View Source AWS.Directory (aws-elixir v1.0.9)
Directory Service
Directory Service is a web service that makes it easy for you to setup and run directories in the Amazon Web Services cloud, or connect your Amazon Web Services resources with an existing self-managed Microsoft Active Directory.
This guide provides detailed information about Directory Service operations, data types, parameters, and errors. For information about Directory Services features, see Directory Service and the Directory Service Administration Guide.
Amazon Web Services provides SDKs that consist of libraries and sample code for various programming languages and platforms (Java, Ruby, .Net, iOS, Android, etc.). The SDKs provide a convenient way to create programmatic access to Directory Service and other Amazon Web Services services. For more information about the Amazon Web Services SDKs, including how to download and install them, see Tools for Amazon Web Services.
Link to this section Summary
Functions
Accepts a directory sharing request that was sent from the directory owner account.
If the DNS server for your self-managed domain uses a publicly addressable IP address, you must add a CIDR address block to correctly route traffic to and from your Microsoft AD on Amazon Web Services.
Adds two domain controllers in the specified Region for the specified directory.
Adds or overwrites one or more tags for the specified directory.
Cancels an in-progress schema extension to a Microsoft AD directory.
Creates an AD Connector to connect to a self-managed directory.
Creates an alias for a directory and assigns the alias to the directory.
Creates an Active Directory computer object in the specified directory.
Creates a conditional forwarder associated with your Amazon Web Services directory.
Creates a Simple AD directory.
Creates a hybrid directory that connects your self-managed Active Directory (AD) infrastructure and Amazon Web Services.
Creates a subscription to forward real-time Directory Service domain controller security logs to the specified Amazon CloudWatch log group in your Amazon Web Services account.
Creates a Microsoft AD directory in the Amazon Web Services Cloud.
Creates a snapshot of a Simple AD or Microsoft AD directory in the Amazon Web Services cloud.
Directory Service for Microsoft Active Directory allows you to configure trust relationships.
Deletes a directory assessment and all associated data.
Deletes a conditional forwarder that has been set up for your Amazon Web Services directory.
Deletes an Directory Service directory.
Deletes the specified log subscription.
Deletes a directory snapshot.
Deletes an existing trust relationship between your Managed Microsoft AD directory and an external domain.
Deletes from the system the certificate that was registered for secure LDAP or client certificate authentication.
Removes the specified directory as a publisher to the specified Amazon SNS topic.
Retrieves detailed information about a directory assessment, including its current status, validation results, and configuration details.
Displays information about the certificate registered for secure LDAP or client certificate authentication.
Retrieves information about the type of client authentication for the specified directory, if the type is specified.
Obtains information about the conditional forwarders for this account.
Obtains information about the directories that belong to this account.
Obtains status of directory data access enablement through the Directory Service Data API for the specified directory.
Provides information about any domain controllers in your directory.
Obtains information about which Amazon SNS topics receive status messages from the specified directory.
Retrieves information about update activities for a hybrid directory.
Describes the status of LDAP security for the specified directory.
Provides information about the Regions that are configured for multi-Region replication.
Retrieves information about the configurable settings for the specified directory.
Returns the shared directories in your account.
Obtains information about the directory snapshots that belong to this account.
Obtains information about the trust relationships for this account.
Describes the updates of a directory for a particular update type.
Disables alternative client authentication methods for the specified directory.
Deactivates access to directory data via the Directory Service Data API for the specified directory.
Deactivates LDAP secure calls for the specified directory.
Disables multi-factor authentication (MFA) with the Remote Authentication Dial In User Service (RADIUS) server for an AD Connector or Microsoft AD directory.
Disables single-sign on for a directory.
Enables alternative client authentication methods for the specified directory.
Enables access to directory data via the Directory Service Data API for the specified directory.
Activates the switch for the specific directory to always use LDAP secure calls.
Enables multi-factor authentication (MFA) with the Remote Authentication Dial In User Service (RADIUS) server for an AD Connector or Microsoft AD directory.
Enables single sign-on for a directory.
Obtains directory limit information for the current Region.
Obtains the manual snapshot limits for a directory.
Retrieves a list of directory assessments for the specified directory or all assessments in your account.
For the specified directory, lists all the certificates registered for a secure LDAP or client certificate authentication.
Lists the address blocks that you have added to a directory.
Lists the active log subscriptions for the Amazon Web Services account.
Lists all schema extensions applied to a Microsoft AD Directory.
Lists all tags on a directory.
Registers a certificate for a secure LDAP or client certificate authentication.
