Microsoft Active Directory
Directory integration
Use NIM to manage Active Directory users, groups, computers, memberships, and organizational units from a single automation platform.
At a glanceDirect link to At a glance
NIM manages Active Directory users, groups, memberships, computers, and organizational units through the account that runs the NIM Service. Use a managed service account where possible and delegate only the rights needed for the objects and organizational units that NIM manages.
Before you start: Create the managed service account, delegate the required Active Directory permissions, and assign that account to the NIM Service. Restart the service after changing its sign-in account.
Verify success: Test the intended collection or change with a safe record. If NIM receives Access denied, use Active Directory's Effective Access view on the affected object to identify missing delegated rights or an explicit deny.
Solutions this integration supportsDirect link to Solutions this integration supports
Directory account lifecycle
Create and maintain Active Directory users, computers, and organizational units.
- Automates lifecycle changes
- Keeps directory records current
Group and membership management
Manage Active Directory groups and memberships through NIM workflows.
- Supports role-based access
- Reduces manual group work
Home folder provisioning
Create and maintain user home folders alongside directory changes.
- Supports consistent onboarding
- Simplifies administration
Delegated directory automation
Apply repeatable, permission-aware Active Directory operations at scale.
- Uses controlled service access
- Improves audit readiness
Configuration guidesDirect link to Configuration guides
Connector repositories
Browse the NIM connector variants for Microsoft Active Directory on GitHub:
- Microsoft Active Directory (PowerShell) connector repository on GitHub
- Microsoft Active Directory Group Policy (PowerShell) connector repository on GitHub
- Microsoft Active Directory MD (PowerShell) connector repository on GitHub
Supported operationsDirect link to Supported operations
Filter tables by supported operation
Showing 7 of 7 tables| Table | Read | Create | Update | Delete |
|---|---|---|---|---|
| Acls | ||||
| Computers | ||||
| Contacts | ||||
| Group | ||||
| Membership | ||||
| OrganizationalUnits | ||||
| User |
TroubleshootingDirect link to Troubleshooting
Start with the symptom that best matches what you see in NIM. Each path identifies the likely cause and the next action to take.
Problem
Access denied when NIM modifies an object
Likely cause
NIM is running as Local Service or Local System, its domain account lacks delegated rights, or an explicit deny exists in the object's access control list.
Resolution
- Confirm that the NIM service runs as a domain account, preferably a managed service account.
- Confirm that account has delegated rights to manage the affected users, groups, computers, or organizational units.
- In Active Directory Users and Computers, enable View > Advanced Features, then open the affected object's Properties > Security > Advanced > Effective Access.
- Select the NIM service account and choose View Effective Access. A red X on the requested action indicates a missing permission or explicit deny; review the object and its parent containers.
Problem
NIM cannot change password-related flags
Likely cause
The service account is not included in the Enable computer and user accounts to be trusted for delegation user-right assignment.
Resolution
- Open Group Policy Management and edit the Group Policy Object that manages this setting.
- Navigate to Computer Configuration > Windows Settings > Security Settings > Local Policies > User Rights Assignment.
- Open Enable computer and user accounts to be trusted for delegation and add the NIM service account, or one of its groups.
- Apply the policy and try the operation again. If that setting does not exist, investigate the object's delegated permissions instead.