Create a Directory Query
You can create an Active Directory or LDAP query to retrieve information from Active Directory or LDAP to populate a Smart Rule. To work with directory queries, the BeyondInsight user must be a member of the Administrators group or assigned the Asset Management permission.
Create a new directory query or clone an existing query as follows:
- In the BeyondInsight Console, navigate to Configuration > Role Based Access > Directory Queries.
- Click Create New Directory Query + or click the vertical ellipsis for an existing query and select Clone.
- Select Active Directory or LDAP from the Directory Type list.
Cloned queries keep the same directory type as the query being cloned.
- Enter a name for the query in the Title field.
- Select a stored credential for running this query or click Create New Credential to be taken to the Directory Credentials page where you can add a new one.
At minimum, the credential must have Read permissions on the computer assets you are enumerating.
- Enter the directory path for the Query Target, or click Browse to search for a path and add it.
- Select a scope to apply to the container: This Object and All Child Objects or Immediate Children Only.
- Select an object type: Computer Objects or User Objects.
- Enter the directory path for the Query Target, or click Browse to search for a path and add it.
- Select a scope to apply to the container: This Object and All Child Objects or Immediate Children Only.
- Select an object type: Computer Objects or User Objects.
- Enable or disable the Dynamically refresh results each use option.
- Provide a Name and Description or use the * wild card character to match multiple values for the Basic Filter.
- Optionally, click Advanced Filterto provide an LDAP Query.
- Click Test to ensure the query returns expected results.
- Click Create Directory Query.
For more information, please see the following: