Search the AD catalogue
searchInspect a domain's Active Directory schema catalogue to find classes, attributes, LDAP controls, extended rights, and policy settings before scripting AD changes.
Instructions
Search one domain's Active Directory catalogue: every class and attribute in its schema, which attributes are confidential, each attribute's syntax and whether it holds one value, which attributes a class may hold, the LDAP controls the domain controller supports, and the extended rights. Use it before execute to find the right attribute or class rather than guessing.
The catalogue is read from the domain the first time you search it, which takes a few seconds, and kept for the session. Pass refresh: true after a schema change. Your script runs with no network and cannot reach the domain.
Write the body of an async function and "return" the value you want back. Output is capped at about 10,000 tokens, so filter inside the script.
Available in the script: declare const catalogue: { domain: string; readAt: string; dc: string; schemaNamingContext: string; forestFunctionality: number; domainFunctionality: number; // 10 = Windows Server 2025 attributes: Record<string, { // keyed by lDAPDisplayName, e.g. "member" oid: string; guid?: string; syntax: string; // e.g. "DN", "UnicodeString", "LargeInteger", "SID" single: boolean; confidential?: true; indexed?: true; systemOnly?: true; linkID?: number; range?: [number | null, number | null]; propertySet?: string; description?: string; }>; classes: Record<string, { // keyed by lDAPDisplayName, e.g. "user" oid: string; guid?: string; kind: "structural" | "abstract" | "auxiliary" | "88"; parent: string; must: string[]; may: string[]; // including inherited and auxiliary-class attributes auxiliary: string[]; possibleSuperiors: string[]; description?: string; }>; controls: Array<{ oid: string; name?: string }>; // what the DC supports extendedRights: Record<string, { // keyed by name, e.g. "User-Force-Change-Password" displayName: string; guid: string; kind: "control" | "propertySet" | "validatedWrite" | "other"; appliesTo: string[]; }>; // Policy settings from the ADMX files (the domain's central store, or the local PolicyDefinitions). // To set one with gpo.set, prefix key with HKLM\ for class Machine or HKCU\ for class User. // A policy's own valueName is set to 1 to enable it; elements are its extra values. policies: Array<{ name: string; displayName: string; class: "Machine" | "User" | "Both"; key: string; valueName?: string; category: string; file: string; elements: Array<{ type: string; id?: string; valueName?: string; key?: string }> }>; policiesSource?: string; policiesError?: string; };
Examples: // Confidential attributes return Object.entries(catalogue.attributes).filter(([, a]) => a.confidential).map(([n]) => n);
// Attributes about passwords, with their syntax return Object.entries(catalogue.attributes).filter(([n]) => /pwd|password/i.test(n)).map(([n, a]) => ({ n, syntax: a.syntax, single: a.single }));
// Everything a user object may hold return catalogue.classes.user.may.length;
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| code | Yes | Body of an async JavaScript function over `catalogue`. Return a value. | |
| domain | Yes | Connection alias or the domain's DNS name. See connections_list. | |
| refresh | No | Read the catalogue from the domain again. Defaults to false. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ok | Yes | ||
| logs | Yes | ||
| error | No | ||
| domain | Yes | ||
| result | No | ||
| truncated | Yes |