local Area Connection`. name: adapter_names required: true - description: Single or ordered list of DNS server IPv4 addresses to configure for lookup. An empty list will configure the adapter to use the DHCP-assigned values on connections where DHCP is enabled, or disable DNS lookup on statically-configured connections. name: ipv4_addresses required: true description: Configures DNS lookup on Windows hosts. name: win-dns-client - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The name of the record. name: name required: true - auto: PREDEFINED defaultValue: present description: Whether the record should exist or not. name: state predefined: - absent - present - defaultValue: "3600" description: |- The "time to live" of the record, in seconds. Ignored when `state=absent`. Valid range is 1 - 31557600. Note that an Active Directory forest can specify a minimum TTL, and will dynamically "round up" other values to that minimum. name: ttl - auto: PREDEFINED description: The type of DNS record to manage. name: type predefined: - A - AAAA - CNAME - PTR required: true - description: |- The value(s) to specify. Required when `state=present`. When c(type=PTR) only the partial part of the IP should be given. isArray: true name: value - description: |- The name of the zone to manage (eg `example.com`). The zone must already exist. name: zone required: true - description: |- Specifies a DNS server. You can specify an IP address or any value that resolves to an IP address, such as a fully qualified domain name (FQDN), host name, or NETBIOS name. name: computer_name description: Manage Windows Server DNS records. name: win-dns-record - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The DNS name of the domain which should exist and be reachable or reside on the target Windows host. name: dns_domain_name required: true - description: |- The NetBIOS name for the root domain in the new forest. For NetBIOS names to be valid for use with this parameter they must be single label names of 15 characters or less, if not it will fail. If this parameter is not set, then the default is automatically computed from the value of the `domain_name` parameter. name: domain_netbios_name - description: Safe mode password for the domain controller. name: safe_mode_password required: true - description: |- The path to a directory on a fixed disk of the Windows host where the domain database will be created. If not set then the default path is `%SYSTEMROOT%\NTDS`. name: database_path - description: |- The path to a directory on a fixed disk of the Windows host where the Sysvol file will be created. If not set then the default path is `%SYSTEMROOT%\SYSVOL`. name: sysvol_path - description: |- Whether to create a DNS delegation that references the new DNS server that you install along with the domain controller. Valid for Active Directory-integrated DNS only. The default is computed automatically based on the environment. name: create_dns_delegation - auto: PREDEFINED description: |- Specifies the domain functional level of the first domain in the creation of a new forest. The domain functional level cannot be lower than the forest functional level, but it can be higher. The default is automatically computed and set. name: domain_mode predefined: - Win2003 - Win2008 - Win2008R2 - Win2012 - Win2012R2 - WinThreshold - auto: PREDEFINED description: |- Specifies the forest functional level for the new forest. The default forest functional level in Windows Server is typically the same as the version you are running. name: forest_mode predefined: - Win2003 - Win2008 - Win2008R2 - Win2012 - Win2012R2 - WinThreshold description: Ensures the existence of a Windows domain. name: win-domain - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Specifies the name of the object. This parameter sets the Name property of the Active Directory object. The LDAP display name (ldapDisplayName) of this property is name. name: name required: true - description: |- Specifies the Security Account Manager (SAM) account name of the computer. It maximum is 256 characters, 15 is advised for older operating systems compatibility. The LDAP display name (ldapDisplayName) for this property is sAMAccountName. If ommitted the value is the same as `name`. Note that all computer SAMAccountNames need to end with a $. name: sam_account_name - defaultValue: "True" description: |- Specifies if an account is enabled. An enabled account requires a password. This parameter sets the Enabled property for an account object. This parameter also sets the ADS_UF_ACCOUNTDISABLE flag of the Active Directory User Account Control (UAC) attribute. name: enabled - description: Specifies the X.500 path of the Organizational Unit (OU) or container where the new object is created. Required when `state=present`. name: ou - description: |- Specifies a description of the object. This parameter sets the value of the Description property for the object. The LDAP display name (ldapDisplayName) for this property is description. name: description - description: |- Specifies the fully qualified domain name (FQDN) of the computer. This parameter sets the DNSHostName property for a computer object. The LDAP display name for this property is dNSHostName. Required when `state=present`. name: dns_hostname - description: |- The username to use when interacting with AD. If this is not set then the user Ansible used to log in with will be used instead when using CredSSP or Kerberos with credential delegation. name: domain_username - description: The password for `username`. name: domain_password - description: |- Specifies the Active Directory Domain Services instance to connect to. Can be in the form of an FQDN or NetBIOS name. If not specified then the value is based on the domain of the computer running PowerShell. name: domain_server - auto: PREDEFINED defaultValue: present description: Specified whether the computer should be `present` or `absent` in Active Directory. name: state predefined: - absent - present description: Manage computers in Active Directory. name: win-domain-computer - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: When `state` is `domain_controller`, the DNS name of the domain for which the targeted Windows host should be a DC. name: dns_domain_name - description: Username of a domain admin for the target domain (necessary to promote or demote a domain controller). name: domain_admin_user required: true - description: Password for the specified `domain_admin_user`. name: domain_admin_password required: true - description: Safe mode password for the domain controller (required when `state` is `domain_controller`). name: safe_mode_password - description: Password to be assigned to the local `Administrator` user (required when `state` is `member_server`). name: local_admin_password - defaultValue: "False" description: Whether to install the domain controller as a read only replica for an existing domain. name: read_only - description: |- Specifies the name of an existing site where you can place the new domain controller. This option is required when `read_only` is `yes`. name: site_name - auto: PREDEFINED description: Whether the target host should be a domain controller or a member server. name: state predefined: - domain_controller - member_server - description: |- The path to a directory on a fixed disk of the Windows host where the domain database will be created.. If not set then the default path is `%SYSTEMROOT%\NTDS`. name: database_path - description: |- The path to a directory on a fixed disk of the Windows host where the Sysvol folder will be created. If not set then the default path is `%SYSTEMROOT%\SYSVOL`. name: sysvol_path description: Manage domain controller/member server state for a Windows host. name: win-domain-controller - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- A dict of custom LDAP attributes to set on the group. This can be used to set custom attributes that are not exposed as module parameters, e.g. `mail`. See the examples on how to format this parameter. isArray: true name: attributes - auto: PREDEFINED description: |- The category of the group, this is the value to assign to the LDAP `groupType` attribute. If a new group is created then `security` will be used by default. name: category predefined: - distribution - security - description: The value to be assigned to the LDAP `description` attribute. name: description - description: The value to assign to the LDAP `displayName` attribute. name: display_name - description: |- The username to use when interacting with AD. If this is not set then the user Ansible used to log in with will be used instead. name: domain_username - description: The password for `username`. name: domain_password - description: |- Specifies the Active Directory Domain Services instance to connect to. Can be in the form of an FQDN or NetBIOS name. If not specified then the value is based on the domain of the computer running PowerShell. name: domain_server - defaultValue: "False" description: |- Will ignore the `ProtectedFromAccidentalDeletion` flag when deleting or moving a group. The module will fail if one of these actions need to occur and this value is set to `no`. name: ignore_protection - description: |- The value to be assigned to the LDAP `managedBy` attribute. This value can be in the forms `Distinguished Name`, `objectGUID`, `objectSid` or `sAMAccountName`, see examples for more details. name: managed_by - description: |- The name of the group to create, modify or remove. This value can be in the forms `Distinguished Name`, `objectGUID`, `objectSid` or `sAMAccountName`, see examples for more details. name: name required: true - description: |- The full LDAP path to create or move the group to. This should be the path to the parent object to create or move the group to. See examples for details of how this path is formed. name: organizational_unit - description: |- Will set the `ProtectedFromAccidentalDeletion` flag based on this value. This flag stops a user from deleting or moving a group to a different path. name: protect - auto: PREDEFINED description: |- The scope of the group. If `state=present` and the group doesn't exist then this must be set. name: scope predefined: - domainlocal - global - universal - auto: PREDEFINED defaultValue: present description: |- If `state=present` this module will ensure the group is created and is configured accordingly. If `state=absent` this module will delete the group if it exists. name: state predefined: - absent - present description: Creates, modifies or removes domain groups. name: win-domain-group - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the domain group to manage membership on. name: name required: true - description: |- A list of members to ensure are present/absent from the group. The given names must be a SamAccountName of a user, group, service account, or computer. For computers, you must add "$" after the name; for example, to add "Mycomputer" to a group, use "Mycomputer$" as the member. isArray: true name: members required: true - auto: PREDEFINED defaultValue: present description: |- Desired state of the members in the group. When `state` is `pure`, only the members specified will exist, and all other existing members not specified are removed. name: state predefined: - absent - present - pure - description: |- The username to use when interacting with AD. If this is not set then the user Ansible used to log in with will be used instead when using CredSSP or Kerberos with credential delegation. name: domain_username - description: The password for `username`. name: domain_password - description: |- Specifies the Active Directory Domain Services instance to connect to. Can be in the form of an FQDN or NetBIOS name. If not specified then the value is based on the domain of the computer running PowerShell. name: domain_server description: Manage Windows domain group membership. name: win-domain-group-membership - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: When `state` is `domain`, the DNS name of the domain to which the targeted Windows host should be joined. name: dns_domain_name - description: Username of a domain admin for the target domain (required to join or leave the domain). name: domain_admin_user required: true - description: Password for the specified `domain_admin_user`. name: domain_admin_password - description: The desired hostname for the Windows host. name: hostname - description: |- The desired OU path for adding the computer object. This is only used when adding the target host to a domain, if it is already a member then it is ignored. name: domain_ou_path - auto: PREDEFINED description: Whether the target host should be a member of a domain or workgroup. name: state predefined: - domain - workgroup - description: When `state` is `workgroup`, the name of the workgroup that the Windows host should be in. name: workgroup_name description: Manage domain/workgroup membership for a Windows host. name: win-domain-membership - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the user to create, remove or modify. name: name required: true - auto: PREDEFINED defaultValue: present description: |- When `present`, creates or updates the user account. When `absent`, removes the user account if it exists. When `query`, retrieves the user account details without making any changes. name: state predefined: - absent - present - query - defaultValue: "True" description: |- `yes` will enable the user account. `no` will disable the account. name: enabled - auto: PREDEFINED description: |- `no` will unlock the user account if locked. Note that there is not a way to lock an account as an administrator. Accounts are locked due to user actions; as an admin, you may only unlock a locked account. If you wish to administratively disable an account, set `enabled` to `no`. name: account_locked predefined: - "False" - description: Description of the user. name: description - description: |- Adds or removes the user from this list of groups, depending on the value of `groups_action`. To remove all but the Principal Group, set `groups=<principal group name>` and `groups_action=replace`. Note that users cannot be removed from their principal group (for example, "Domain Users"). isArray: true name: groups - auto: PREDEFINED defaultValue: replace description: |- If `add`, the user is added to each group in `groups` where not already a member. If `remove`, the user is removed from each group in `groups`. If `replace`, the user is added as a member of each group in `groups` and removed from any other groups. name: groups_action predefined: - add - remove - replace - description: |- Optionally set the user's password to this (plain text) value. To enable an account - `enabled` - a password must already be configured on the account, or you must provide a password here. name: password - auto: PREDEFINED defaultValue: always description: |- `always` will always update passwords. `on_create` will only set the password for newly created users. `when_changed` will only set the password when changed (added in ansible 2.9). name: update_password predefined: - always - on_create - when_changed - description: |- `yes` will require the user to change their password at next login. `no` will clear the expired password flag. This is mutually exclusive with `password_never_expires`. name: password_expired - description: |- `yes` will set the password to never expire. `no` will allow the password to expire. This is mutually exclusive with `password_expired`. name: password_never_expires - description: |- `yes` will prevent the user from changing their password. `no` will allow the user to change their password. name: user_cannot_change_password - description: Configures the user's first name (given name). name: firstname - description: Configures the user's last name (surname). name: surname - description: Configures the user's company name. name: company - description: |- Configures the User Principal Name (UPN) for the account. This is not required, but is best practice to configure for modern versions of Active Directory. The format is `<username>@<domain>`. name: upn - description: |- Configures the user's email address. This is a record in AD and does not do anything to configure any email servers or systems. name: email - description: Configures the user's street address. name: street - description: Configures the user's city. name: city - description: Configures the user's state or province. name: state_province - description: Configures the user's postal code / zip code. name: postal_code - description: |- Configures the user's country code. Note that this is a two-character ISO 3166 code. name: country - description: |- Container or OU for the new user; if you do not specify this, the user will be placed in the default container for users in the domain. Setting the path is only available when a new user is created; if you specify a path on an existing user, the user's path will not be updated - you must delete (e.g., `state=absent`) the user and then re-add the user with the appropriate path. name: path - description: |- A dict of custom LDAP attributes to set on the user. This can be used to set custom attributes that are not exposed as module parameters, e.g. `telephoneNumber`. See the examples on how to format this parameter. name: attributes - description: |- The username to use when interacting with AD. If this is not set then the user Ansible used to log in with will be used instead when using CredSSP or Kerberos with credential delegation. name: domain_username - description: The password for `username`. name: domain_password - description: |- Specifies the Active Directory Domain Services instance to connect to. Can be in the form of an FQDN or NetBIOS name. If not specified then the value is based on the domain of the computer running PowerShell. name: domain_server description: Manages Windows Active Directory user accounts. name: win-domain-user - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true description: Runs ngen to recompile DLLs after .NET updates. name: win-dotnet-ngen - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The name of the DSC Resource to use. Must be accessible to PowerShell using any of the default paths. name: resource_name required: true - defaultValue: latest description: |- Can be used to configure the exact version of the DSC resource to be invoked. Useful if the target node has multiple versions installed of the module containing the DSC resource. If not specified, the module will follow standard PowerShell convention and use the highest version available. name: module_version - description: |- The `win-dsc` module takes in multiple free form options based on the DSC resource being invoked by `resource_name`. There is no option actually named `free_form` so