Associates a directory with an Amazon SNS topic.
Rejects a directory sharing request that was sent from the directory owner account.
Removes IP address blocks from a directory.
Stops all replication and removes the domain controllers from the specified Region.
Removes tags from a directory.
Resets the password for any user in your Managed Microsoft AD or Simple AD directory.
Restores a directory using an existing directory snapshot.
Shares a specified directory (DirectoryId
) in your Amazon Web Services account
(directory
owner) with another Amazon Web Services account (directory consumer).
Initiates a directory assessment to validate your self-managed AD environment for hybrid domain join.
Applies a schema extension to a Microsoft AD directory.
Stops the directory sharing between the directory owner and consumer accounts.
Updates a conditional forwarder that has been set up for your Amazon Web Services directory.
Updates the directory for a particular update type.
Updates the configuration of an existing hybrid directory.
Adds or removes domain controllers to or from the directory.
Updates the Remote Authentication Dial In User Service (RADIUS) server information for an AD Connector or Microsoft AD directory.
Updates the configurable settings for the specified directory.
Updates the trust that has been set up between your Managed Microsoft AD directory and an self-managed Active Directory.
Directory Service for Microsoft Active Directory allows you to configure and verify trust relationships.
Link to this section Functions
If the DNS server for your self-managed domain uses a publicly addressable IP address, you must add a CIDR address block to correctly route traffic to and from your Microsoft AD on Amazon Web Services.
AddIpRoutes adds this address block. You can also use AddIpRoutes to facilitate routing traffic that uses public IP ranges from your Microsoft AD on Amazon Web Services to a peer VPC.
Before you call AddIpRoutes, ensure that all of the required permissions have been explicitly granted through a policy. For details about what permissions are required to run the AddIpRoutes operation, see Directory Service API Permissions: Actions, Resources, and Conditions Reference.
Adds two domain controllers in the specified Region for the specified directory.
Adds or overwrites one or more tags for the specified directory.
Each directory can have a maximum of 50 tags. Each tag consists of a key and optional value. Tag keys must be unique to each resource.
Cancels an in-progress schema extension to a Microsoft AD directory.
Once a schema
extension has started replicating to all domain controllers, the task can no
longer be
canceled. A schema extension can be canceled during any of the following states;
Initializing
, CreatingSnapshot
, and
UpdatingSchema
.
Creates an AD Connector to connect to a self-managed directory.
Before you call ConnectDirectory
, ensure that all of the required permissions
have been explicitly granted through a policy. For details about what
permissions are required
to run the ConnectDirectory
operation, see Directory Service API Permissions: Actions, Resources, and Conditions
Reference.
Creates an alias for a directory and assigns the alias to the directory.
The alias is used
to construct the access URL for the directory, such as
http://.awsapps.com
.
After an alias has been created, it cannot be deleted or reused, so this operation should only be used when absolutely necessary.
Creates an Active Directory computer object in the specified directory.
Creates a conditional forwarder associated with your Amazon Web Services directory.
Conditional forwarders are required in order to set up a trust relationship with another domain. The conditional forwarder points to the trusted domain.
Creates a Simple AD directory.
For more information, see Simple Active Directory in the Directory Service Admin Guide.
Before you call CreateDirectory
, ensure that all of the required permissions
have been explicitly granted through a policy. For details about what
permissions are required
to run the CreateDirectory
operation, see Directory Service API Permissions: Actions, Resources, and Conditions
Reference.
Creates a hybrid directory that connects your self-managed Active Directory (AD) infrastructure and Amazon Web Services.
You must have a successful directory assessment using StartADAssessment
to
validate your environment compatibility before you
use this operation.
Updates are applied asynchronously. Use DescribeDirectories
to
monitor the progress of directory creation.
Creates a subscription to forward real-time Directory Service domain controller security logs to the specified Amazon CloudWatch log group in your Amazon Web Services account.
Creates a Microsoft AD directory in the Amazon Web Services Cloud.
For more information, see Managed Microsoft AD in the Directory Service Admin Guide.
Before you call CreateMicrosoftAD, ensure that all of the required permissions have been explicitly granted through a policy. For details about what permissions are required to run the CreateMicrosoftAD operation, see Directory Service API Permissions: Actions, Resources, and Conditions Reference.
Creates a snapshot of a Simple AD or Microsoft AD directory in the Amazon Web Services cloud.
You cannot take snapshots of AD Connector directories.
Directory Service for Microsoft Active Directory allows you to configure trust relationships.
