Retrieves an endpoint's ActiveDirectory configuration by its graph object id: whether Active Directory is enabled, the domain and DNS forest, the domain controller's name and address, the directory status, and the endpoint's domain role, on Windows, macOS, and Linux. Each Endpoint has at most one, also reachable through its activeDirectory field; find them across endpoints with graphSearch on the ACTIVE_DIRECTORY object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.
Response
Returns an ActiveDirectoryPayload!
Arguments
| Name | Description |
|---|---|
id - ID!
|
The ActiveDirectory identifier. |
mockOptions - MockDataInput
|
Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] } |
Example
Query
query activeDirectory(
$id: ID!,
$mockOptions: MockDataInput
) {
activeDirectory(
id: $id,
mockOptions: $mockOptions
) {
node {
id
orgId
seen {
...SeenOnlineFragment
}
objectType
objectTypeLabel
displayName
firstSeen
lastSeen
createdAt
updatedAt
snapshotInfo {
...GraphObjectSnapshotInfoFragment
}
endpoint {
...EndpointFragment
}
enabled
name
domainControllerName
domainControllerIpAddress {
...IpAddressFragment
}
domainControllerAddressType
dnsForestName
status
role
osSpecific {
... on ActiveDirectoryWindows {
...ActiveDirectoryWindowsFragment
}
... on ActiveDirectoryMacOS {
...ActiveDirectoryMacOSFragment
}
... on ActiveDirectoryLinux {
...ActiveDirectoryLinuxFragment
}
}
findings {
...FindingsPayloadFragment
}
issues {
...IssuesPayloadFragment
}
issuesSummary {
...IssuesSummaryFragment
}
}
}
}
Variables
{
"id": "4",
"mockOptions": MockDataInput
}
Response
{"data": {"activeDirectory": {"node": ActiveDirectory}}}