see the examples. This module will try and convert the option to the correct type required by the DSC resource and throw a warning if it fails. If the type of the DSC resource option is a `CimInstance` or `CimInstance[]`, this means the value should be a dictionary or list of dictionaries based on the values required by that option. If the type of the DSC resource option is a `PSCredential` then there needs to be 2 options set in the Ansible task definition suffixed with `_username` and `_password`. If the type of the DSC resource option is an array, then a list should be provided but a comma separated string also work. Use a list where possible as no escaping is required and it works with more complex types list `CimInstance[]`. If the type of the DSC resource option is a `DateTime`, you should use a string in the form of an ISO 8901 string to ensure the exact date is used. Since Ansible 2.8, Ansible will now validate the input fields against the DSC resource definition automatically. Older versions will silently ignore invalid fields. name: free_form required: true description: Invokes a PowerShell DSC configuration. name: win-dsc - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - auto: PREDEFINED defaultValue: present description: |- Set to `present` to ensure environment variable is set. Set to `absent` to ensure it is removed. name: state predefined: - absent - present - description: The name of the environment variable. name: name required: true - description: |- The value to store in the environment variable. Must be set when `state=present` and cannot be an empty string. Can be omitted for `state=absent`. name: value - auto: PREDEFINED description: |- The level at which to set the environment variable. Use `machine` to set for all users. Use `user` to set for the current user that ansible is connected as. Use `process` to set for the current process. Probably not that useful. name: level predefined: - machine - process - user required: true description: Modify environment variables on windows hosts. name: win-environment - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the event log to manage. name: name required: true - auto: PREDEFINED defaultValue: present description: |- Desired state of the log and/or sources. When `sources` is populated, state is checked for sources. When `sources` is not populated, state is checked for the specified log itself. If `state` is `clear`, event log entries are cleared for the target log. name: state predefined: - absent - clear - present - description: |- A list of one or more sources to ensure are present/absent in the log. When `category_file`, `message_file` and/or `parameter_file` are specified, these values are applied across all sources. isArray: true name: sources - description: For one or more sources specified, the path to a custom category resource file. name: category_file - description: For one or more sources specified, the path to a custom event message resource file. name: message_file - description: For one or more sources specified, the path to a custom parameter resource file. name: parameter_file - description: |- The maximum size of the event log. Value must be between 64KB and 4GB, and divisible by 64KB. Size can be specified in KB, MB or GB (e.g. 128KB, 16MB, 2.5GB). name: maximum_size - auto: PREDEFINED description: |- The action for the log to take once it reaches its maximum size. For `DoNotOverwrite`, all existing entries are kept and new entries are not retained. For `OverwriteAsNeeded`, each new entry overwrites the oldest entry. For `OverwriteOlder`, new log entries overwrite those older than the `retention_days` value. name: overflow_action predefined: - DoNotOverwrite - OverwriteAsNeeded - OverwriteOlder - description: |- The minimum number of days event entries must remain in the log. This option is only used when `overflow_action` is `OverwriteOlder`. name: retention_days description: Manage Windows event logs. name: win-eventlog - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the event log to write an entry to. name: log required: true - description: Name of the log source to indicate where the entry is from. name: source required: true - description: |- The numeric event identifier for the entry. Value must be between 0 and 65535. name: event_id required: true - description: The message for the given log entry. name: message required: true - auto: PREDEFINED description: Indicates the entry being written to the log is of a specific type. name: entry_type predefined: - Error - FailureAudit - Information - SuccessAudit - Warning - description: A numeric task category associated with the category message file for the log source. name: category - description: |- Binary data associated with the log entry. Value must be a comma-separated array of 8-bit unsigned integers (0 to 255). name: raw_data description: Write entries to Windows event logs. name: win-eventlog-entry - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Names of roles or features to install as a single feature or a comma-separated list of features. To list all available features use the PowerShell command `Get-WindowsFeature`. isArray: true name: name required: true - auto: PREDEFINED defaultValue: present description: State of the features or roles on the system. name: state predefined: - absent - present - defaultValue: "False" description: Adds all subfeatures of the specified feature. name: include_sub_features - defaultValue: "False" description: |- Adds the corresponding management tools to the specified feature. Not supported in Windows 2008 R2 and will be ignored. name: include_management_tools - description: |- Specify a source to install the feature from. Not supported in Windows 2008 R2 and will be ignored. Can either be `{driveletter}:\sources\sxs` or `\\{IP}\share\sources\sxs`. name: source description: Installs and uninstalls Windows Features on Windows Server. name: win-feature outputs: - contextPath: MicrosoftWindows.feature_result.display_name description: Feature display name. type: string - contextPath: MicrosoftWindows.feature_result.id description: A list of KB article IDs that apply to the update. type: number - contextPath: MicrosoftWindows.feature_result.message description: Any messages returned from the feature subsystem that occurred during installation or removal of this feature. - contextPath: MicrosoftWindows.feature_result.reboot_required description: True when the target server requires a reboot as a result of installing or removing this feature. type: boolean - contextPath: MicrosoftWindows.feature_result.restart_needed description: DEPRECATED in Ansible 2.4 (refer to C(reboot_required) instead). True when the target server requires a reboot as a result of installing or removing this feature. type: boolean - contextPath: MicrosoftWindows.feature_result.skip_reason description: The reason a feature installation or removal was skipped. type: string - contextPath: MicrosoftWindows.feature_result.success description: If the feature installation or removal was successful. type: boolean - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Path to the file being managed. name: path required: true - auto: PREDEFINED description: |- If `directory`, all immediate subdirectories will be created if they do not exist. If `file`, the file will NOT be created if it does not exist, see the `copy` or `template` module if you want that behavior. If `absent`, directories will be recursively deleted, and files will be removed. If `touch`, an empty file will be created if the `path` does not exist, while an existing file or directory will receive updated file access and modification times (similar to the way `touch` works from the command line). name: state predefined: - absent - directory - file - touch description: Creates, touches or removes files or directories. name: win-file - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- File to get version. Always provide absolute path. name: path required: true description: Get DLL or EXE file build version. name: win-file-version - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Select files or folders whose age is equal to or greater than the specified time. Use a negative age to find files equal to or less than the specified time. You can choose seconds, minutes, hours, days or weeks by specifying the first letter of an of those words (e.g., "2s", "10d", 1w"). name: age - auto: PREDEFINED defaultValue: mtime description: |- Choose the file property against which we compare `age`. The default attribute we compare with is the last modification time. name: age_stamp predefined: - atime - ctime - mtime - auto: PREDEFINED defaultValue: sha1 description: |- Algorithm to determine the checksum of a file. Will throw an error if the host is unable to use specified algorithm. name: checksum_algorithm predefined: - md5 - sha1 - sha256 - sha384 - sha512 - auto: PREDEFINED defaultValue: file description: Type of file to search for. name: file_type predefined: - directory - file - defaultValue: "False" description: |- Set this to `yes` to follow symlinks in the path. This needs to be used in conjunction with `recurse`. name: follow - defaultValue: "True" description: Whether to return a checksum of the file in the return info (default sha1), use `checksum_algorithm` to change from the default. name: get_checksum - defaultValue: "False" description: Set this to include hidden files or folders. name: hidden - description: |- List of paths of directories to search for files or folders in. This can be supplied as a single path or a list of paths. isArray: true name: paths required: true - description: |- One or more (powershell or regex) patterns to compare filenames with. The type of pattern matching is controlled by `use_regex` option. The patterns restrict the list of files or folders to be returned based on the filenames. For a file to be matched it only has to match with one pattern in a list provided. isArray: true name: patterns - defaultValue: "False" description: Will recursively descend into the directory looking for files or folders. name: recurse - description: |- Select files or folders whose size is equal to or greater than the specified size. Use a negative value to find files equal to or less than the specified size. You can specify the size with a suffix of the byte type i.e. kilo = k, mega = m... Size is not evaluated for symbolic links. name: size - defaultValue: "False" description: Will set patterns to run as a regex check if set to `yes`. name: use_regex description: Return a list of files based on specific criteria. name: win-find outputs: - contextPath: MicrosoftWindows.files.attributes description: attributes of the file at path in raw form. type: string - contextPath: MicrosoftWindows.files.checksum description: The checksum of a file based on checksum_algorithm specified. type: string - contextPath: MicrosoftWindows.files.creationtime description: The create time of the file represented in seconds since epoch. - contextPath: MicrosoftWindows.files.extension description: The extension of the file at path. type: string - contextPath: MicrosoftWindows.files.filename description: The name of the file. type: string - contextPath: MicrosoftWindows.files.isarchive description: If the path is ready for archiving or not. type: boolean - contextPath: MicrosoftWindows.files.isdir description: If the path is a directory or not. type: boolean - contextPath: MicrosoftWindows.files.ishidden description: If the path is hidden or not. type: boolean - contextPath: MicrosoftWindows.files.islnk description: If the path is a symbolic link or junction or not. type: boolean - contextPath: MicrosoftWindows.files.isreadonly description: If the path is read only or not. type: boolean - contextPath: MicrosoftWindows.files.isshared description: If the path is shared or not. type: boolean - contextPath: MicrosoftWindows.files.lastaccesstime description: The last access time of the file represented in seconds since epoch. - contextPath: MicrosoftWindows.files.lastwritetime description: The last modification time of the file represented in seconds since epoch. - contextPath: MicrosoftWindows.files.lnk_source description: The target of the symbolic link, will return null if not a link or the link is broken. type: string - contextPath: MicrosoftWindows.files.owner description: The owner of the file. type: string - contextPath: MicrosoftWindows.files.path description: The full absolute path to the file. type: string - contextPath: MicrosoftWindows.files.sharename description: The name of share if folder is shared. type: string - contextPath: MicrosoftWindows.files.size description: The size in bytes of a file or folder. type: number - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - auto: PREDEFINED defaultValue: '[''Domain'', ''Private'', ''Public'']' description: Specify one or more profiles to change. isArray: true name: profiles predefined: - Domain - Private - Public - auto: PREDEFINED description: Set state of firewall for given profile. name: state predefined: - disabled - enabled description: Enable or disable the Windows Firewall. name: win-firewall - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Whether this firewall rule is enabled or disabled. Defaults to `true` when creating a new rule. name: enabled - auto: PREDEFINED defaultValue: present description: Should this rule be added or removed. name: state predefined: - absent - present - description: The rule's display name. name: name required: true - description: The group name for the rule. name: group - auto: PREDEFINED description: |- Whether this rule is for inbound or outbound traffic. Defaults to `in` when creating a new rule. name: direction predefined: - in - out - auto: PREDEFINED description: |- What to do with the items this rule is for. Defaults to `allow` when creating a new rule. name: action predefined: - allow - block - description: Description for the firewall rule. name: description - description: |- The local ip address this rule applies to. Set to `any` to apply to all local ip addresses. Defaults to `any` when creating a new rule. name: localip - description: |- The remote ip address/range this rule applies to. Set to `any` to apply to all remote ip addresses. Defaults to `any` when creating a new rule. name: remoteip - description: |- The local port this rule applies to. Set to `any` to apply to all local ports. Defaults to `any` when creating a new rule. Must have `protocol` set. name: localport - description: |- The remote port this rule applies to. Set to `any` to apply to all remote ports. Defaults to `any` when creating a new rule. Must have `protocol` set. name: remoteport - description: |- The program this rule applies to. Set to `any` to apply to all programs. Defaults to `any` when creating a new rule. name: program - description: |- The service this rule applies to. Set to `any` to apply to all services. Defaults to `any` when creating a new rule. name: service - description: |- The protocol this rule applies to. Set to `any` to apply to all services. Defaults to `any` when creating a new rule. name: protocol - description: |- The profile this rule applies to. Defaults to `domain,private,public` when creating a new rule. isArray: true name: profiles description: Windows firewall automation. name: win-firewall-rule - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Used to specify the drive letter of the volume to be formatted. name: drive_letter - description: Used to specify the path to the volume to be formatted. name: path - description: Used to specify the label of the volume to be formatted. name: label - description: Used to specify the new file system label of the formatted volume. name: new_label - auto: PREDEFINED description: Used to specify the file system to be used when formatting the target volume. name: file_system predefined: - ntfs - refs - exfat - fat32 - fat - description: |- Specifies the cluster size to use when formatting the volume. If no cluster size is specified when you format a partition, defaults are selected based on the size of the partition. name: allocation_unit_size - description: Specifies that large File Record System (FRS) should be used. name: large_frs - description: |- Enable compression on the resulting NTFS volume. NTFS compression is not supported where `allocation_unit_size` is more than 4096. name: compress - description: Enable integrity streams on the resulting ReFS volume. name: integrity_streams - description: |- A full format writes to every sector of the disk, takes much longer to perform than the default (quick) format, and is not recommended on storage that is thinly provisioned. Specify `true` for full format. name: full - description: Specify if formatting should be forced for volumes that are not created from new partitions or if the source and target file system are different. name: force description: Formats an existing volume or a new volume on an existing partition on Windows. name: win-format - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The full URL of a file to download. name: url required: true - description: |- The location to save the file at the URL. Be sure to include a filename and extension as appropriate. name: dest required: true - defaultValue: "True" description: |- If `yes`, will download the file every time and replace the file if the contents change. If `no`, will only download the file if it does not exist or the remote file has been modified more recently than the local file. This works by sending an http HEAD request to retrieve last modified time of the requested resource, so for this to work, the remote web server must support HEAD requests. name: force - description: |- If a `checksum` is passed to this parameter, the digest of the destination file will be calculated after it is downloaded to ensure its integrity and verify that the transfer completed successfully. This option cannot be set with `checksum_url`. name: checksum - auto: PREDEFINED defaultValue: sha1 description: Specifies the hashing algorithm used when calculating the checksum of the remote and destination file. name: checksum_algorithm predefined: - md5 - sha1 - sha256 - sha384 - sha512 - description: |- Specifies a URL that contains the checksum values for the resource at `url`. Like `checksum`, this is used to verify the integrity of the remote transfer. This option cannot be set with `checksum`. name: checksum_url - description: |- An explicit proxy to use for the request. By default, the request will use the IE defined proxy unless `use_proxy` is set to `no`. name: proxy_url - description: The username to use for proxy authentication. name: proxy_username - description: The password for `proxy_username`. name: proxy_password - description: |- Extra headers to set on the request. This