---
sourceDocument: Australia Workflow Data Fabric
sourceDocumentLink: https://www.servicenow.com/docs/r/integrate-applications

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Workflow Data Fabric

ft:clusterId :

    - crint

bundleId :

    - crint

workflow :

    - Creator


---

# Microsoft Active Directory Spoke

# Microsoft Active Directory Spoke {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Create, delete, and manage objects in Microsoft Active Directory, such as users, groups, and computers.

## Integration Hub subscription {#microsoft-ad-spoke__section_rsf_yvb_l3b}

This spoke requires an Integration Hub subscription. For more information, see [Legal schedules - IntegrationHub overview](https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/legal/snc-addendum-integrationhub.pdf).  
Important:  
* Starting with the Vancouver release, Microsoft Active Directory Spoke is being prepared for future deprecation. It is hidden and no longer activated on new instances but will continue to be supported. Microsoft Active Directory v2 Spoke provides the latest experience for this functionality. For details, see the Deprecation Process \[[KB0867184](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0867184)\] article in the Now Support Knowledge Base.
* This spoke is available as part of the family release. This spoke can be used to handle the computer objects.
{#microsoft-ad-spoke__ul_iml_3qr_2yb}

## Spoke requirements {#microsoft-ad-spoke__section_vn5_yzt_nkb}

Confirm that the Active Directory web services (ADWS) is deployed on the server that has Microsoft AD installed. For information on deploying ADWS, see <https://learn.microsoft.com/en-us/services-hub/unified/health/remediation-steps-ad/configure-the-active-directory-web-services-adws-to-start-automatically-on-all-servers> for information about deploying ADWS.

Since your instance must have a MID Server set up and configured to use the PowerShell, the MID Server must be able to access the ADWS at port 9389.  
In the MID Server and Microsoft AD server, run these PowerShell commands to install the Active Directory module:

    PS> Import-Module ServerManager
    PS> Install-WindowsFeature -Name RSAT-AD-PowerShell

## Spoke flows {#microsoft-ad-spoke__section_j5k_qgf_kfb}

The Microsoft Active Directory spoke provides sample flows in the draft state to demonstrate automating Active Directory tasks. To customize a sample flow, copy it to a new application scope. Available sample flows include:  
{#microsoft-ad-spoke__table_lq3_4hf_kfb__entry__2}

| Flow | Description |
|-|-|
| User Offboarding | Disables an AD user account and removes the user from any AD groups when a ServiceNow user record is deactivated. |
| User Onboarding | Creates and enables an AD user account when a ServiceNow user record is activated. |
[ ]

{#microsoft-ad-spoke__table_lq3_4hf_kfb}

## Spoke subflows {#microsoft-ad-spoke__section_uxx_tgf_kfb}

This spoke has no sample subflows.

## Spoke actions {#microsoft-ad-spoke__section_b43_3h2_hfb}

The Microsoft AD spoke provides actions to automate Microsoft Active Directory tasks when events occur in the ServiceNow AI Platform. Available actions include:  
{#microsoft-ad-spoke__table_u1p_kh2_hfb__entry__3}

| Category | Action | Description |
|-|-|-|
| Computer Management | Create Computer | Creates a Computer Account in Active Directory. |
| Computer Management | Delete Computer | Deletes a computer from Active Directory. |
| Computer Management | Disable Computer | Disables a computer account in Active Directory. |
| Computer Management | Enable Computer | Enables a computer account in Active Directory. |
| Computer Management | Get Computer OU | Gets the Organizational Unit (OU) of a Computer Account. |
| Computer Management | Is Computer Enabled | Checks the status of the specified computer account in Active Directory. |
| Computer Management | Move Computer to OU | Changes the Organizational Unit (OU) of a Computer Account in Active Directory. |
| Group Management | Add User To Group | Adds an existing Active Directory user to an Active Directory group. |
| Group Management | Create Group | Creates a group in Active Directory. |
| Group Management | Delete Group | Deletes a group from Active Directory. |
| Group Management | Lookup Group | Gets the details of a given group in Active Directory, including the group category, scope, and distinguished name. |
| Group Management | Remove User From Group | Removes an existing user from a group in Active Directory. |
| Password Management | Change User Password | Changes the user password in AD. The password input must comply with Active Directory password requirements. |
| Password Management | Is User Account Locked | Checks the locked status of the specified user account in Active Directory. |
| Password Management | Reset AD User Password | Resets a user's password in Active Directory. |
| User Management | Create User | Creates a user with no password in Active Directory. To enable a user to set a password, log in to AD, create a default password for the user, and enable password reset. |
| User Management | Delete User | Deletes a user from Active Directory. |
| User Management | Disable User | Disables a user account in Active Directory. |
| User Management | Enable User | Enables a user account in Active Directory. |
| User Management | Is User Enabled | Checks the status of a user account in Active Directory. |
| User Management | Is User In Group | Checks if an existing Active Directory user is a member of an Active Directory group. |
| User Management | Lookup User | Gets the details of a given user in Active Directory. |
| User Management | Unlock AD Account | Unlocks a user account in Active Directory. |
| User Management | Update User | Updates user attributes in Active Directory. |
| User Management | Update User Home Location | Updates the Home Directory for a User in Active Directory. |
| Object Management | Create AD Object | Creates an object of any type supported in Active Directory. |
| Object Management | Delete AD Object | Deletes an object of any type from Active Directory. |
| Object Management | Query AD | Queries AD for objects specified by a search filter. |
| Object Management | Update AD Object OU | Changes the Organizational Unit (OU) of an object in Active Directory. |
| Object Management | Update AD Object Expiration | Update the account expiration date of an object in Active Directory. |
[ ]

{#microsoft-ad-spoke__table_u1p_kh2_hfb}

## MID Server requirements {#microsoft-ad-spoke__section_qpb_55w_qfb}

To use these actions, your instance must have a MID Server set up and configured to use the PowerShell. For more information about running actions on the MID Server, see [Integration steps](https://www.servicenow.com/docs/3HAkBEjCzmcSEOfq7SkGnQ "Enable custom actions to integrate with external systems by activating Integration Hub, which adds integration steps to the Workflow Studio interface."). For information, see [MID Server](https://www.servicenow.com/docs/access?context=mid-server-landing&version=australia&pubname=australia-servicenow-platform&ft:locale=en-US).  
Note:  
MID and Microsoft Active Directory must be installed on different servers.

## Connection and credential alias requirements {#microsoft-ad-spoke__section_ibn_pj2_hfb}

Integration Hub uses aliases to manage connection and credential information, and OAuth credentials. Using an alias eliminates the need to configure multiple credentials and connection information
profiles when using multiple environments. If the connection or credential information changes, you don't need to update any actions that use the connection.

This spoke uses the AD alias record to authorize actions in Microsoft Active Directory.  
{#microsoft-ad-spoke__table_nnk_g2h_gfb__entry__3}

| Connection alias | Description | Connection URL |
|-|-|-|
| AD | Connection to Microsoft Active Directory. | The URL of the host machine where Microsoft Active Directory is installed. |
[ ]

{#microsoft-ad-spoke__table_nnk_g2h_gfb}

For information about setting up the spoke, see
[Set up Microsoft Active Directory spoke](https://www.servicenow.com/docs/VOJroM0d0Lx5itTBhcVUbA#set-up-ad "Integrate the ServiceNow instance and your Microsoft AD account using Windows credentials to authenticate ServiceNow requests.").

