DirectoryServiceDataClient

Amazon Web Services Directory Service Data is an extension of Directory Service. This API reference provides detailed information about Directory Service Data operations and object types.

With Directory Service Data, you can create, read, update, and delete users, groups, and memberships from your Managed Microsoft AD without additional costs and without deploying dedicated management instances. You can also perform built-in object management tasks across directories without direct network connectivity, which simplifies provisioning and access management to achieve fully automated deployments. Directory Service Data supports user and group write operations, such as CreateUser and CreateGroup, within the organizational unit (OU) of your Managed Microsoft AD. Directory Service Data supports read operations, such as ListUsers and ListGroups, on all users, groups, and group memberships within your Managed Microsoft AD and across trusted realms. Directory Service Data supports adding and removing group members in your OU and the Amazon Web Services Delegated Groups OU, so you can grant and deny access to specific roles and permissions. For more information, see Manage users and groups in the Directory Service Administration Guide.

Directory management operations and configuration changes made against the Directory Service API will also reflect in Directory Service Data API with eventual consistency. You can expect a short delay between management changes, such as adding a new directory trust and calling the Directory Service Data API for the newly created trusted realm.

Directory Service Data connects to your Managed Microsoft AD domain controllers and performs operations on underlying directory objects. When you create your Managed Microsoft AD, you choose subnets for domain controllers that Directory Service creates on your behalf. If a domain controller is unavailable, Directory Service Data uses an available domain controller. As a result, you might notice eventual consistency while objects replicate from one domain controller to another domain controller. For more information, see What gets created in the Directory Service Administration Guide. Directory limits vary by Managed Microsoft AD edition:

  • Standard edition – Supports 8 transactions per second (TPS) for read operations and 4 TPS for write operations per directory. There's a concurrency limit of 10 concurrent requests.

  • Enterprise edition – Supports 16 transactions per second (TPS) for read operations and 8 TPS for write operations per directory. There's a concurrency limit of 10 concurrent requests.

  • Amazon Web Services Account - Supports a total of 100 TPS for Directory Service Data operations across all directories.

Directory Service Data only supports the Managed Microsoft AD directory type and is only available in the primary Amazon Web Services Region. For more information, see Managed Microsoft AD and Primary vs additional Regions in the Directory Service Administration Guide.

Properties

Link copied to clipboard

DirectoryServiceDataClient's configuration

Functions

Link copied to clipboard

Adds an existing user, group, or computer as a group member.

Link copied to clipboard
abstract suspend fun createGroup(input: CreateGroupRequest): CreateGroupResponse

Creates a new group.

Link copied to clipboard
abstract suspend fun createUser(input: CreateUserRequest): CreateUserResponse

Creates a new user.

Link copied to clipboard
abstract suspend fun deleteGroup(input: DeleteGroupRequest): DeleteGroupResponse

Deletes a group.

Link copied to clipboard
abstract suspend fun deleteUser(input: DeleteUserRequest): DeleteUserResponse

Deletes a user.

Link copied to clipboard

Returns information about a specific group.

Link copied to clipboard

Returns information about a specific user.

Link copied to clipboard
abstract suspend fun disableUser(input: DisableUserRequest): DisableUserResponse

Deactivates an active user account. For information about how to enable an inactive user account, see ResetUserPassword in the Directory Service API Reference.

Link copied to clipboard

Returns member information for the specified group.

Link copied to clipboard
abstract suspend fun listGroups(input: ListGroupsRequest): ListGroupsResponse

Returns group information for the specified directory.

Link copied to clipboard

Returns group information for the specified member.

Link copied to clipboard
abstract suspend fun listUsers(input: ListUsersRequest): ListUsersResponse

Returns user information for the specified directory.

Link copied to clipboard

Removes a member from a group.

Link copied to clipboard

Searches the specified directory for a group. You can find groups that match the SearchString parameter with the value of their attributes included in the SearchString parameter.

Link copied to clipboard
abstract suspend fun searchUsers(input: SearchUsersRequest): SearchUsersResponse

Searches the specified directory for a user. You can find users that match the SearchString parameter with the value of their attributes included in the SearchString parameter.

Link copied to clipboard
abstract suspend fun updateGroup(input: UpdateGroupRequest): UpdateGroupResponse

Updates group information.

Link copied to clipboard
abstract suspend fun updateUser(input: UpdateUserRequest): UpdateUserResponse

Updates user information.

Inherited functions

Link copied to clipboard

Adds an existing user, group, or computer as a group member.

Link copied to clipboard
expect abstract fun close()
Link copied to clipboard

Creates a new group.

Link copied to clipboard

Creates a new user.

Link copied to clipboard

Deletes a group.

Link copied to clipboard

Deletes a user.

Link copied to clipboard

Returns information about a specific group.

Link copied to clipboard

Returns information about a specific user.

Link copied to clipboard

Deactivates an active user account. For information about how to enable an inactive user account, see ResetUserPassword in the Directory Service API Reference.

Link copied to clipboard

Returns member information for the specified group.

Link copied to clipboard

Returns group information for the specified directory.

Link copied to clipboard

Returns group information for the specified member.

Link copied to clipboard

Returns user information for the specified directory.

Link copied to clipboard

Removes a member from a group.

Link copied to clipboard

Searches the specified directory for a group. You can find groups that match the SearchString parameter with the value of their attributes included in the SearchString parameter.

Link copied to clipboard

Searches the specified directory for a user. You can find users that match the SearchString parameter with the value of their attributes included in the SearchString parameter.

Link copied to clipboard

Updates group information.

Link copied to clipboard

Updates user information.

Link copied to clipboard

Create a copy of the client with one or more configuration values overridden. This method allows the caller to perform scoped config overrides for one or more client operations.