Endpoint configuration · GraphQL query

activeDirectory query

Retrieves an endpoint's ActiveDirectory configuration by its graph object id: whether Active Directory is enabled, the domain and DNS forest, the domain controller's name and address, the directory status, and the endpoint's domain role, on Windows, macOS, and Linux. Each Endpoint has at most one, also reachable through its activeDirectory field; find them across endpoints with graphSearch on the ACTIVE_DIRECTORY object type. Returns a not-found error when no object has the id, and an error when the id belongs to another object type.

Response

Returns an ActiveDirectoryPayload!

Arguments

Name Description
id - ID! The ActiveDirectory identifier.
mockOptions - MockDataInput

Options for mock data generation. Options supported: key: "PLATFORM", value: OsPlatform

example: "mockOptions": { "options": [ { "key": "PLATFORM", "value": "WINDOWS" } ] }

Example

Query

query activeDirectory(
  $id: ID!,
  $mockOptions: MockDataInput
) {
  activeDirectory(
    id: $id,
    mockOptions: $mockOptions
  ) {
    node {
      id
      orgId
      seen {
        ...SeenOnlineFragment
      }
      objectType
      objectTypeLabel
      displayName
      firstSeen
      lastSeen
      createdAt
      updatedAt
      snapshotInfo {
        ...GraphObjectSnapshotInfoFragment
      }
      endpoint {
        ...EndpointFragment
      }
      enabled
      name
      domainControllerName
      domainControllerIpAddress {
        ...IpAddressFragment
      }
      domainControllerAddressType
      dnsForestName
      status
      role
      osSpecific {
        ... on ActiveDirectoryWindows {
          ...ActiveDirectoryWindowsFragment
        }
        ... on ActiveDirectoryMacOS {
          ...ActiveDirectoryMacOSFragment
        }
        ... on ActiveDirectoryLinux {
          ...ActiveDirectoryLinuxFragment
        }
      }
      findings {
        ...FindingsPayloadFragment
      }
      issues {
        ...IssuesPayloadFragment
      }
      issuesSummary {
        ...IssuesSummaryFragment
      }
    }
  }
}

Variables

{
  "id": "4",
  "mockOptions": MockDataInput
}

Response

{"data": {"activeDirectory": {"node": ActiveDirectory}}}