For example, you can establish a trust between your Managed Microsoft AD directory, and your existing self-managed Microsoft Active Directory. This would allow you to provide users and groups access to resources in either domain, with a single set of credentials.
This action initiates the creation of the Amazon Web Services side of a trust relationship between an Managed Microsoft AD directory and an external domain. You can create either a forest trust or an external trust.
Deletes a directory assessment and all associated data.
This operation permanently removes the assessment results, validation reports, and configuration information.
You cannot delete system-initiated assessments. You can delete customer-created assessments even if they are in progress.
Deletes a conditional forwarder that has been set up for your Amazon Web Services directory.
Deletes an Directory Service directory.
Before you call DeleteDirectory
, ensure that all of the required permissions
have been explicitly granted through a policy. For details about what
permissions are required
to run the DeleteDirectory
operation, see Directory Service API Permissions: Actions, Resources, and Conditions
Reference.
Deletes the specified log subscription.
Deletes a directory snapshot.
Deletes an existing trust relationship between your Managed Microsoft AD directory and an external domain.
Deletes from the system the certificate that was registered for secure LDAP or client certificate authentication.
Removes the specified directory as a publisher to the specified Amazon SNS topic.
Retrieves detailed information about a directory assessment, including its current status, validation results, and configuration details.
Use this operation to monitor assessment progress and review results.
Displays information about the certificate registered for secure LDAP or client certificate authentication.
describe_client_authentication_settings(client, input, options \\ [])
View SourceRetrieves information about the type of client authentication for the specified directory, if the type is specified.
If no type is specified, information about all client authentication
types that are supported for the specified directory is retrieved. Currently,
only
SmartCard
is supported.
Obtains information about the conditional forwarders for this account.
If no input parameters are provided for RemoteDomainNames, this request describes all conditional forwarders for the specified directory ID.
Obtains information about the directories that belong to this account.
You can retrieve information about specific directories by passing the directory
identifiers in the DirectoryIds
parameter. Otherwise, all directories that
belong
to the current account are returned.
This operation supports pagination with the use of the NextToken
request and
response parameters. If more results are available, the
DescribeDirectoriesResult.NextToken
member contains a token that you pass in
the next call to DescribeDirectories
to retrieve the next set of
items.
You can also specify a maximum number of return results with the Limit
parameter.
Obtains status of directory data access enablement through the Directory Service Data API for the specified directory.
Provides information about any domain controllers in your directory.
Obtains information about which Amazon SNS topics receive status messages from the specified directory.
If no input parameters are provided, such as DirectoryId or TopicName, this request describes all of the associations in the account.
Retrieves information about update activities for a hybrid directory.
This operation provides details about configuration changes, administrator account updates, and self-managed instance settings (IDs and DNS IPs).
Describes the status of LDAP security for the specified directory.
Provides information about the Regions that are configured for multi-Region replication.
Retrieves information about the configurable settings for the specified directory.
Obtains information about the directory snapshots that belong to this account.
This operation supports pagination with the use of the NextToken request and
response parameters. If more results are available, the
DescribeSnapshots.NextToken
member contains a token that you pass in the next call to DescribeSnapshots
to
retrieve the next set of items.
You can also specify a maximum number of return results with the Limit parameter.
Obtains information about the trust relationships for this account.
If no input parameters are provided, such as DirectoryId or TrustIds, this request describes all the trust relationships belonging to the account.
Describes the updates of a directory for a particular update type.
Disables alternative client authentication methods for the specified directory.
Deactivates access to directory data via the Directory Service Data API for the specified directory.
For more information, see Directory Service Data API Reference.
Deactivates LDAP secure calls for the specified directory.
Disables multi-factor authentication (MFA) with the Remote Authentication Dial In User Service (RADIUS) server for an AD Connector or Microsoft AD directory.
Disables single-sign on for a directory.
Enables alternative client authentication methods for the specified directory.
Enables access to directory data via the Directory Service Data API for the specified directory.
For more information, see Directory Service Data API Reference.
Activates the switch for the specific directory to always use LDAP secure calls.
Enables multi-factor authentication (MFA) with the Remote Authentication Dial In User Service (RADIUS) server for an AD Connector or Microsoft AD directory.
Enables single sign-on for a directory.
Single sign-on allows users in your directory to access certain Amazon Web Services services from a computer joined to the directory without having to enter their credentials separately.
Obtains directory limit information for the current Region.
Obtains the manual snapshot limits for a directory.
Retrieves a list of directory assessments for the specified directory or all assessments in your account.
Use this operation to monitor assessment status and manage multiple assessments.
