The Active Directory (AD) domain membership and directory-binding configuration of an Endpoint. Collected on Windows, macOS and Linux, it records whether Active Directory is enabled on the endpoint, the domain and DNS forest names, the domain controller's name and address, the directory status and the endpoint's domain role (ActiveDirectoryRole). Platform-specific detail is carried in ActiveDirectoryWindows, ActiveDirectoryMacOS or ActiveDirectoryLinux. Each Endpoint has at most one ActiveDirectory, reachable from the Endpoint's activeDirectory field.
Fields
| Field Name | Description |
|---|---|
id - ID!
|
The ActiveDirectory's unique identifier on the security graph. |
orgId - OrganizationId!
|
Unique identifier that corresponds to your deployment of this product or a specific customer account that this Endpoint belongs to. |
seen - SeenOnline!
|
Describes when this ActiveDirectory was seen. |
objectType - GraphObjectType!
|
The type of this graph object. |
objectTypeLabel - String!
|
A localized label describing the object type. |
displayName - String!
|
A concise human-friendly identifier for this object suitable for display in user interface page titles and in AI chat responses that refer to the object. |
firstSeen - Time!
|
Time this object was first seen. |
lastSeen - Time!
|
Time this object was last seen. |
createdAt - Time!
|
The time this object was created in the security graph. |
updatedAt - Time!
|
The time this object was last mutated in the security graph. |
snapshotInfo - GraphObjectSnapshotInfo!
|
Whether this object is a point-in-time snapshot of an object's state rather than the object's live state, and when that state was observed. |
endpoint - Endpoint
|
The Endpoint this ActiveDirectory belongs to if available. |
enabled - Boolean!
|
Whether Active Directory is enabled on the endpoint. When false, the other domain fields are not populated from the endpoint and osSpecific is null. |
name - String!
|
The name of the Active Directory domain. |
domainControllerName - String!
|
The name of the Active Directory domain controller. |
domainControllerIpAddress - IpAddress
|
The IP address of the Active Directory domain controller. |
domainControllerAddressType - DomainControllerAddressType!
|
The format of the domain controller address: an IP address or a NetBIOS name. |
dnsForestName - String!
|
The name of the root of the DNS tree. |
status - ActiveDirectoryStatus!
|
The current status of the domain object. |
role - ActiveDirectoryRole!
|
The endpoint's role in the domain, such as a standalone or member workstation or server, or a domain controller. |
osSpecific - ActiveDirectoryOsSpecific
|
The platform-specific Active Directory attributes: ActiveDirectoryWindows, ActiveDirectoryMacOS or ActiveDirectoryLinux. Null when Active Directory is not enabled. |
findings - FindingsPayload!
|
Policy findings for this object. |
issues - IssuesPayload!
|
Policy issues for this object. |
issuesSummary - IssuesSummary!
|
Summary of the active policy issues currently open on this object, broken down by severity. |
Returned by
activeDirectoryquery: Retrieves an endpoint's ActiveDirectory configuration by its graph object id: whether Active Directory is enabled, the domain and DNS forest, the…
Used by
Endpointtype: A Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.ActiveDirectoryPayloadtype: Payload wrapper for a single ActiveDirectory result.GraphObjectTypeenum: An enumeration of the different types of security graph objects.GraphObjectTypeCategoryenum: High-level grouping used to organize GraphObjectType values in UI navigation and API discovery.
Related types
EndpointA Windows, macOS, or Linux computer that runs the Wartiva endpoint agent and is enrolled with an organization.
Example
Example
{
"id": 4,
"orgId": "615f3b3b28284380e28a7342",
"seen": SeenOnline,
"objectType": "ACCOUNT_POLICY",
"objectTypeLabel": "abc123",
"displayName": "abc123",
"firstSeen": "2021-10-07T18:23:25.829Z",
"lastSeen": "2021-10-07T18:23:25.829Z",
"createdAt": "2021-10-07T18:23:25.829Z",
"updatedAt": "2021-10-07T18:23:25.829Z",
"snapshotInfo": GraphObjectSnapshotInfo,
"endpoint": Endpoint,
"enabled": false,
"name": "xyz789",
"domainControllerName": "abc123",
"domainControllerIpAddress": IpAddress,
"domainControllerAddressType": "INET",
"dnsForestName": "xyz789",
"status": "OK",
"role": "STANDALONE_WORKSTATION",
"osSpecific": ActiveDirectoryWindows,
"findings": FindingsPayload,
"issues": IssuesPayload,
"issuesSummary": IssuesSummary
}