should be a dictionary where the key is the header name and the value is the value for that header. isArray: true name: headers - defaultValue: "True" description: If `no`, it will not use the proxy defined in IE for the current user. name: use_proxy - auto: PREDEFINED defaultValue: safe description: |- Whether or the module should follow redirects. `all` will follow all redirect. `none` will not follow any redirect. `safe` will follow only "safe" redirects, where "safe" means that the client is only doing a `GET` or `HEAD` on the URI to which it is being redirected. name: follow_redirects predefined: - all - none - safe - defaultValue: "50" description: |- Specify how many times the module will redirect a connection to an alternative URI before the connection fails. If set to `0` or `follow_redirects` is set to `none`, or `safe` when not doing a `GET` or `HEAD` it prevents all redirection. name: maximum_redirection - description: |- The path to the client certificate (.pfx) that is used for X509 authentication. This path can either be the path to the `pfx` on the filesystem or the PowerShell certificate path `Cert:\CurrentUser\My\<thumbprint>`. The WinRM connection must be authenticated with `CredSSP` or `become` is used on the task if the certificate file is not password protected. Other authentication types can set `client_cert_password` when the cert is password protected. name: client_cert - description: The password for `client_cert` if the cert is password protected. name: client_cert_password - description: This option is not for use with `win_get_url` and should be ignored. name: method - defaultValue: ansible-httpget description: |- Header to identify as, generally appears in web server logs. This is set to the `User-Agent` header on a HTTP request. name: http_agent - defaultValue: "30" description: |- Specifies how long the request can be pending before it times out (in seconds). Set to `0` to specify an infinite timeout. name: timeout - defaultValue: "True" description: |- If `no`, SSL certificates will not be validated. This should only be used on personally controlled sites using self-signed certificates. name: validate_certs - defaultValue: "False" description: |- By default the authentication header is only sent when a webservice responses to an initial request with a 401 status. Since some basic auth services do not properly send a 401, logins will fail. This option forces the sending of the Basic authentication header upon the original request. name: force_basic_auth - description: The username to use for authentication. name: url_username - description: The password for `url_username`. name: url_password - defaultValue: "False" description: |- Uses the current user's credentials when authenticating with a server protected with `NTLM`, `Kerberos`, or `Negotiate` authentication. Sites that use `Basic` auth will still require explicit credentials through the `url_username` and `url_password` options. The module will only have access to the user's credentials if using `become` with a password, you are connecting with SSH using a password, or connecting with WinRM using `CredSSP` or `Kerberos with delegation`. If not using `become` or a different auth method to the ones stated above, there will be no default credentials available and no authentication will occur. name: use_default_credential - defaultValue: "False" description: |- Uses the current user's credentials when authenticating with a proxy host protected with `NTLM`, `Kerberos`, or `Negotiate` authentication. Proxies that use `Basic` auth will still require explicit credentials through the `proxy_username` and `proxy_password` options. The module will only have access to the user's credentials if using `become` with a password, you are connecting with SSH using a password, or connecting with WinRM using `CredSSP` or `Kerberos with delegation`. If not using `become` or a different auth method to the ones stated above, there will be no default credentials available and no proxy authentication will occur. name: proxy_use_default_credential description: Downloads file from HTTP, HTTPS, or FTP to node. name: win-get-url - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the group. name: name required: true - description: Description of the group. name: description - auto: PREDEFINED defaultValue: present description: Create or remove the group. name: state predefined: - absent - present description: Add and remove local groups. name: win-group - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the local group to manage membership on. name: name required: true - description: |- A list of members to ensure are present/absent from the group. Accepts local users as .\username, and SERVERNAME\username. Accepts domain users and groups as DOMAIN\username and username@DOMAIN. Accepts service users as NT AUTHORITY\username. Accepts all local, domain and service user types as username, favoring domain lookups when in a domain. isArray: true name: members required: true - auto: PREDEFINED defaultValue: present description: |- Desired state of the members in the group. `pure` was added in Ansible 2.8. When `state` is `pure`, only the members specified will exist, and all other existing members not specified are removed. name: state predefined: - absent - present - pure description: Manage Windows local group membership. name: win-group-membership - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The hostname to set for the computer. name: name required: true description: Manages local Windows computer name. name: win-hostname - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - auto: PREDEFINED defaultValue: present description: |- Whether the entry should be present or absent. If only `canonical_name` is provided when `state=absent`, then all hosts entries with the canonical name of `canonical_name` will be removed. If only `ip_address` is provided when `state=absent`, then all hosts entries with the ip address of `ip_address` will be removed. If `ip_address` and `canonical_name` are both omitted when `state=absent`, then all hosts entries will be removed. name: state predefined: - absent - present - description: |- A canonical name for the host entry. required for `state=present`. name: canonical_name - description: |- The ip address for the host entry. Can be either IPv4 (A record) or IPv6 (AAAA record). Required for `state=present`. name: ip_address - description: |- A list of additional names (cname records) for the host entry. Only applicable when `state=present`. isArray: true name: aliases - auto: PREDEFINED defaultValue: set description: |- Controls the behavior of `aliases`. Only applicable when `state=present`. If `add`, each alias in `aliases` will be added to the host entry. If `set`, each alias in `aliases` will be added to the host entry, and other aliases will be removed from the entry. name: action predefined: - add - remove - set description: Manages hosts file entries on Windows. name: win-hosts - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The name of the hotfix as shown in DISM, see examples for details. This or `hotfix_kb` MUST be set when `state=absent`. If `state=present` then the hotfix at `source` will be validated against this value, if it does not match an error will occur. You can get the identifier by running 'Get-WindowsPackage -Online -PackagePath path-to-cab-in-msu' after expanding the msu file. name: hotfix_identifier - description: |- The name of the KB the hotfix relates to, see examples for details. This or `hotfix_identifier` MUST be set when `state=absent`. If `state=present` then the hotfix at `source` will be validated against this value, if it does not match an error will occur. Because DISM uses the identifier as a key and doesn't refer to a KB in all cases it is recommended to use `hotfix_identifier` instead. name: hotfix_kb - auto: PREDEFINED defaultValue: present description: |- Whether to install or uninstall the hotfix. When `present`, `source` MUST be set. When `absent`, `hotfix_identifier` or `hotfix_kb` MUST be set. name: state predefined: - absent - present - description: |- The path to the downloaded hotfix .msu file. This MUST be set if `state=present` and MUST be a .msu hotfix file. name: source description: Install and uninstalls Windows hotfixes. name: win-hotfix - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- A list of hosts that will bypass the set proxy when being accessed. Use `<local>` to match hostnames that are not fully qualified domain names. This is useful when needing to connect to intranet sites using just the hostname. Omit, set to null or an empty string/list to remove the bypass list. If this is set then `proxy` must also be set. isArray: true name: bypass - description: |- A string or dict that specifies the proxy to be set. If setting a string, should be in the form `hostname`, `hostname:port`, or `protocol=hostname:port`. If the port is undefined, the default port for the protocol in use is used. If setting a dict, the keys should be the protocol and the values should be the hostname and/or port for that protocol. Valid protocols are `http`, `https`, `ftp`, and `socks`. Omit, set to null or an empty string to remove the proxy settings. name: proxy - auto: PREDEFINED description: |- Instead of manually specifying the `proxy` and/or `bypass`, set this to import the proxy from a set source like Internet Explorer. Using `ie` will import the Internet Explorer proxy settings for the current active network connection of the current user. Only IE's proxy URL and bypass list will be imported into WinHTTP. This is like running `netsh winhttp import proxy source=ie`. The value is imported when the module runs and will not automatically be updated if the IE configuration changes in the future. The module will have to be run again to sync the latest changes. name: source predefined: - ie description: Manages proxy settings for WinHTTP. name: win-http-proxy - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The name of the virtual directory to create or remove. name: name required: true - auto: PREDEFINED defaultValue: present description: |- Whether to add or remove the specified virtual directory. Removing will remove the virtual directory and all under it (Recursively). name: state predefined: - absent - present - description: The site name under which the virtual directory is created or exists. name: site required: true - description: The application under which the virtual directory is created or exists. name: application - description: |- The physical path to the folder in which the new virtual directory is created. The specified folder must already exist. name: physical_path description: Configures a virtual directory in IIS. name: win-iis-virtualdirectory - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the web application. name: name required: true - description: Name of the site on which the application is created. name: site required: true - auto: PREDEFINED defaultValue: present description: State of the web application. name: state predefined: - absent - present - description: |- The physical path on the remote host to use for the new application. The specified folder must already exist. name: physical_path - description: The application pool in which the new site executes. name: application_pool description: Configures IIS web applications. name: win-iis-webapplication - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- This field is a free form dictionary value for the application pool attributes. These attributes are based on the naming standard at `https://www.iis.net/configreference/system.applicationhost/applicationpools/add#005`, see the examples section for more details on how to set this. You can also set the attributes of child elements like cpu and processModel, see the examples to see how it is done. While you can use the numeric values for enums it is recommended to use the enum name itself, e.g. use SpecificUser instead of 3 for processModel.identityType. managedPipelineMode may be either "Integrated" or "Classic". startMode may be either "OnDemand" or "AlwaysRunning". Use `state` module parameter to modify the state of the app pool. When trying to set 'processModel.password' and you receive a 'Value does fall within the expected range' error, you have a corrupted keystore. Please follow `http://structuredsight.com/2014/10/26/im-out-of-range-youre-out-of-range/` to help fix your host. name: attributes - description: Name of the application pool. name: name required: true - auto: PREDEFINED defaultValue: present description: |- The state of the application pool. If `absent` will ensure the app pool is removed. If `present` will ensure the app pool is configured and exists. If `restarted` will ensure the app pool exists and will restart, this is never idempotent. If `started` will ensure the app pool exists and is started. If `stopped` will ensure the app pool exists and is stopped. name: state predefined: - absent - present - restarted - started - stopped description: Configure IIS Web Application Pools. name: win-iis-webapppool outputs: - contextPath: MicrosoftWindows.info.attributes description: Key value pairs showing the current Application Pool attributes. - contextPath: MicrosoftWindows.info.cpu description: Key value pairs showing the current Application Pool cpu attributes. - contextPath: MicrosoftWindows.info.failure description: Key value pairs showing the current Application Pool failure attributes. - contextPath: MicrosoftWindows.info.name description: Name of Application Pool that was processed by this module invocation. type: string - contextPath: MicrosoftWindows.info.processModel description: Key value pairs showing the current Application Pool processModel attributes. - contextPath: MicrosoftWindows.info.recycling description: Key value pairs showing the current Application Pool recycling attributes. - contextPath: MicrosoftWindows.info.state description: Current runtime state of the pool as the module completed. type: string - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Names of web site. name: name required: true - auto: PREDEFINED defaultValue: present description: State of the binding. name: state predefined: - absent - present - defaultValue: "80" description: The port to bind to / use for the new site. name: port - defaultValue: '*' description: The IP address to bind to / use for the new site. name: ip - description: |- The host header to bind to / use for the new site. If you are creating/removing a catch-all binding, omit this parameter rather than defining it as '*'. name: host_header - defaultValue: http description: The protocol to be used for the Web binding (usually HTTP, HTTPS, or FTP). name: protocol - description: Certificate hash (thumbprint) for the SSL binding. The certificate hash is the unique identifier for the certificate. name: certificate_hash - defaultValue: my description: Name of the certificate store where the certificate for the binding is located. name: certificate_store_name - description: |- This parameter is only valid on Server 2012 and newer. Primarily used for enabling and disabling server name indication (SNI). Set to c(0) to disable SNI. Set to c(1) to enable SNI. name: ssl_flags description: Configures a IIS Web site binding. name: win-iis-webbinding - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Names of web site. name: name required: true - description: |- Explicitly set the IIS numeric ID for a site. Note that this value cannot be changed after the website has been created. name: site_id - auto: PREDEFINED description: State of the web site. name: state predefined: - absent - started - stopped - restarted - description: |- The physical path on the remote host to use for the new site. The specified folder must already exist. name: physical_path - description: The application pool in which the new site executes. name: application_pool - description: The port to bind to / use for the new site. name: port - description: The IP address to bind to / use for the new site. name: ip - description: The host header to bind to / use for the new site. name: hostname - description: Enables HTTPS binding on the site.. name: ssl - description: Custom site Parameters from string where properties are separated by a pipe and property name/values by colon Ex. "foo:1|bar:2". name: parameters description: Configures a IIS Web site. name: win-iis-website - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: "True" description: |- Whether to configure WinINet to automatically detect proxy settings through Web Proxy Auto-Detection `WPAD`. This corresponds to the checkbox `Automatically detect settings` in the connection settings window. name: auto_detect - description: |- The URL of a proxy configuration script. Proxy configuration scripts are typically JavaScript files with the `.pac` extension that implement the `FindProxyForURL(url, host` function. Omit, set to null or an empty string to remove the auto config URL. This corresponds to the checkbox `Use automatic configuration script` in the connection settings window. name: auto_config_url - description: |- A list of hosts that will bypass the set proxy when being accessed. Use `<local>` to match hostnames that are not fully qualified domain names. This is useful when needing to connect to intranet sites using just the hostname. If defined, this should be the last entry in the bypass list. Use `<-loopback>` to stop automatically bypassing the proxy when connecting through any loopback address like `127.0.0.1`, `localhost`, or the local hostname. Omit, set to null or an empty string/list to remove the bypass list. If this is set then `proxy` must also be set. isArray: true name: bypass - description: |- The name of the IE connection to set the proxy settings for. These are the connections under the `Dial-up and Virtual Private Network` header in the IE settings. When omitted, the default LAN connection is used. name: connection - description: |- A string or dict that specifies the proxy to be set. If setting a string, should be in the form `hostname`, `hostname:port`, or `protocol=hostname:port`. If the port is undefined, the default port for the protocol in use is used. If setting a dict, the keys should be the protocol and the values should be the hostname and/or port for that protocol. Valid protocols are `http`, `https`, `ftp`, and `socks`. Omit, set to null or an empty string to remove the proxy settings. name: proxy description: Manages proxy settings for WinINet and Internet Explorer. name: win-inet-proxy - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The path of the file to modify. Note that the Windows path delimiter `\` must be escaped as `\\` when the line is double quoted. Before Ansible 2.3 this option was only usable as `dest`, `destfile` and `name`. name: path required: true - defaultValue: "False" description: |- Determine whether a backup should be created. When set to `yes`, create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly. name: backup - description: The regular expression to look for in every line of the file. For `state=present`, the pattern to replace if found; only the last line found will be replaced. For `state=absent`, the pattern of the line to remove. Uses .NET compatible regular expressions; see `https://msdn.microsoft.com/en-us/library/hs600312%28v=vs.110%29.aspx`. name: regex - auto: PREDEFINED defaultValue: present description: Whether the line should be there or not. name: state predefined: - absent - present - description: |- Required for `state=present`. The line to insert/replace into the file. If `backrefs` is set, may contain backreferences that will get expanded with the `regexp` capture groups if the regexp matches. Be aware that the line is processed first on the controller and thus is dependent on yaml quoting rules. Any double quoted line will have control characters, such as '\r\n', expanded. To print such characters literally, use single or no quotes. name: line - defaultValue: "False" description: |- Used with `state=present`. If set, line can contain backreferences (both positional and named) that will get populated if the `regexp` matches. This flag changes the operation of the module slightly; `insertbefore` and `insertafter` will be ignored, and if the `regexp` doesn't match anywhere in the file, the file will be left unchanged. If the `regexp` does match, the last matching line will be replaced by the expanded line parameter. name: backrefs - auto: PREDEFINED defaultValue: EOF description: |- Used with `state=present`. If specified, the line will be inserted after the last match of specified regular expression. A special value is available; `EOF` for inserting the line at the end of the file. If specified regular expression has no matches, EOF will be used instead. May not be used with `backrefs`. name: insertafter predefined: - EOF - '*regex*' - auto: PREDEFINED description: |- Used with `state=present`. If specified, the line will be inserted before the last match of specified regular expression. A value is available; `BOF` for inserting the line at the beginning of the file. If specified regular expression has no matches, the line will be inserted at the end of the file. May not be used with `backrefs`. name: insertbefore predefined: - BOF - '*regex*' - defaultValue: "False" description: Used with `state=present`. If specified, the file will be created if it does not already exist. By default it will fail if the file is missing. name: create - description: |- Validation to run before copying into place. Use %s in the command to indicate the current file to validate. The command is passed securely so shell features like expansion and pipes won't work. name: validate - defaultValue: auto description: |- Specifies the encoding of the source text file to operate on (and thus what the output encoding will be). The default of `auto` will cause the module to auto-detect the encoding of the source file and ensure that the modified file is written with the same encoding. An explicit encoding can be passed as a string that is a valid value to pass to the .NET framework System.Text.Encoding.GetEncoding() method - see `https://msdn.microsoft.com/en-us/library/system.text.encoding%28v=vs.110%29.aspx`. This is mostly useful with `create=yes` if you want to create a new file with a specific encoding. If `create=yes` is specified without a specific encoding, the default encoding (UTF-8, no BOM) will be used. name: encoding - auto: PREDEFINED defaultValue: windows description: Specifies the line separator style to use for the modified file. This defaults to the windows line separator (`\r\n`). Note that the indicated line separator will be used for file output regardless of the original line separator that appears in the input file. name: newline predefined: - unix - windows description: Ensure a particular line is in a file, or replace an existing line using a back-referenced regular expression. name: win-lineinfile - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The letter of the network path to map to. This letter must not already be in use with Windows. name: letter required: true - description: |- The password for `username` that is used when testing the initial connection. This is never saved with a mapped drive, use the `win_credential` module to persist a username and password for a host. name: password - description: |- The UNC path to map the drive to. If pointing to a WebDAV location this must still be in a UNC path in the format `\\hostname\path` and not a URL, see examples for more details. To specify a `https` WebDAV path, add `@SSL` after the hostname. To specify a custom WebDAV port add `@<port num>` after the `@SSL` or hostname portion of the UNC path, e.g. `\\server@SSL@1234` or `\\server@1234`. This is required if `state=present`. If `state=absent` and `path` is not set, the module will delete the mapped drive regardless of the target. If `state=absent` and the `path` is set, the module will throw an error if path does not match the target of the mapped drive. name: path - auto: PREDEFINED defaultValue: present description: |- If `present` will ensure the mapped drive exists. If `absent` will ensure the mapped drive does not exist. name: state predefined: - absent - present - description: |- The username that is used when testing the initial connection. This is never saved with a mapped drive, the the `win_credential` module to persist a username and password for a host. This is required if the mapped drive requires authentication with custom credentials and become, or CredSSP cannot be used. If become or CredSSP is used, any credentials saved with `win_credential` will automatically be used instead. name: username description: Map network drives for users. name: win-mapped-drive - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: '*' description: Who to send the message to. Can be a username, sessionname or sessionid. name: to - defaultValue: "10" description: How long to wait for receiver to acknowledge message, in seconds. name: display_seconds - defaultValue: "no" description: Whether to wait for users to respond. Module will only wait for the number of seconds specified in display_seconds or 10 seconds if not specified. However, if `wait` is `yes`, the message is sent to each logged on user in turn, waiting for the user to either press 'ok' or for the timeout to elapse before moving on to the next user. name: wait - defaultValue: Hello world! description: |- The text of the message to be displayed. The message must be less than 256 characters. name: msg description: Sends a message to logged in users on Windows hosts. name: win-msg - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - auto: PREDEFINED description: Whether NetBIOS should be enabled, disabled, or default (use setting from DHCP server or if static IP address is assigned enable NetBIOS). name: state predefined: - enabled - disabled - default required: true - description: |- List of adapter names for which to manage NetBIOS settings. If this option is omitted then configuration is applied to all adapters on the system. The adapter name used is the connection caption in the Network Control Panel or via `Get-NetAdapter`, eg `Ethernet 2`. isArray: true name: adapter_names description: Manage NetBIOS over TCP/IP settings on Windows. name: win-netbios - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the service to operate on. name: name required: true - auto: PREDEFINED defaultValue: present description: |- State of the service on the system. Values `started`, `stopped`, and `restarted` are deprecated since v2.8, please use the `win_service` module instead to start, stop or restart the service. name: state predefined: - absent - present - started - stopped - restarted - description: |- The application binary to run as a service Required when `state` is `present`, `started`, `stopped`, or `restarted`. name: application - defaultValue: nssm.exe description: The location of the NSSM utility (in case it is not located in your PATH). name: executable - description: The description to set for the service. name: description - description: The display name to set for the service. name: display_name - description: The working directory to run the service executable from (defaults to the directory containing the application binary). name: working_directory - description: Path to receive output. name: stdout_file - description: Path to receive error output. name: stderr_file - description: |- A string representing a dictionary of parameters to be passed to the application when it starts. DEPRECATED since v2.8, please use `arguments` instead. This is mutually exclusive with `arguments`. name: app_parameters - description: |- Parameters to be passed to the application when it starts. This can be either a simple string or a list. This parameter was renamed from `app_parameters_free_form` in 2.8. This is mutually exclusive with `app_parameters`. name: arguments - description: |- Service dependencies that has to be started to trigger startup, separated by comma. DEPRECATED since v2.8, please use the `win_service` module instead. isArray: true name: dependencies - description: |- User to be used for service startup. DEPRECATED since v2.8, please use the `win_service` module instead. name: user - description: |- Password to be used for service startup. DEPRECATED since v2.8, please use the `win_service` module instead. name: password - auto: PREDEFINED defaultValue: auto description: |- If `auto` is selected, the service will start at bootup. `delayed` causes a delayed but automatic start after boot (added in version 2.5). `manual` means that the service will start only when another service needs it. `disabled` means that the service will stay off, regardless if it is needed or not. DEPRECATED since v2.8, please use the `win_service` module instead. name: start_mode predefined: - auto - delayed - disabled - manual description: Install a service using NSSM. name: win-nssm - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The name(s) of the feature to install. This relates to `FeatureName` in the Powershell cmdlet. To list all available features use the PowerShell command `Get-WindowsOptionalFeature`. isArray: true name: name required: true - auto: PREDEFINED defaultValue: present description: Whether to ensure the feature is absent or present on the system. name: state predefined: - absent - present - defaultValue: "False" description: Whether to enable the parent feature and the parent's dependencies. name: include_parent - description: |- Specify a source to install the feature from. Can either be `{driveletter}:\sources\sxs` or `\\{IP}\share\sources\sxs`. name: source description: Manage optional Windows features. name: win-optional-feature - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Path to be used for changing owner. name: path required: true - description: Name to be used for changing owner. name: user required: true - defaultValue: "False" description: Indicates if the owner should be changed recursively. name: recurse description: Set owner. name: win-owner - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Any arguments the installer needs to either install or uninstall the package. If the package is an MSI do not supply the `/qn`, `/log` or `/norestart` arguments. As of Ansible 2.5, this parameter can be a list of arguments and the module will escape the arguments as necessary, it is recommended to use a string when dealing with MSI packages due to the unique escaping issues with msiexec. name: arguments - description: Set the specified path as the current working directory before installing or uninstalling a package. name: chdir - description: |- Will check the existence of the path specified and use the result to determine whether the package is already installed. You can use this in conjunction with `product_id` and other `creates_*`. name: creates_path - description: |- Will check the existing of the service specified and use the result to determine whether the package is already installed. You can use this in conjunction with `product_id` and other `creates_*`. name: creates_service - description: |- Will check the file version property of the file at `creates_path` and use the result to determine whether the package is already installed. `creates_path` MUST be set and is a file. You can use this in conjunction with `product_id` and other `creates_*`. name: creates_version - defaultValue: '[0, 3010]' description: |- One or more return codes from the package installation that indicates success. Before Ansible 2.4 this was just 0 but since Ansible 2.4 this is both `0` and `3010`. A return code of `3010` usually means that a reboot is required, the `reboot_required` return value is set if the return code is `3010`. isArray: true name: expected_return_code - description: The password for `user_name`, must be set when `user_name` is. name: password - description: |- Location of the package to be installed or uninstalled. This package can either be on the local file system, network share or a url. If the path is on a network share and the current WinRM transport doesn't support credential delegation, then `user_name` and `user_password` must be set to access the file. There are cases where this file will be copied locally to the server so it can access it, see the notes for more info. If `state=present` then this value MUST be set. If `state=absent` then this value does not need to be set if `product_id` is. name: path - description: |- The product id of the installed packaged. This is used for checking whether the product is already installed and getting the uninstall information if `state=absent`. You can find product ids for installed programs in the Windows registry editor either at `HKLM:Software\Microsoft\Windows\CurrentVersion\Uninstall` or for 32 bit programs at `HKLM:Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall`. This SHOULD be set when the package is not an MSI, or the path is a url or a network share and credential delegation is not being used. The `creates_*` options can be used instead but is not recommended. name: product_id - auto: PREDEFINED defaultValue: present description: |- Whether to install or uninstall the package. The module uses `product_id` and whether it exists at the registry path to see whether it needs to install or uninstall the package. name: state predefined: - absent - present - description: |- Username of an account with access to the package if it is located on a file share. This is only needed if the WinRM transport is over an auth method that does not support credential delegation like Basic or NTLM. name: username - defaultValue: "True" description: |- If `no`, SSL certificates will not be validated. This should only be used on personally controlled sites using self-signed certificates. Before Ansible 2.4 this defaulted to `no`. name: validate_certs - description: |- Specifies the path to a log file that is persisted after an MSI package is installed or uninstalled. When omitted, a temporary log file is used for MSI packages. This is only valid for MSI files, use `arguments` for other package types. name: log_path description: Installs/uninstalls an installable package. name: win-package - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The drive of the pagefile. name: drive - description: The initial size of the pagefile in megabytes. name: initial_size - description: The maximum size of the pagefile in megabytes. name: maximum_size - defaultValue: "True" description: Override the current pagefile on the drive. name: override - defaultValue: "False" description: Configures current pagefile to be managed by the system. name: system_managed - description: Configures AutomaticManagedPagefile for the entire system. name: automatic - defaultValue: "False" description: Remove all pagefiles in the system, not including automatic managed. name: remove_all - defaultValue: "True" description: Use Test-Path on the drive to make sure the drive is accessible before creating the pagefile. name: test_path - auto: PREDEFINED defaultValue: query description: State of the pagefile. name: state predefined: - absent - present - query description: Query or change pagefile configuration. name: win-pagefile - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - auto: PREDEFINED defaultValue: present description: Used to specify the state of the partition. Use `absent` to specify if a partition should be removed and `present` to specify if the partition should be created or updated. name: state predefined: - absent - present - description: |- Used for accessing partitions if `disk_number` and `partition_number` are not provided. Use `auto` for automatically assigning a drive letter, or a letter A-Z for manually assigning a drive letter to a new partition. If not specified, no drive letter is assigned when creating a new partition. name: drive_letter - description: |- Disk number is mandatory for creating new partitions. A combination of `disk_number` and `partition_number` can be used to specify the partition instead of `drive_letter` if required. name: disk_number - description: Used in conjunction with `disk_number` to uniquely identify a partition. name: partition_number - description: |- Specify size of the partition in B, KB, KiB, MB, MiB, GB, GiB, TB or TiB. Use -1 to specify maximum supported size. Partition size is mandatory for creating a new partition but not for updating or deleting a partition. The decimal SI prefixes kilo, mega, giga, tera, etc., are powers of 10^3 = 1000. The binary prefixes kibi, mebi, gibi, tebi, etc. respectively refer to the corresponding power of 2^10 = 1024. Thus, a gigabyte (GB) is 1000000000 (1000^3) bytes while 1 gibibyte (GiB) is 1073741824 (1024^3) bytes. name: partition_size - description: Make the partition read only, restricting changes from being made to the partition. name: read_only - description: Specifies if the partition is active and can be used to start the system. This property is only valid when the disk's partition style is MBR. name: active - description: Hides the target partition, making it undetectable by the mount manager. name: hidden - description: |- Sets the partition offline. Adding a mount point (such as a drive letter) will cause the partition to go online again. name: offline - auto: PREDEFINED description: |- Specify the partition's MBR type if the disk's partition style is MBR. This only applies to new partitions. This does not relate to the partitions file system formatting. name: mbr_type predefined: - fat12 - fat16 - extended - huge - ifs - fat32 - auto: PREDEFINED description: |- Specify the partition's GPT type if the disk's partition style is GPT. This only applies to new partitions. This does not relate to the partitions file system formatting. name: gpt_type predefined: - system_partition - microsoft_reserved - basic_data - microsoft_recovery description: Creates, changes and removes partitions on Windows Server. name: win-partition - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: PATH description: Target path environment variable name. name: name - description: |- A single path element, or a list of path elements (ie, directories) to add or remove. When multiple elements are included in the list (and `state` is `present`), the elements are guaranteed to appear in the same relative order in the resultant path value. Variable expansions (eg, `%VARNAME%`) are allowed, and are stored unexpanded in the target path element. Any existing path elements not mentioned in `elements` are always preserved in their current order. New path elements are appended to the path, and existing path elements may be moved closer to the end to satisfy the requested ordering. Paths are compared in a case-insensitive fashion, and trailing backslashes are ignored for comparison purposes. However, note that trailing backslashes in YAML require quotes. isArray: true name: elements required: true - auto: PREDEFINED description: Whether the path elements specified in `elements` should be present or absent. name: state predefined: - absent - present - auto: PREDEFINED defaultValue: machine description: The level at which the environment variable specified by `name` should be managed (either for the current user or global machine scope). name: scope predefined: - machine - user description: Manage Windows path environment variables. name: win-path - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Path to a pester test file or a folder where tests can be found. If the path is a folder, the module will consider all ps1 files as Pester tests. name: path required: true - description: |- Runs only tests in Describe blocks with specified Tags values. Accepts multiple comma separated tags. isArray: true name: tags - description: Allows to specify parameters to the test script. isArray: true name: test_parameters - description: Minimum version of the pester module that has to be available on the remote host. name: version description: Run Pester tests on Windows hosts. name: win-pester - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: pong description: |- Alternate data to return instead of 'pong'. If this parameter is set to `crash`, the module will cause an exception. name: data description: A windows version of the classic ping module. name: win-ping - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- String value that indicates the desired power plan. The power plan must already be present on the system. Commonly there will be options for `balanced` and `high performance`. name: name required: true description: Changes the power plan of a Windows system. name: win-power-plan - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true description: Provides Windows product and license information. name: win-product-facts outputs: - contextPath: MicrosoftWindows.ansible_facts.ansible_os_license_channel description: The Windows license channel. type: string - contextPath: MicrosoftWindows.ansible_facts.ansible_os_license_edition description: The Windows license edition. type: string - contextPath: MicrosoftWindows.ansible_facts.ansible_os_license_status description: The Windows license status. type: string - contextPath: MicrosoftWindows.ansible_facts.ansible_os_product_id description: The Windows product ID. type: string - contextPath: MicrosoftWindows.ansible_facts.ansible_os_product_key description: The Windows product key. type: string - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The command line to run through PsExec (limited to 260 characters). name: command required: true - defaultValue: psexec.exe description: The location of the PsExec utility (in case it is not located in your PATH). name: executable - description: |- Specify additional options to add onto the PsExec invocation. This module was undocumented in older releases and will be removed in Ansible 2.10. isArray: true name: extra_opts - description: |- The hostnames to run the command. If not provided, the command is run locally. isArray: true name: hostnames - description: |- The (remote) user to run the command as. If not provided, the current user is used. name: username - description: |- The password for the (remote) user to run the command as. This is mandatory in order authenticate yourself. name: password - description: Run the command from this (remote) directory. name: chdir - defaultValue: "False" description: |- Do not display the startup banner and copyright message. This only works for specific versions of the PsExec binary. name: nobanner - defaultValue: "False" description: Run the command without loading the account's profile. name: noprofile - defaultValue: "False" description: Run the command with elevated privileges. name: elevated - defaultValue: "False" description: Run the program so that it interacts with the desktop on the remote system. name: interactive - description: |- Specifies the session ID to use. This parameter works in conjunction with `interactive`. It has no effect when `interactive` is set to `no`. name: session - defaultValue: "False" description: Run the command as limited user (strips the Administrators group and allows only privileges assigned to the Users group). name: limited - defaultValue: "False" description: Run the remote command in the System account. name: system - auto: PREDEFINED description: Used to run the command at a different priority. name: priority predefined: - abovenormal - background - belownormal - high - low - realtime - description: The connection timeout in seconds. name: timeout - defaultValue: "True" description: |- Wait for the application to terminate. Only use for non-interactive applications. name: wait description: Runs commands (remotely) as another (privileged) user. name: win-psexec - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the Windows PowerShell module that has to be installed. name: name required: true - auto: PREDEFINED defaultValue: present description: |- If `present` a new module is installed. If `absent` a module is removed. If `latest` a module is updated to the newest version. This option was added in version 2.8. name: state predefined: - absent - latest - present - description: The exact version of the PowerShell module that has to be installed. name: required_version - description: The minimum version of the PowerShell module that has to be installed. name: minimum_version - description: The maximum version of the PowerShell module that has to be installed. name: maximum_version - defaultValue: "False" description: If `yes` allows install modules that contains commands those have the same names as commands that already exists. name: allow_clobber - defaultValue: "False" description: If `yes`, allows you to install a different version of a module that already exists on your computer in the case when a different one is not digitally signed by a trusted publisher and the newest existing module is digitally signed by a trusted publisher. name: skip_publisher_check - defaultValue: "False" description: |- If `yes` installs modules marked as prereleases. It doesn't work with the parameters `minimum_version` and/or `maximum_version`. It doesn't work with the `state` set to absent. name: allow_prerelease - description: Name of the custom repository to use. name: repository - description: |- URL of the custom repository to register. This option is deprecated and will be removed in Ansible 2.12. Use the `win_psrepository` module instead. name: url description: Adds or removes a Windows PowerShell module. name: win-psmodule - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the repository to work with. name: name required: true - description: |- Specifies the URI for discovering and installing modules from this repository. A URI can be a NuGet server feed (most common situation), HTTP, HTTPS, FTP or file location. name: source - auto: PREDEFINED defaultValue: present description: |- If `present` a new repository is added or updated. If `absent` a repository is removed. name: state predefined: - absent - present - auto: PREDEFINED description: |- Sets the `InstallationPolicy` of a repository. Will default to `trusted` when creating a new repository. name: installation_policy predefined: - trusted - untrusted description: Adds, removes or updates a Windows PowerShell repository. name: win-psrepository - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Comma-separated list of plugin names. name: names required: true - defaultValue: "False" description: |- Only enable missing plugins. Does not disable plugins that are not in the names list. name: new_only - auto: PREDEFINED defaultValue: enabled description: Specify if plugins are to be enabled or disabled. name: state predefined: - disabled - enabled - description: Specify a custom install prefix to a Rabbit. name: prefix description: Manage RabbitMQ plugins. name: win-rabbitmq-plugin - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the connection authorization policy. name: name required: true - auto: PREDEFINED defaultValue: present description: |- The state of connection authorization policy. If `absent` will ensure the policy is removed. If `present` will ensure the policy is configured and exists. If `enabled` will ensure the policy is configured, exists and enabled. If `disabled` will ensure the policy is configured, exists, but disabled. name: state predefined: - absent - enabled - disabled - present - auto: PREDEFINED description: |- Specifies how the RD Gateway server authenticates users. When a new CAP is created, the default value is `password`. name: auth_method predefined: - both - none - password - smartcard - description: |- Evaluation order of the policy. The CAP in which `order` is set to a value of '1' is evaluated first. By default, a newly created CAP will take the first position. If the given value exceed the total number of existing policies, the policy will take the last position but the evaluation order will be capped to this number. name: order - description: |- The maximum time, in minutes, that a session can be idle. A value of zero disables session timeout. name: session_timeout - auto: PREDEFINED defaultValue: disconnect description: |- The action the server takes when a session times out. `disconnect`: disconnect the session. `reauth`: silently reauthenticate and reauthorize the session. name: session_timeout_action predefined: - disconnect - reauth - description: |- Specifies the time interval, in minutes, after which an idle session is disconnected. A value of zero disables idle timeout. name: idle_timeout - description: Specifies whether connections are allowed only to Remote Desktop Session Host servers that enforce Remote Desktop Gateway redirection policy. name: allow_only_sdrts_servers - description: |- A list of user groups that is allowed to connect to the Remote Gateway server. Required when a new CAP is created. isArray: true name: user_groups - description: A list of computer groups that is allowed to connect to the Remote Gateway server. isArray: true name: computer_groups - description: Allow clipboard redirection. name: redirect_clipboard - description: Allow disk drive redirection. name: redirect_drives - description: Allow printers redirection. name: redirect_printers - description: Allow serial port redirection. name: redirect_serial - description: Allow Plug and Play devices redirection. name: redirect_pnp description: Manage Connection Authorization Policies (CAP) on a Remote Desktop Gateway server. name: win-rds-cap - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the resource authorization policy. name: name required: true - auto: PREDEFINED defaultValue: present description: |- The state of resource authorization policy. If `absent` will ensure the policy is removed. If `present` will ensure the policy is configured and exists. If `enabled` will ensure the policy is configured, exists and enabled. If `disabled` will ensure the policy is configured, exists, but disabled. name: state predefined: - absent - disabled - enabled - present - description: Optional description of the resource authorization policy. name: description - description: |- List of user groups that are associated with this resource authorization policy (RAP). A user must belong to one of these groups to access the RD Gateway server. Required when a new RAP is created. isArray: true name: user_groups - description: |- List of port numbers through which connections are allowed for this policy. To allow connections through any port, specify 'any'. isArray: true name: allowed_ports - auto: PREDEFINED description: |- The computer group type: `rdg_group`: RD Gateway-managed group `ad_network_resource_group`: Active Directory Domain Services network resource group `allow_any`: Allow users to connect to any network resource. name: computer_group_type predefined: - rdg_group - ad_network_resource_group - allow_any - description: |- The computer group name that is associated with this resource authorization policy (RAP). This is required when `computer_group_type` is `rdg_group` or `ad_network_resource_group`. name: computer_group description: Manage Resource Authorization Policies (RAP) on a Remote Desktop Gateway server. name: win-rds-rap - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Certificate hash (thumbprint) for the Remote Desktop Gateway server. The certificate hash is the unique identifier for the certificate. name: certificate_hash - description: |- The maximum number of connections allowed. If set to `0`, no new connections are allowed. If set to `-1`, the number of connections is unlimited. name: max_connections - auto: PREDEFINED description: |- Specifies whether to use SSL Bridging. `none`: no SSL bridging. `https_http`: HTTPS-HTTP bridging. `https_https`: HTTPS-HTTPS bridging. name: ssl_bridging predefined: - https_http - https_https - none - description: If enabled, only clients that support logon messages and administrator messages can connect. name: enable_only_messaging_capable_clients description: Manage main settings of a Remote Desktop Gateway server. name: win-rds-settings - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: "2" description: Seconds to wait before reboot. Passed as a parameter to the reboot command. name: pre_reboot_delay - defaultValue: "0" description: |- Seconds to wait after the reboot command was successful before attempting to validate the system rebooted successfully. This is useful if you want wait for something to settle despite your connection already working. name: post_reboot_delay - defaultValue: "600" description: |- Maximum seconds to wait for shutdown to occur. Increase this timeout for very slow hardware, large update applications, etc. This option has been removed since Ansible 2.5 as the win-reboot behavior has changed. name: shutdown_timeout - defaultValue: "600" description: |- Maximum seconds to wait for machine to re-appear on the network and respond to a test command. This timeout is evaluated separately for both reboot verification and test command success so maximum clock time is actually twice this value. name: reboot_timeout - defaultValue: "5" description: Maximum seconds to wait for a single successful TCP connection to the WinRM endpoint before trying again. name: connect_timeout - defaultValue: whoami description: Command to expect success for to determine the machine is ready for management. name: test_command - defaultValue: Reboot initiated by Ansible description: Message to display to users. name: msg description: Reboot a windows machine. name: win-reboot - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The full registry key path including the hive to search for. name: path required: true - description: |- The registry property name to get information for, the return json will not include the sub_keys and properties entries for the `key` specified. Set to an empty string to target the registry key's `(Default`) property value. name: name description: Get information about Windows registry keys. name: win-reg-stat - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Name of the registry path. Should be in one of the following registry hives: HKCC, HKCR, HKCU, HKLM, HKU. name: path required: true - description: |- Name of the registry entry in the above `path` parameters. If not provided, or empty then the '(Default)' property for the key will be used. name: name - description: |- Value of the registry entry `name` in `path`. If not specified then the value for the property will be null for the corresponding `type`. Binary and None data should be expressed in a yaml byte array or as comma separated hex values. An easy way to generate this is to run `regedit.exe` and use the `export` option to save the registry values to a file. In the exported file, binary value will look like `hex:be,ef,be,ef`, the `hex:` prefix is optional. DWORD and QWORD values should either be represented as a decimal number or a hex value. Multistring values should be passed in as a list. See the examples for more details on how to format this data. name: data - auto: PREDEFINED defaultValue: string description: The registry value data type. name: type predefined: - binary - dword - expandstring - multistring - string - qword - auto: PREDEFINED defaultValue: present description: The state of the registry entry. name: state predefined: - absent - present - defaultValue: "True" description: |- When `state` is 'absent' then this will delete the entire key. If `no` then it will only clear out the '(Default)' property for that key. name: delete_key - description: |- A path to a hive key like C:\Users\Default\NTUSER.DAT to load in the registry. This hive is loaded under the HKLM:\ANSIBLE key which can then be used in `name` like any other path. This can be used to load the default user profile registry hive or any other hive saved as a file. Using this function requires the user to have the `SeRestorePrivilege` and `SeBackupPrivilege` privileges enabled. name: hive description: Add, change, or remove registry keys and values. name: win-regedit - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The location to set for the current user, see `https://msdn.microsoft.com/en-us/library/dd374073.aspx` for a list of GeoIDs you can use and what location it relates to. This needs to be set if `format` or `unicode_language` is not set. name: location - description: |- The language format to set for the current user, see `https://msdn.microsoft.com/en-us/library/system.globalization.cultureinfo.aspx` for a list of culture names to use. This needs to be set if `location` or `unicode_language` is not set. name: format - description: |- The unicode language format to set for all users, see `https://msdn.microsoft.com/en-us/library/system.globalization.cultureinfo.aspx` for a list of culture names to use. This needs to be set if `location` or `format` is not set. After setting this value a reboot is required for it to take effect. name: unicode_language - defaultValue: "False" description: This will copy the current format and location values to new user profiles and the welcome screen. This will only run if `location`, `format` or `unicode_language` has resulted in a change. If this process runs then it will always result in a change. name: copy_settings description: Set the region and format settings. name: win-region - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The full path including file name to the registry file on the remote machine to be merged. name: path required: true - description: The parent key to use when comparing the contents of the registry to the contents of the file. Needs to be in HKLM or HKCU part of registry. Use a PS-Drive style path for example HKLM:\SOFTWARE not HKEY_LOCAL_MACHINE\SOFTWARE If not supplied, or the registry key is not found, no comparison will be made, and the module will report changed. name: compare_key description: Merges the contents of a registry file into the Windows registry. name: win-regmerge - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Source file/directory to sync. name: src required: true - description: Destination file/directory to sync (Will receive contents of src). name: dest required: true - defaultValue: "False" description: |- Includes all subdirectories (Toggles the `/e` flag to RoboCopy). If `flags` is set, this will be ignored. name: recurse - defaultValue: "False" description: |- Deletes any files/directories found in the destination that do not exist in the source. Toggles the `/purge` flag to RoboCopy. If `flags` is set, this will be ignored. name: purge - description: |- Directly supply Robocopy flags. If set, `purge` and `recurse` will be ignored. name: flags description: Synchronizes the contents of two directories using Robocopy. name: win-robocopy - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Destination IP address in CIDR format (ip address/prefix length). name: destination required: true - description: |- The gateway used by the static route. If `gateway` is not provided it will be set to `0.0.0.0`. name: gateway - defaultValue: "1" description: Metric used by the static route. name: metric - auto: PREDEFINED defaultValue: present description: |- If `absent`, it removes a network static route. If `present`, it adds a network static route. name: state predefined: - absent - present description: Add or remove a static route. name: win-route - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The text to be spoken. Use either `msg` or `msg_file`. Optional so that you can use this module just to play sounds. name: msg - description: |- Full path to a windows format text file containing the text to be spoken. Use either `msg` or `msg_file`. Optional so that you can use this module just to play sounds. name: msg_file - description: |- Which voice to use. See notes for how to discover installed voices. If the requested voice is not available the default voice will be used. Example voice names from Windows 10 are `Microsoft Zira Desktop` and `Microsoft Hazel Desktop`. name: voice - defaultValue: "0" description: |- How fast or slow to speak the text. Must be an integer value in the range -10 to 10. -10 is slowest, 10 is fastest. name: speech_speed - description: |- Full path to a `.wav` file containing a sound to play before the text is spoken. Useful on conference calls to alert other speakers that ansible has something to say. name: start_sound_path - description: |- Full path to a `.wav` file containing a sound to play after the text has been spoken. Useful on conference calls to alert other speakers that ansible has finished speaking. name: end_sound_path description: Text to speech module for Windows to speak messages and optionally play sounds. name: win-say - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The name of the scheduled task without the path. name: name required: true - defaultValue: \ description: |- Task folder in which this task will be stored. Will create the folder when `state=present` and the folder does not already exist. Will remove the folder when `state=absent` and there are no tasks left in the folder. name: path - auto: PREDEFINED defaultValue: present description: |- When `state=present` will ensure the task exists. When `state=absent` will ensure the task does not exist. name: state predefined: - absent - present - description: |- A list of action to configure for the task. See suboptions for details on how to construct each list entry. When creating a task there MUST be at least one action but when deleting a task this can be a null or an empty list. The ordering of this list is important, the module will ensure the order is kept when modifying the task. This module only supports the `ExecAction` type but can still delete the older legacy types. isArray: true name: actions - description: |- A list of triggers to configure for the task. See suboptions for details on how to construct each list entry. The ordering of this list is important, the module will ensure the order is kept when modifying the task. There are multiple types of triggers, see `https://msdn.microsoft.com/en-us/library/windows/desktop/aa383868.aspx` for a list of trigger types and their options. The suboption options listed below are not required for all trigger types, read the description for more details. isArray: true name: triggers - description: The name of the user/group that is displayed in the Task Scheduler UI. name: display_name - description: |- The group that will run the task. `group` and `username` are exclusive to each other and cannot be set at the same time. `logon_type` can either be not set or equal `group`. name: group - auto: PREDEFINED description: |- The logon method that the task will run with. `password` means the password will be stored and the task has access to network resources. `s4u` means the existing token will be used to run the task and no password will be stored with the task. Means no network or encrypted files access. `interactive_token` means the user must already be logged on interactively and will run in an existing interactive session. `group` means that the task will run as a group. `service_account` means that a service account like System, Local Service or Network Service will run the task. name: logon_type predefined: - none - password - s4u - interactive_token - group - service_account - token_or_password - auto: PREDEFINED description: |- The level of user rights used to run the task. If not specified the task will be created with limited rights. name: run_level predefined: - limited - highest - description: |- The user to run the scheduled task as. Will default to the current user under an interactive token if not specified during creation. name: username - description: |- The password for the user account to run the scheduled task as. This is required when running a task without the user being logged in, excluding the builtin service accounts and Group Managed Service Accounts (gMSA). If set, will always result in a change unless `update_password` is set to `no` and no other changes are required for the service. name: password - defaultValue: "True" description: |- Whether to update the password even when not other changes have occurred. When `yes` will always result in a change when executing the module. name: update_password - description: The author of the task. name: author - description: The date when the task was registered. name: date - description: The description of the task. name: description - description: The source of the task. name: source - description: The version number of the task. name: version - description: Whether the task can be started by using either the Run command or the Context menu. name: allow_demand_start - description: Whether the task can be terminated by using TerminateProcess. name: allow_hard_terminate - auto: PREDEFINED description: |- The integer value with indicates which version of Task Scheduler a task is compatible with. `0` means the task is compatible with the AT command. `1` means the task is compatible with Task Scheduler 1.0. `2` means the task is compatible with Task Scheduler 2.0. name: compatibility predefined: - "0" - "1" - "2" - description: |- The amount of time that the Task Scheduler will wait before deleting the task after it expires. A task expires after the end_boundary has been exceeded for all triggers associated with the task. This is in the ISO 8601 Duration format `P[n]Y[n]M[n]DT[n]H[n]M[n]S`. name: delete_expired_task_after - description: Whether the task will not be started if the computer is running on battery power. name: disallow_start_if_on_batteries - description: Whether the task is enabled, the task can only run when `yes`. name: enabled - description: |- The amount of time allowed to complete the task. When not set, the time limit is infinite. This is in the ISO 8601 Duration format `P[n]Y[n]M[n]DT[n]H[n]M[n]S`. name: execution_time_limit - description: Whether the task will be hidden in the UI. name: hidden - auto: PREDEFINED description: |- An integer that indicates the behaviour when starting a task that is already running. `0` will start a new instance in parallel with existing instances of that task. `1` will wait until other instances of that task to finish running before starting itself. `2` will not start a new instance if another is running. `3` will stop other instances of the task and start the new one. name: multiple_instances predefined: - "0" - "1" - "2" - "3" - description: |- The priority level (0-10) of the task. When creating a new task the default is `7`. See `https://msdn.microsoft.com/en-us/library/windows/desktop/aa383512.aspx` for details on the priority levels. name: priority - description: The number of times that the Task Scheduler will attempt to restart the task. name: restart_count - description: |- How long the Task Scheduler will attempt to restart the task. If this is set then `restart_count` must also be set. The maximum allowed time is 31 days. The minimum allowed time is 1 minute. This is in the ISO 8601 Duration format `P[n]Y[n]M[n]DT[n]H[n]M[n]S`. name: restart_interval - description: Whether the task will run the task only if the computer is in an idle state. name: run_only_if_idle - description: Whether the task will run only when a network is available. name: run_only_if_network_available - description: Whether the task can start at any time after its scheduled time has passed. name: start_when_available - description: Whether the task will be stopped if the computer begins to run on battery power. name: stop_if_going_on_batteries - description: Whether the task will wake the computer when it is time to run the task. name: wake_to_run description: Manage scheduled tasks. name: win-scheduled-task - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: \ description: The folder path where the task lives. name: path - description: |- The name of the scheduled task to get information for. If `name` is set and exists, will return information on the task itself. name: name description: Get information about Windows Scheduled Tasks. name: win-scheduled-task-stat outputs: - contextPath: MicrosoftWindows.principal.display_name description: The name of the user/group that is displayed in the Task Scheduler UI. type: string - contextPath: MicrosoftWindows.principal.group_id description: The group that will run the task. type: string - contextPath: MicrosoftWindows.principal.id description: The ID for the principal. type: string - contextPath: MicrosoftWindows.principal.logon_type description: The logon method that the task will run with. type: string - contextPath: MicrosoftWindows.principal.run_level description: The level of user rights used to run the task. type: string - contextPath: MicrosoftWindows.principal.user_id description: The user that will run the task. type: string - contextPath: MicrosoftWindows.registration_info.author description: The author os the task. type: string - contextPath: MicrosoftWindows.registration_info.date description: The date when the task was register. type: string - contextPath: MicrosoftWindows.registration_info.description description: The description of the task. type: string - contextPath: MicrosoftWindows.registration_info.documentation description: The documentation of the task. type: string - contextPath: MicrosoftWindows.registration_info.security_descriptor description: The security descriptor of the task. type: string - contextPath: MicrosoftWindows.registration_info.source description: The source of the task. type: string - contextPath: MicrosoftWindows.registration_info.uri description: The URI/path of the task. type: string - contextPath: MicrosoftWindows.registration_info.version description: The version of the task. type: string - contextPath: MicrosoftWindows.settings.allow_demand_start description: Whether the task can be started by using either the Run command of the Context menu. type: boolean - contextPath: MicrosoftWindows.settings.allow_hard_terminate description: Whether the task can terminated by using TerminateProcess. type: boolean - contextPath: MicrosoftWindows.settings.compatibility description: The compatibility level of the task. type: number - contextPath: MicrosoftWindows.settings.delete_expired_task_after description: The amount of time the Task Scheduler will wait before deleting the task after it expires. type: string - contextPath: MicrosoftWindows.settings.disallow_start_if_on_batteries description: Whether the task will not be started if the computer is running on battery power. type: boolean - contextPath: MicrosoftWindows.settings.disallow_start_on_remote_app_session description: Whether the task will not be started when in a remote app session. type: boolean - contextPath: MicrosoftWindows.settings.enabled description: Whether the task is enabled. type: boolean - contextPath: MicrosoftWindows.settings.execution_time_limit description: The amount of time allowed to complete the task. type: string - contextPath: MicrosoftWindows.settings.hidden description: Whether the task is hidden in the UI. type: boolean - contextPath: MicrosoftWindows.settings.idle_settings description: The idle settings of the task. - contextPath: MicrosoftWindows.settings.maintenance_settings description: The maintenance settings of the task. type: string - contextPath: MicrosoftWindows.settings.mulitple_instances description: Indicates the behaviour when starting a task that is already running. type: number - contextPath: MicrosoftWindows.settings.network_settings description: The network settings of the task. - contextPath: MicrosoftWindows.settings.priority description: The priority level of the task. type: number - contextPath: MicrosoftWindows.settings.restart_count description: The number of times that the task will attempt to restart on failures. type: number - contextPath: MicrosoftWindows.settings.restart_interval description: How long the Task Scheduler will attempt to restart the task. type: string - contextPath: MicrosoftWindows.settings.run_only_id_idle description: Whether the task will run if the computer is in an idle state. type: boolean - contextPath: MicrosoftWindows.settings.run_only_if_network_available description: Whether the task will run only when a network is available. type: boolean - contextPath: MicrosoftWindows.settings.start_when_available description: Whether the task can start at any time after its scheduled time has passed. type: boolean - contextPath: MicrosoftWindows.settings.stop_if_going_on_batteries description: Whether the task will be stopped if the computer begins to run on battery power. type: boolean - contextPath: MicrosoftWindows.settings.use_unified_scheduling_engine description: Whether the task will use the unified scheduling engine. type: boolean - contextPath: MicrosoftWindows.settings.volatile description: Whether the task is volatile. type: boolean - contextPath: MicrosoftWindows.settings.wake_to_run description: Whether the task will wake the computer when it is time to run the task. type: boolean - contextPath: MicrosoftWindows.state.last_run_time description: The time the registered task was last run. type: string - contextPath: MicrosoftWindows.state.last_task_result description: The results that were returned the last time the task was run. type: number - contextPath: MicrosoftWindows.state.next_run_time description: The time when the task is next scheduled to run. type: string - contextPath: MicrosoftWindows.state.number_of_missed_runs description: The number of times a task has missed a scheduled run. type: number - contextPath: MicrosoftWindows.state.status description: The status of the task, whether it is running, stopped, etc. type: string - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The ini section the key exists in. If the section does not exist then the module will return an error. Example sections to use are 'Account Policies', 'Local Policies', 'Event Log', 'Restricted Groups', 'System Services', 'Registry' and 'File System' If wanting to edit the `Privilege Rights` section, use the `win_user_right` module instead. name: section required: true - description: |- The ini key of the section or policy name to modify. The module will return an error if this key is invalid. name: key required: true - description: |- The value for the ini key or policy name. If the key takes in a boolean value then 0 = False and 1 = True. name: value required: true description: Change local security policy settings. name: win-security-policy - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- A list of service dependencies to set for this particular service. This should be a list of service names and not the display name of the service. This works by `dependency_action` to either add/remove or set the services in this list. isArray: true name: dependencies - auto: PREDEFINED defaultValue: set description: |- Used in conjunction with `dependency` to either add the dependencies to the existing service dependencies. Remove the dependencies to the existing dependencies. Set the dependencies to only the values in the list replacing the existing dependencies. name: dependency_action predefined: - add - remove - set - defaultValue: "False" description: |- Whether to allow the service user to interact with the desktop. This should