For the specified directory, lists all the certificates registered for a secure LDAP or client certificate authentication.
Lists the address blocks that you have added to a directory.
Lists the active log subscriptions for the Amazon Web Services account.
Lists all schema extensions applied to a Microsoft AD Directory.
Lists all tags on a directory.
Registers a certificate for a secure LDAP or client certificate authentication.
Associates a directory with an Amazon SNS topic.
This establishes the directory as a publisher to the specified Amazon SNS topic. You can then receive email or text (SMS) messages when the status of your directory changes. You get notified if your directory goes from an Active status to an Impaired or Inoperable status. You also receive a notification when the directory returns to an Active status.
Removes IP address blocks from a directory.
Stops all replication and removes the domain controllers from the specified Region.
You
cannot remove the primary Region with this operation. Instead, use the
DeleteDirectory
API.
Removes tags from a directory.
Resets the password for any user in your Managed Microsoft AD or Simple AD directory.
Disabled users will become enabled and can be authenticated following the API call.
You can reset the password for any user in your directory with the following exceptions:
For Simple AD, you cannot reset the password for any user that is a member of either the Domain Admins or *Enterprise Admins group except for the administrator user.
For Managed Microsoft AD, you can only reset the password for a user that is in an OU based off of the NetBIOS name that you typed when you created your directory. For example, you cannot reset the password for a user in the Amazon Web Services Reserved OU. For more information about the OU structure for an Managed Microsoft AD directory, see What Gets Created in the Directory Service Administration Guide*.
Restores a directory using an existing directory snapshot.
When you restore a directory from a snapshot, any changes made to the directory after the snapshot date are overwritten.
This action returns as soon as the restore operation is initiated. You can
monitor the
progress of the restore operation by calling the DescribeDirectories
operation
with
the directory identifier. When the DirectoryDescription.Stage value changes
to
Active
, the restore operation is complete.
Initiates a directory assessment to validate your self-managed AD environment for hybrid domain join.
The assessment checks compatibility and connectivity of the self-managed AD environment.
A directory assessment is automatically created when you create a hybrid
directory.
There are two types of assessments: CUSTOMER
and SYSTEM
. Your
Amazon Web Services account has a limit of 100 CUSTOMER
directory assessments.
The assessment process typically takes 30 minutes or more to complete. The
assessment
process is asynchronous and you can monitor it with
DescribeADAssessment
.
The InstanceIds
must have a one-to-one correspondence with
CustomerDnsIps
, meaning that if the IP address for instance i-10243410
is 10.24.34.100 and the IP address for instance i-10243420 is 10.24.34.200, then
the
input arrays must maintain the same order relationship, either [10.24.34.100, 10.24.34.200] paired with [i-10243410, i-10243420] or [10.24.34.200, 10.24.34.100]
paired with [i-10243420, i-10243410].
Note: You must provide exactly one DirectoryId
or
AssessmentConfiguration
.
Applies a schema extension to a Microsoft AD directory.
Updates a conditional forwarder that has been set up for your Amazon Web Services directory.
Updates the directory for a particular update type.
Updates the configuration of an existing hybrid directory.
You can recover hybrid directory administrator account or modify self-managed instance settings.
Updates are applied asynchronously. Use DescribeHybridADUpdate
to
monitor the progress of configuration changes.
The InstanceIds
must have a one-to-one correspondence with
CustomerDnsIps
, meaning that if the IP address for instance i-10243410
is 10.24.34.100 and the IP address for instance i-10243420 is 10.24.34.200, then
the
input arrays must maintain the same order relationship, either [10.24.34.100, 10.24.34.200] paired with [i-10243410, i-10243420] or [10.24.34.200, 10.24.34.100]
paired with [i-10243420, i-10243410].
You must provide at least one update to
UpdateHybridADRequest$HybridAdministratorAccountUpdate
or
UpdateHybridADRequest$SelfManagedInstancesSettings
.
Adds or removes domain controllers to or from the directory.
Based on the difference between current value and new value (provided through this API call), domain controllers will be added or removed. It may take up to 45 minutes for any new domain controllers to become fully active once the requested number of domain controllers is updated. During this time, you cannot make another update request.
Updates the Remote Authentication Dial In User Service (RADIUS) server information for an AD Connector or Microsoft AD directory.
Updates the configurable settings for the specified directory.
Updates the trust that has been set up between your Managed Microsoft AD directory and an self-managed Active Directory.
Directory Service for Microsoft Active Directory allows you to configure and verify trust relationships.
This action verifies a trust relationship between your Managed Microsoft AD directory and an external domain.