Groups and OUs
The API calls are given in brackets (Vertex API).
Groups
The group list (GET /tenants/{tenantID}/groups) shows every group of the
domain from the mirror, searchable by text (q) and OU (ou), with its
member count and the in_scope and protected flags. Built-in and
administrative groups (Domain Admins, Administrators, …) are
listed but protected: Vertex never changes them or their members.
Creating a group
A new group (POST …/groups, Tenant admin, the groups switch):
| Field | Meaning |
|---|---|
| Name (required) | The CN, at most 64 characters. |
Logon name (sam_account_name) | Defaults to the name. |
| Scope (required) | DomainLocal, Global or Universal. |
| Category (required) | Security or Distribution. |
| OU | Defaults to the settings' default user OU; must be a managed OU or below one. |
| Description | At most 1,024 characters. |
| Attributes | Further attributes, as for users (for example mail, managedBy, info). |
Members
The members of a group (GET …/groups/{objectID}/members) are its
direct members from the mirror; members Vertex does not know (for
example computers or objects of other domains) are shown by their DN only.
POST …/groups/{objectID}/members adds and removes members by DN (add,
remove: up to 500 each) in one operation. Members can be users, groups
or computers. The rules:
- the group must be below a managed OU and not protected;
- a protected object (an administrator, a built-in account) cannot be added to any group;
- every member counts as one change against the change limits and the connector's write cap.
The helpdesk may change members too: this is how they add a user to a class or a department group. From the user's side: Users → Group membership.
Changing, moving, renaming, deleting
Groups use the same object operations as users: attributes
(PATCH …/objects/{objectID}; member, groupType and the other
denied attributes are
refused), move, rename and delete (the deletes switch and a step-up).
The scope and category of an existing group are not changed through
Vertex.
Organizational units
The OU list (GET …/ous) has every OU of the domain and the domain
itself, parents before children, each with:
in_scopeandprotected;is_domainfor the domain object;block_inheritance(GPO inheritance is blocked on it);- its GPO links in order (
order1 has the highest precedence), each enabled or not and enforced or not (Group Policy).
The managed OUs themselves are where Vertex may create and change objects. An OU below a managed OU can itself be renamed, moved and deleted; a managed OU itself cannot (change it on the domain controller and in the settings instead).
Creating an OU
POST …/ous (Tenant admin, the OUs switch) with the parent OU's
DN (a managed OU or below one), the name (at most 64 characters), an
optional description and protect from accidental deletion (on by
default).
Renaming, moving and deleting an OU
- Rename and move (
POST …/objects/{objectID}/rename|move): the target must be a managed OU or below one. - Delete (
DELETE …/objects/{objectID}, the deletes switch and a step-up) deletes an empty OU. Withrecursive=trueit deletes the OU and everything below it, unless any object below is protected (then nothing is deleted). Vertex removes the protection from accidental deletion of the OU (and, recursively, of the objects below) before deleting: confirm with care. - Attributes (
PATCH …/objects/{objectID}): for exampledescription;gPLinkandgPOptionsare on the deny list (links are changed through Group Policy).