Skip to main content

Groups and OUs

The web interface is in development

The API calls are given in brackets (Vertex API).

Groups​

The group list (GET /tenants/{tenantID}/groups) shows every group of the domain from the mirror, searchable by text (q) and OU (ou), with its member count and the in_scope and protected flags. Built-in and administrative groups (Domain Admins, Administrators, …) are listed but protected: Vertex never changes them or their members.

Creating a group​

A new group (POST …/groups, Tenant admin, the groups switch):

FieldMeaning
Name (required)The CN, at most 64 characters.
Logon name (sam_account_name)Defaults to the name.
Scope (required)DomainLocal, Global or Universal.
Category (required)Security or Distribution.
OUDefaults to the settings' default user OU; must be a managed OU or below one.
DescriptionAt most 1,024 characters.
AttributesFurther attributes, as for users (for example mail, managedBy, info).

Members​

The members of a group (GET …/groups/{objectID}/members) are its direct members from the mirror; members Vertex does not know (for example computers or objects of other domains) are shown by their DN only.

POST …/groups/{objectID}/members adds and removes members by DN (add, remove: up to 500 each) in one operation. Members can be users, groups or computers. The rules:

  • the group must be below a managed OU and not protected;
  • a protected object (an administrator, a built-in account) cannot be added to any group;
  • every member counts as one change against the change limits and the connector's write cap.

The helpdesk may change members too: this is how they add a user to a class or a department group. From the user's side: Users → Group membership.

Changing, moving, renaming, deleting​

Groups use the same object operations as users: attributes (PATCH …/objects/{objectID}; member, groupType and the other denied attributes are refused), move, rename and delete (the deletes switch and a step-up). The scope and category of an existing group are not changed through Vertex.

Organizational units​

The OU list (GET …/ous) has every OU of the domain and the domain itself, parents before children, each with:

  • in_scope and protected;
  • is_domain for the domain object;
  • block_inheritance (GPO inheritance is blocked on it);
  • its GPO links in order (order 1 has the highest precedence), each enabled or not and enforced or not (Group Policy).

The managed OUs themselves are where Vertex may create and change objects. An OU below a managed OU can itself be renamed, moved and deleted; a managed OU itself cannot (change it on the domain controller and in the settings instead).

Creating an OU​

POST …/ous (Tenant admin, the OUs switch) with the parent OU's DN (a managed OU or below one), the name (at most 64 characters), an optional description and protect from accidental deletion (on by default).

Renaming, moving and deleting an OU​

  • Rename and move (POST …/objects/{objectID}/rename|move): the target must be a managed OU or below one.
  • Delete (DELETE …/objects/{objectID}, the deletes switch and a step-up) deletes an empty OU. With recursive=true it deletes the OU and everything below it, unless any object below is protected (then nothing is deleted). Vertex removes the protection from accidental deletion of the OU (and, recursively, of the objects below) before deleting: confirm with care.
  • Attributes (PATCH …/objects/{objectID}): for example description; gPLink and gPOptions are on the deny list (links are changed through Group Policy).