public sealed class ActiveDirectoryClient Curated Active Directory operations built on explicit, protected LDAP access.
Constructors
ActiveDirectoryClient
public ActiveDirectoryClient(WindowsDirectoryClient directory) Creates a client using a configured directory transport.
Methods
AddMemberAsync
public Task AddMemberAsync(string groupDistinguishedName, string memberDistinguishedName, CancellationToken cancellationToken = default) Adds a group member. An existing value is reported by LDAP as a conflict.
AddServicePrincipalNamesAsync
public Task AddServicePrincipalNamesAsync(string distinguishedName, ImmutableArray<string> names, CancellationToken cancellationToken = default) Adds explicit SPNs; does not generate names or choose an account.
ChangePasswordAsync
public Task ChangePasswordAsync(string distinguishedName, string oldPassword, string newPassword, CancellationToken cancellationToken = default) Changes a password through one LDAP delete/add request, preserving the user's change-password authorization semantics.
CreateComputerAsync
public Task CreateComputerAsync(string parentDistinguishedName, string commonName, string accountName, CancellationToken cancellationToken = default) Creates a disabled workstation computer account. accountName must include its trailing dollar sign.
CreateGroupAsync
public Task CreateGroupAsync(string parentDistinguishedName, string commonName, string accountName, ActiveDirectoryGroupScope scope, bool securityEnabled, CancellationToken cancellationToken = default) Creates a group with explicit scope and security/distribution semantics.
CreateOrganizationalUnitAsync
public Task CreateOrganizationalUnitAsync(string parentDistinguishedName, string name, CancellationToken cancellationToken = default) Creates an organizational unit with an escaped relative name.
CreateUserAsync
public Task CreateUserAsync(string parentDistinguishedName, string commonName, string accountName, string? userPrincipalName = null, CancellationToken cancellationToken = default) Creates a disabled user. Assign a password and enable it explicitly afterward.
GetMembersAsync
public Task<ImmutableArray<DirectoryValue>> GetMembersAsync(string groupDistinguishedName, CancellationToken cancellationToken = default) Retrieves all member DNs, including ranged attributes on large groups.
GetServicePrincipalNamesAsync
public Task<ImmutableArray<DirectoryValue>> GetServicePrincipalNamesAsync(string distinguishedName, CancellationToken cancellationToken = default) Reads all service principal names.
RemoveMemberAsync
public Task RemoveMemberAsync(string groupDistinguishedName, string memberDistinguishedName, CancellationToken cancellationToken = default) Removes a group member. A missing value remains distinguishable as an LDAP error.
RemoveServicePrincipalNamesAsync
public Task RemoveServicePrincipalNamesAsync(string distinguishedName, ImmutableArray<string> names, CancellationToken cancellationToken = default) Removes only explicitly supplied SPNs.
ResetPasswordAsync
public Task ResetPasswordAsync(string distinguishedName, string newPassword, CancellationToken cancellationToken = default) Resets an account password. Requires reset rights; the configured LDAP connection always uses TLS or signing/sealing.
SetAccountEnabledAsync
public Task SetAccountEnabledAsync(string distinguishedName, bool enabled, CancellationToken cancellationToken = default) Enables or disables an account while retaining other control bits and asserting that the observed value has not changed.