only be set to `yes` when using the `LocalSystem` username. name: desktop_interact - description: The description to set for the service. name: description - description: The display name to set for the service. name: display_name - defaultValue: "False" description: |- If `yes`, stopping or restarting a service with dependent services will force the dependent services to stop or restart also. If `no`, stopping or restarting a service with dependent services may fail. name: force_dependent_services - description: |- Name of the service. If only the name parameter is specified, the module will report on whether the service exists or not without making any changes. name: name required: true - description: The path to the executable to set for the service. name: path - description: |- The password to set the service to start as. This and the `username` argument must be supplied together. If specifying `LocalSystem`, `NetworkService` or `LocalService` this field must be an empty string and not null. name: password - auto: PREDEFINED description: |- Set the startup type for the service. A newly created service will default to `auto`. `delayed` added in Ansible 2.3. name: start_mode predefined: - auto - delayed - disabled - manual - auto: PREDEFINED description: |- The desired state of the service. `started`/`stopped`/`absent`/`paused` are idempotent actions that will not run commands unless necessary. `restarted` will always bounce the service. `absent` was added in Ansible 2.3 `paused` was added in Ansible 2.4 Only services that support the paused state can be paused, you can check the return value `can_pause_and_continue`. You can only pause a service that is already started. A newly created service will default to `stopped`. name: state predefined: - absent - paused - started - stopped - restarted - description: |- The username to set the service to start as. This and the `password` argument must be supplied together when using a local or domain account. Set to `LocalSystem` to use the SYSTEM account. A newly created service will default to `LocalSystem`. If using a custom user account, it must have the `SeServiceLogonRight` granted to be able to start up. You can use the `win_user_right` module to grant this user right for you. name: username description: Manage and query Windows services. name: win-service - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Share name. name: name required: true - description: Share directory. name: path required: true - auto: PREDEFINED defaultValue: present description: Specify whether to add `present` or remove `absent` the specified share. name: state predefined: - absent - present - description: Share description. name: description - defaultValue: "False" description: Specify whether to allow or deny file listing, in case user has no permission on share. Also known as Access-Based Enumeration. name: list - description: Specify user list that should get read access on share, separated by comma. name: read - description: Specify user list that should get read and write access on share, separated by comma. name: change - description: Specify user list that should get full access on share, separated by comma. name: full - description: Specify user list that should get no access, regardless of implied access on share, separated by comma. name: deny - auto: PREDEFINED defaultValue: Manual description: Set the CachingMode for this share. name: caching_mode predefined: - BranchCache - Documents - Manual - None - Programs - Unknown - defaultValue: "False" description: Sets whether to encrypt the traffic to the share or not. name: encrypt description: Manage Windows shares. name: win-share - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Executable or URL the shortcut points to. The executable needs to be in your PATH, or has to be an absolute path to the executable. name: src - description: |- Description for the shortcut. This is usually shown when hoovering the icon. name: description - description: |- Destination file for the shortcuting file. File name should have a `.lnk` or `.url` extension. name: dest required: true - description: |- Additional arguments for the executable defined in `src`. Was originally just `args` but renamed in Ansible 2.8. name: arguments - description: Working directory for executable defined in `src`. name: directory - description: |- Icon used for the shortcut. File name should have a `.ico` extension. The file name is followed by a comma and the number in the library file (.dll) or use 0 for an image file. name: icon - description: |- Key combination for the shortcut. This is a combination of one or more modifiers and a key. Possible modifiers are Alt, Ctrl, Shift, Ext. Possible keys are [A-Z] and [0-9]. name: hotkey - auto: PREDEFINED description: Influences how the application is displayed when it is launched. name: windowstyle predefined: - maximized - minimized - normal - auto: PREDEFINED defaultValue: present description: |- When `absent`, removes the shortcut if it exists. When `present`, creates or updates the shortcut. name: state predefined: - absent - present - defaultValue: "False" description: When `src` is an executable, this can control whether the shortcut will be opened as an administrator or not. name: run_as_admin description: Manage shortcuts on Windows. name: win-shortcut - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The list of permitted SNMP managers. isArray: true name: permitted_managers - description: The list of read-only SNMP community strings. isArray: true name: community_strings - auto: PREDEFINED defaultValue: set description: |- `add` will add new SNMP community strings and/or SNMP managers `set` will replace SNMP community strings and/or SNMP managers. An empty list for either `community_strings` or `permitted_managers` will result in the respective lists being removed entirely. `remove` will remove SNMP community strings and/or SNMP managers. name: action predefined: - add - set - remove description: Configures the Windows SNMP service. name: win-snmp - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The full path of the file/object to get the facts of; both forward and back slashes are accepted. name: path required: true - defaultValue: "False" description: |- Whether to return the checksum sum of the file. Between Ansible 1.9 and Ansible 2.2 this is no longer an MD5, but a SHA1 instead. As of Ansible 2.3 this is back to an MD5. Will return None if host is unable to use specified algorithm. The default of this option changed from `yes` to `no` in Ansible 2.5 and will be removed altogether in Ansible 2.9. Use `get_checksum=yes` with `checksum_algorithm=md5` to return an md5 hash under the `checksum` return value. name: get_md5 - defaultValue: "True" description: Whether to return a checksum of the file (default sha1). name: get_checksum - auto: PREDEFINED defaultValue: sha1 description: |- Algorithm to determine checksum of file. Will throw an error if the host is unable to use specified algorithm. name: checksum_algorithm predefined: - md5 - sha1 - sha256 - sha384 - sha512 - defaultValue: "False" description: |- Whether to follow symlinks or junction points. In the case of `path` pointing to another link, then that will be followed until no more links are found. name: follow description: Get information about Windows files. name: win-stat outputs: - contextPath: MicrosoftWindows.stat.attributes description: Attributes of the file at path in raw form. type: string - contextPath: MicrosoftWindows.stat.checksum description: The checksum of a file based on checksum_algorithm specified. type: string - contextPath: MicrosoftWindows.stat.creationtime description: The create time of the file represented in seconds since epoch. - contextPath: MicrosoftWindows.stat.exists description: If the path exists or not. type: boolean - contextPath: MicrosoftWindows.stat.extension description: The extension of the file at path. type: string - contextPath: MicrosoftWindows.stat.filename description: The name of the file (without path). type: string - contextPath: MicrosoftWindows.stat.hlnk_targets description: List of other files pointing to the same file (hard links), excludes the current file. - contextPath: MicrosoftWindows.stat.isarchive description: If the path is ready for archiving or not. type: boolean - contextPath: MicrosoftWindows.stat.isdir description: If the path is a directory or not. type: boolean - contextPath: MicrosoftWindows.stat.ishidden description: If the path is hidden or not. type: boolean - contextPath: MicrosoftWindows.stat.isjunction description: If the path is a junction point or not. type: boolean - contextPath: MicrosoftWindows.stat.islnk description: If the path is a symbolic link or not. type: boolean - contextPath: MicrosoftWindows.stat.isreadonly description: If the path is read only or not. type: boolean - contextPath: MicrosoftWindows.stat.isreg description: If the path is a regular file. type: boolean - contextPath: MicrosoftWindows.stat.isshared description: If the path is shared or not. type: boolean - contextPath: MicrosoftWindows.stat.lastaccesstime description: The last access time of the file represented in seconds since epoch. - contextPath: MicrosoftWindows.stat.lastwritetime description: The last modification time of the file represented in seconds since epoch. - contextPath: MicrosoftWindows.stat.lnk_source description: Target of the symlink normalized for the remote filesystem. type: string - contextPath: MicrosoftWindows.stat.lnk_target description: Target of the symlink. Note that relative paths remain relative. type: string - contextPath: MicrosoftWindows.stat.md5 description: The MD5 checksum of a file (Between Ansible 1.9 and Ansible 2.2 this was returned as a SHA1 hash), will be removed in Ansible 2.9. type: string - contextPath: MicrosoftWindows.stat.nlink description: Number of links to the file (hard links). type: number - contextPath: MicrosoftWindows.stat.owner description: The owner of the file. type: string - contextPath: MicrosoftWindows.stat.path description: The full absolute path to the file. type: string - contextPath: MicrosoftWindows.stat.sharename description: The name of share if folder is shared. type: string - contextPath: MicrosoftWindows.stat.size description: The size in bytes of a file or folder. type: number - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - auto: PREDEFINED defaultValue: file description: Whether to create file or directory. name: state predefined: - directory - file - defaultValue: '%TEMP%' description: |- Location where temporary file or directory should be created. If path is not specified default system temporary directory (%TEMP%) will be used. name: path - defaultValue: ansible. description: Prefix of file/directory name created by module. name: prefix - description: Suffix of file/directory name created by module. name: suffix description: Creates temporary files and directories. name: win-tempfile - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: "False" description: |- Determine whether a backup should be created. When set to `yes`, create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly. name: backup - auto: PREDEFINED defaultValue: \r\n description: Specify the newline sequence to use for templating files. name: newline_sequence predefined: - \n - \r - \r\n - defaultValue: "True" description: |- Determine when the file is being transferred if the destination already exists. When set to `yes`, replace the remote file when contents are different than the source. When set to `no`, the file will only be transferred if the destination does not exist. name: force - description: |- Path of a Jinja2 formatted template on the Ansible controller. This can be a relative or an absolute path. The file must be encoded with `utf-8` but `output_encoding` can be used to control the encoding of the output template. name: src required: true - description: Location to render the template to on the remote machine. name: dest required: true - defaultValue: '{%' description: The string marking the beginning of a block. name: block_start_string - defaultValue: '%}' description: The string marking the end of a block. name: block_end_string - defaultValue: '{{' description: The string marking the beginning of a print statement. name: variable_start_string - defaultValue: '}}' description: The string marking the end of a print statement. name: variable_end_string - defaultValue: "True" description: |- Determine when newlines should be removed from blocks. When set to `yes` the first newline after a block is removed (block, not variable tag!). name: trim_blocks - defaultValue: "False" description: |- Determine when leading spaces and tabs should be stripped. When set to `yes` leading spaces and tabs are stripped from the start of a line to a block. This functionality requires Jinja 2.7 or newer. name: lstrip_blocks - defaultValue: utf-8 description: |- Overrides the encoding used to write the template file defined by `dest`. It defaults to `utf-8`, but any encoding supported by python can be used. The source template file must always be encoded using `utf-8`, for homogeneity. name: output_encoding description: Template a file out to a remote server. name: win-template - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Timezone to set to. Example: Central Standard Time. name: timezone required: true description: Sets Windows machine timezone. name: win-timezone - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: "45" description: How long in seconds before the notification expires. name: expire - defaultValue: Powershell description: Which notification group to add the notification to. name: group - defaultValue: Hello, World! description: |- The message to appear inside the notification. May include \n to format the message to appear within the Action Center. name: msg - defaultValue: "True" description: If `no`, the notification will not pop up and will only appear in the Action Center. name: popup - defaultValue: Ansible description: The tag to add to the notification. name: tag - defaultValue: Notification HH:mm description: The notification title, which appears in the pop up.. name: title description: Sends Toast windows notification to logged in users on Windows 10 or later hosts. name: win-toast - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: File to be unzipped (provide absolute path). name: src required: true - description: Destination of zip file (provide absolute path of directory). If it does not exist, the directory will be created. name: dest required: true - defaultValue: "False" description: Remove the zip file, after unzipping. name: delete_archive - defaultValue: "False" description: |- Recursively expand zipped files within the src file. Setting to a value of `yes` requires the PSCX module to be installed. name: recurse - description: If this file or directory exists the specified src will not be extracted. name: creates description: Unzips compressed files and archives on the Windows node. name: win-unzip - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- A list of update titles or KB numbers that can be used to specify which updates are to be excluded from installation. If an available update does match one of the entries, then it is skipped and not installed. Each entry can either be the KB article or Update title as a regex according to the PowerShell regex rules. isArray: true name: blacklist - defaultValue: '[''CriticalUpdates'', ''SecurityUpdates'', ''UpdateRollups'']' description: |- A scalar or list of categories to install updates from. To get the list of categories, run the module with `state=searched`. The category must be the full category string, but is case insensitive. Some possible categories are Application, Connectors, Critical Updates, Definition Updates, Developer Kits, Feature Packs, Guidance, Security Updates, Service Packs, Tools, Update Rollups and Updates. isArray: true name: category_names - defaultValue: "False" description: |- Ansible will automatically reboot the remote host if it is required and continue to install updates after the reboot. This can be used instead of using a `win-reboot` task after this one and ensures all updates for that category is installed in one go. Async does not work when `reboot=yes`. name: reboot - defaultValue: "1200" description: |- The time in seconds to wait until the host is back online from a reboot. This is only used if `reboot=yes` and a reboot is required. name: reboot_timeout - auto: PREDEFINED defaultValue: default description: |- Defines the Windows Update source catalog. `default` Use the default search source. For many systems default is set to the Microsoft Windows Update catalog. Systems participating in Windows Server Update Services (WSUS), Systems Center Configuration Manager (SCCM), or similar corporate update server environments may default to those managed update sources instead of the Windows Update catalog. `managed_server` Use a managed server catalog. For environments utilizing Windows Server Update Services (WSUS), Systems Center Configuration Manager (SCCM), or similar corporate update servers, this option selects the defined corporate update source. `windows_update` Use the Microsoft Windows Update catalog. name: server_selection predefined: - default - managed_server - windows_update - auto: PREDEFINED defaultValue: installed description: |- Controls whether found updates are downloaded or installed or listed This module also supports Ansible check mode, which has the same effect as setting state=searched. name: state predefined: - installed - searched - downloaded - description: If set, `win-updates` will append update progress to the specified file. The directory must already exist. name: log_path - description: |- A list of update titles or KB numbers that can be used to specify which updates are to be searched or installed. If an available update does not match one of the entries, then it is skipped and not installed. Each entry can either be the KB article or Update title as a regex according to the PowerShell regex rules. The allow list is only validated on updates that were found based on `category_names`. It will not force the module to install an update if it was not in the category specified. isArray: true name: whitelist - defaultValue: "False" description: |- Will not auto elevate the remote process with `become` and use a scheduled task instead. Set this to `yes` when using this module with async on Server 2008, 2008 R2, or Windows 7, or on Server 2008 that is not authenticated with basic or credssp. Can also be set to `yes` on newer hosts where become does not work due to further privilege restrictions from the OS defaults. name: use_scheduled_task description: Download and install Windows updates. name: win-updates outputs: - contextPath: MicrosoftWindows.updates.title description: Display name. type: string - contextPath: MicrosoftWindows.updates.kb description: A list of KB article IDs that apply to the update. - contextPath: MicrosoftWindows.updates.id description: Internal Windows Update GUID. type: string - contextPath: MicrosoftWindows.updates.installed description: Was the update successfully installed. type: boolean - contextPath: MicrosoftWindows.updates.categories description: A list of category strings for this update. - contextPath: MicrosoftWindows.updates.failure_hresult_code description: The HRESULT code from a failed update. type: boolean - contextPath: MicrosoftWindows.filtered_updates.filtered_reason description: The reason why this update was filtered. type: string - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Supports FTP, HTTP or HTTPS URLs in the form of (ftp|http|https)://host.domain:port/path. name: url required: true - defaultValue: GET description: The HTTP Method of the request or response. name: method - description: Sets the "Content-Type" header. name: content_type - description: The body of the HTTP request/response to the web service. name: body - description: Output the response body to a file. name: dest - description: A filename, when it already exists, this step will be skipped. name: creates - description: A filename, when it does not exist, this step will be skipped. name: removes - defaultValue: "False" description: Whether or not to return the body of the response as a "content" key in the dictionary result. If the reported Content-type is "application/json", then the JSON is additionally loaded into a key called `json` in the dictionary results. name: return_content - defaultValue: '[200]' description: |- A valid, numeric, HTTP status code that signifies success of the request. Can also be comma separated list of status codes. isArray: true name: status_code - description: |- The username to use for authentication. Was originally called `user` but was changed to `url_username` in Ansible 2.9. name: url_username - description: |- The password for `url_username`. Was originally called `password` but was changed to `url_password` in Ansible 2.9. name: url_password - auto: PREDEFINED defaultValue: safe description: |- Whether or the module should follow redirects. `all` will follow all redirect. `none` will not follow any redirect. `safe` will follow only "safe" redirects, where "safe" means that the client is only doing a `GET` or `HEAD` on the URI to which it is being redirected. name: follow_redirects predefined: - all - none - safe - defaultValue: "50" description: |- Specify how many times the module will redirect a connection to an alternative URI before the connection fails. If set to `0` or `follow_redirects` is set to `none`, or `safe` when not doing a `GET` or `HEAD` it prevents all redirection. name: maximum_redirection - description: |- The path to the client certificate (.pfx) that is used for X509 authentication. This path can either be the path to the `pfx` on the filesystem or the PowerShell certificate path `Cert:\CurrentUser\My\<thumbprint>`. The WinRM connection must be authenticated with `CredSSP` or `become` is used on the task if the certificate file is not password protected. Other authentication types can set `client_cert_password` when the cert is password protected. name: client_cert - description: The password for `client_cert` if the cert is password protected. name: client_cert_password - defaultValue: "True" description: If `no`, it will not use the proxy defined in IE for the current user. name: use_proxy - description: |- An explicit proxy to use for the request. By default, the request will use the IE defined proxy unless `use_proxy` is set to `no`. name: proxy_url - description: The username to use for proxy authentication. name: proxy_username - description: The password for `proxy_username`. name: proxy_password - description: |- Extra headers to set on the request. This should be a dictionary where the key is the header name and the value is the value for that header. isArray: true name: headers - defaultValue: ansible-httpget description: |- Header to identify as, generally appears in web server logs. This is set to the `User-Agent` header on a HTTP request. name: http_agent - defaultValue: "30" description: |- Specifies how long the request can be pending before it times out (in seconds). Set to `0` to specify an infinite timeout. name: timeout - defaultValue: "True" description: |- If `no`, SSL certificates will not be validated. This should only be used on personally controlled sites using self-signed certificates. name: validate_certs - defaultValue: "False" description: |- By default the authentication header is only sent when a webservice responses to an initial request with a 401 status. Since some basic auth services do not properly send a 401, logins will fail. This option forces the sending of the Basic authentication header upon the original request. name: force_basic_auth - defaultValue: "False" description: |- Uses the current user's credentials when authenticating with a server protected with `NTLM`, `Kerberos`, or `Negotiate` authentication. Sites that use `Basic` auth will still require explicit credentials through the `url_username` and `url_password` options. The module will only have access to the user's credentials if using `become` with a password, you are connecting with SSH using a password, or connecting with WinRM using `CredSSP` or `Kerberos with delegation`. If not using `become` or a different auth method to the ones stated above, there will be no default credentials available and no authentication will occur. name: use_default_credential - defaultValue: "False" description: |- Uses the current user's credentials when authenticating with a proxy host protected with `NTLM`, `Kerberos`, or `Negotiate` authentication. Proxies that use `Basic` auth will still require explicit credentials through the `proxy_username` and `proxy_password` options. The module will only have access to the user's credentials if using `become` with a password, you are connecting with SSH using a password, or connecting with WinRM using `CredSSP` or `Kerberos with delegation`. If not using `become` or a different auth method to the ones stated above, there will be no default credentials available and no proxy authentication will occur. name: proxy_use_default_credential description: Interacts with webservices. name: win-uri - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the user to create, remove or modify. name: name required: true - description: Full name of the user. name: fullname - description: Description of the user. name: description - description: Optionally set the user's password to this (plain text) value. name: password - auto: PREDEFINED defaultValue: always description: '`always` will update passwords if they differ. `on_create` will only set the password for newly created users.' name: update_password predefined: - always - on_create - description: |- `yes` will require the user to change their password at next login. `no` will clear the expired password flag. name: password_expired - description: |- `yes` will set the password to never expire. `no` will allow the password to expire. name: password_never_expires - description: |- `yes` will prevent the user from changing their password. `no` will allow the user to change their password. name: user_cannot_change_password - description: |- `yes` will disable the user account. `no` will clear the disabled flag. name: account_disabled - auto: PREDEFINED description: '`no` will unlock the user account if locked.' name: account_locked predefined: - "no" - description: |- Adds or removes the user from this comma-separated list of groups, depending on the value of `groups_action`. When `groups_action` is `replace` and `groups` is set to the empty string ('groups='), the user is removed from all groups. name: groups - auto: PREDEFINED defaultValue: replace description: |- If `add`, the user is added to each group in `groups` where not already a member. If `replace`, the user is added as a member of each group in `groups` and removed from any other groups. If `remove`, the user is removed from each group in `groups`. name: groups_action predefined: - add - replace - remove - auto: PREDEFINED defaultValue: present description: |- When `absent`, removes the user account if it exists. When `present`, creates or updates the user account. When `query` (new in 1.9), retrieves the user account details without making any changes. name: state predefined: - absent - present - query description: Manages local Windows user accounts. name: win-user compliantpolicies: - User Hard Remediation - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- Specifies the base name for the profile path. When `state` is `present` this is used to create the profile for `username` at a specific path within the profile directory. This cannot be used to specify a path outside of the profile directory but rather it specifies a folder(s) within this directory. If a profile for another user already exists at the same path, then a 3 digit incremental number is appended by Windows automatically. When `state` is `absent` and `username` is not set, then the module will remove all profiles that point to the profile path derived by this value. This is useful if the account no longer exists but the profile still remains. name: name - defaultValue: "False" description: |- When `state` is `absent` and the value for `name` matches multiple profiles the module will fail. Set this value to `yes` to force the module to delete all the profiles found. name: remove_multiple - auto: PREDEFINED defaultValue: present description: |- Will ensure the profile exists when set to `present`. When creating a profile the `username` option must be set to a valid account. Will remove the profile(s) when set to `absent`. When removing a profile either `username` must be set to a valid account, or `name` is set to the profile's base name. name: state predefined: - absent - present - description: |- The account name of security identifier (SID) for the profile. This must be set when `state` is `present` and must be a valid account or the SID of a valid account. When `state` is `absent` then this must still be a valid account number but the SID can be a deleted user's SID. name: username description: Manages the Windows user profiles. name: win-user-profile - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The name of the User Right as shown by the `Constant Name` value from `https://technet.microsoft.com/en-us/library/dd349804.aspx`. The module will return an error if the right is invalid. name: name required: true - description: |- A list of users or groups to add/remove on the User Right. These can be in the form DOMAIN\user-group, user-group@DOMAIN.COM for domain users/groups. For local users/groups it can be in the form user-group, .\user-group, SERVERNAME\user-group where SERVERNAME is the name of the remote server. You can also add special local accounts like SYSTEM and others. Can be set to an empty list with `action=set` to remove all accounts from the right. isArray: true name: users required: true - auto: PREDEFINED defaultValue: set description: |- `add` will add the users/groups to the existing right. `remove` will remove the users/groups from the existing right. `set` will replace the users/groups of the existing right. name: action predefined: - add - remove - set description: Manage Windows User Rights. name: win-user-right - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - defaultValue: "5" description: The maximum number of seconds to wait for a connection to happen before closing and retrying. name: connect_timeout - description: The number of seconds to wait before starting to poll. name: delay - description: The list of hosts or IPs to ignore when looking for active TCP connections when `state=drained`. isArray: true name: exclude_hosts - description: |- The path to a file on the filesystem to check. If `state` is present or started then it will wait until the file exists. If `state` is absent then it will wait until the file does not exist. name: path - description: The port number to poll on `host`. name: port - description: |- Can be used to match a string in a file. If `state` is present or started then it will wait until the regex matches. If `state` is absent then it will wait until the regex does not match. Defaults to a multiline regex. name: regex - defaultValue: "1" description: Number of seconds to sleep between checks. name: sleep - auto: PREDEFINED defaultValue: started description: |- When checking a port, `started` will ensure the port is open, `stopped` will check that is it closed and `drained` will check for active connections. When checking for a file or a search string `present` or `started` will ensure that the file or string is present, `absent` will check that the file or search string is absent or removed. name: state predefined: - absent - drained - present - started - stopped - defaultValue: "300" description: The maximum number of seconds to wait for. name: timeout description: Waits for a condition before continuing. name: win-wait-for - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: The name of the process(es) for which to wait. The name of the process(es) should not include the file extension suffix. isArray: true name: process_name_exact - description: RegEx pattern matching desired process(es). name: process_name_pattern - defaultValue: "1" description: |- Number of seconds to sleep between checks. Only applies when waiting for a process to start. Waiting for a process to start does not have a native non-polling mechanism. Waiting for a stop uses native PowerShell and does not require polling. name: sleep - defaultValue: "1" description: |- Minimum number of process matching the supplied pattern to satisfy `present` condition. Only applies to `present`. name: process_min_count - description: The PID of the process. name: pid - description: |- The owner of the process. Requires PowerShell version 4.0 or newer. name: owner - defaultValue: "0" description: Seconds to wait before checking processes. name: pre_wait_delay - defaultValue: "0" description: Seconds to wait after checking for processes. name: post_wait_delay - auto: PREDEFINED defaultValue: present description: |- When checking for a running process `present` will block execution until the process exists, or until the timeout has been reached. `absent` will block execution until the process no longer exists, or until the timeout has been reached. When waiting for `present`, the module will return changed only if the process was not present on the initial check but became present on subsequent checks. If, while waiting for `absent`, new processes matching the supplied pattern are started, these new processes will not be included in the action. name: state predefined: - absent - present - defaultValue: "300" description: The maximum number of seconds to wait for a for a process to start or stop before erroring out. name: timeout description: Waits for a process to exist or not exist before continuing. name: win-wait-for-process outputs: - contextPath: MicrosoftWindows.matched_processes.name description: The name of the matched process. type: string - contextPath: MicrosoftWindows.matched_processes.owner description: The owner of the matched process. type: string - contextPath: MicrosoftWindows.matched_processes.pid description: The PID of the matched process. type: number - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: MAC address to send Wake-on-LAN broadcast packet for. name: mac required: true - defaultValue: 255.255.255.255 description: Network broadcast address to use for broadcasting magic Wake-on-LAN packet. name: broadcast - defaultValue: "7" description: UDP port to use for magic Wake-on-LAN packet. name: port description: Send a magic Wake-on-LAN (WoL) broadcast packet. name: win-wakeonlan - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: Name of the package to be installed. name: name required: true description: Installs packages using Web Platform Installer command-line. name: win-webpicmd - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true description: Get information about the current user and process. name: win-whoami outputs: - contextPath: MicrosoftWindows.label.domain_name description: The domain name of the label SID. type: string - contextPath: MicrosoftWindows.label.sid description: The SID in string form. type: string - contextPath: MicrosoftWindows.label.account_name description: The account name of the label SID. type: string - contextPath: MicrosoftWindows.label.type description: The type of SID. type: string - contextPath: MicrosoftWindows.account.domain_name description: The domain name of the account SID. type: string - contextPath: MicrosoftWindows.account.sid description: The SID in string form. type: string - contextPath: MicrosoftWindows.account.account_name description: The account name of the account SID. type: string - contextPath: MicrosoftWindows.account.type description: The type of SID. type: string - arguments: - description: hostname or IP of target. Optionally the port can be specified using :PORT. If multiple targets are specified using an array, the integration will use the configured concurrency factor for high performance. isArray: true name: host required: true - description: |- The attribute name if the type is 'attribute'. Required if `type=attribute`. name: attribute - defaultValue: "False" description: When set to `yes`, return the number of nodes matched by `xpath`. name: count - defaultValue: "False" description: |- Determine whether a backup should be created. When set to `yes`, create a backup file including the timestamp information so you can get the original file back if you somehow clobbered it incorrectly. name: backup - description: The string representation of the XML fragment expected at xpath. Since ansible 2.9 not required when `state=absent`, or when `count=yes`. name: fragment - description: Path to the file to operate on. name: path required: true - auto: PREDEFINED defaultValue: present description: Set or remove the nodes (or attributes) matched by `xpath`. name: state predefined: - present - absent - auto: PREDEFINED defaultValue: element description: The type of XML node you are working with. name: type predefined: - attribute - element - text required: true - description: Xpath to select the node or nodes to operate on. name: xpath required: true description: Manages XML file content on Windows hosts. name: win-xml dockerimage: demisto/ansible-runner:1.0.0.3456168 script: '' subtype: python3 type: python fromversion: 6.0.0 tests: - No tests (auto formatted) deprecated: true