System.DirectoryServices
Specifies what kind of acknowledgment to get after sending a message.
Requests secure authentication. When this flag is set, the WinNT provider uses NT LAN Manager (NTLM)
to authenticate the client. Active Directory will use Kerberos, and possibly NTLM, to authenticate the client.
Forces ADSI to use encryption for data exchange over the network.
Encrypts the channel with SSL. Data will be encrypted using SSL. Active Directory requires that the
Certificate Server be installed to support SSL encryption.
For a WinNT provider, ADSI tries to connect to a primary domain controller or a backup domain
controller. For Active Directory, this flag indicates that a writeable server is not required for a
serverless binding.
Request no authentication. The providers may attempt to bind client, as an anonymous user, to the targeted
object. The WinNT provider does not support this flag. Active Directory establishes a connection between
the client and the targeted object, but will not perform any authentication. Setting this flag amounts to
requesting an anonymous binding, which means "Everyone" as the security context.
When this flag is set, ADSI will not attempt to query the objectClass property and thus will only expose
the base interfaces supported by all ADSI objects instead of the full object support.
Verifies data integrity to ensure the data received is the same as the data sent. The Secure flag
must be set also in order to use the signing.
Encrypts data using Kerberos. The Secure flag must be set also in order to use the sealing.
Enables ADSI to delegate the user's security context, which is necessary for moving objects across domains.
Specify this flag when using the LDAP provider if your ADsPath includes a server name. Do not use
this flag for paths that include a domain name or for serverless paths.
Specifies the behavior in which aliases are dereferenced.
Contains the children (child entries) of an entry in the Active Directory.
Gets the schemas that specify which children are shown.
Creates a request to create a new entry in the container.
Returns the child with the given name.
Returns the child with the given name and of the given type.
Deletes a child from this collection.
Supports a simple ForEach-style iteration over a collection and defines
enumerators, size, and synchronization methods.
Gets the current element in the collection.
Advances the enumerator to the next element of the collection
and returns a Boolean value indicating whether a valid element is available.
Resets the enumerator back to its initial position before the first element in the collection.
Encapsulates a node or an object in the Active Directory hierarchy.
Initializes a new instance of the class.
Initializes a new instance of the class that will bind
to the directory entry at .
Initializes a new instance of the class.
Initializes a new instance of the class.
Initializes a new instance of the class that will bind
to the native Active Directory object which is passed in.
Gets a
containing the child entries of this node in the Active
Directory hierarchy.
Gets the globally unique identifier of the .
Gets the relative name of the object as named with the underlying directory service.
Gets the native Active Directory Services Interface (ADSI) object.
Gets this entry's parent entry in the Active Directory hierarchy.
Gets or sets the password to use when authenticating the client.
Gets or sets the path for this .
Gets a of properties set on this object.
Gets the name of the schema used for this
Gets the that holds schema information for this
entry. An entry's
determines what properties are valid for it.
Gets a value indicating whether the cache should be committed after each
operation.
Gets or sets the username to use when authenticating the client.
Binds to the ADs object (if not already bound).
Closes the
and releases any system resources associated with this component.
Saves any changes to the entry in the directory store.
Creates a copy of this entry as a child of the given parent.
Creates a copy of this entry as a child of the given parent and gives it a new name.
Deletes this entry and its entire subtree from the Active Directory hierarchy.
Searches the directory store at the given path to see whether an entry exists.
If UsePropertyCache is true, calls GetInfo the first time it's necessary.
If it's false, calls GetInfoEx on the given property name.
Calls a method on the native Active Directory.
Reads a property on the native Active Directory object.
Sets a property on the native Active Directory object.
Moves this entry to the given parent.
Moves this entry to the given parent, and gives it a new name.
Loads the property values for this directory entry into the property cache.
Loads the values of the specified properties into the property cache.
Changes the name of this entry.
Performs queries against the Active Directory hierarchy.
Initializes a new instance of the class with ,
, , and set to their default values.
Initializes a new instance of the class with
, , and set to their default
values, and set to the given value.
Initializes a new instance of the class with
and set to their default
values, and and set to the respective given values.
Initializes a new instance of the class with
set to its default
value, and , , and set to the respective given values.
Initializes a new instance of the class with ,
, and set to their default
values, and set to the given value.
Initializes a new instance of the class with
and set to their default
values, and and set to the respective given values.
Initializes a new instance of the class with set to its default
value, and , , and set to the respective given values.
Initializes a new instance of the class with the , , , and properties set to the given
values.
Gets or sets a value indicating whether the result should be cached on the
client machine.
Gets or sets the maximum amount of time that the client waits for
the server to return results. If the server does not respond within this time,
the search is aborted, and no results are returned.
Gets or sets a value indicating whether the search should retrieve only the names of requested
properties or the names and values of requested properties.
Gets or sets the Lightweight Directory Access Protocol (LDAP) filter string format.
Gets or sets the page size in a paged search.
Gets the set of properties retrieved during the search. By default, the
and properties are retrieved.
Gets or sets how referrals are chased.
Gets or sets the scope of the search that should be observed by the server.
Gets or sets the time limit that the server should observe to search a page of results (as
opposed to the time limit for the entire search).
Gets or sets the maximum amount of time the server spends searching. If the
time limit is reached, only entries found up to that point will be returned.
Gets or sets the maximum number of objects that the
server should return in a search.
Gets or sets the node in the Active Directory hierarchy
at which the search will start.
Gets the property on which the results should be sorted.
Gets or sets a value indicating whether searches should be carried out in an asynchronous
way.
Gets or sets a value indicating whether the search should also return deleted objects that match the search
filter.
Gets or sets an attribute name to indicate that an attribute-scoped query search should be
performed.
Gets or sets a value to indicate how the aliases of found objects are to be
resolved.
Gets or sets a value to indicate the search should return security access information for the specified
attributes.
Gets or sets a value to return extended DNs according to the requested
format.
Gets or sets a value to indicate a directory synchronization search, which returns all changes since a specified
state.
Gets or sets a value to indicate the search should use the LDAP virtual list view (VLV)
control.
Executes the search and returns only the first entry that is found.
Executes the search and returns a collection of the entries that are found.
Specifies the possible representations of the distinguished name.
Contains the properties on a .
Gets the property with the given name.
Gets the number of properties available on this entry.
Copies the elements of this instance into an , starting at a particular index into the array.
Returns an enumerator, which can be used to iterate through the collection.
Holds a collection of values for a multi-valued property.
Appends the value to the set of values for this property.
Appends the values to the set of values for this property.
Appends the values to the set of values for this property.
Copies the elements of this instance into an ,
starting at a particular index into the given .
Removes the value from the collection.
Specifies if and how referral chasing is pursued.
Never chase the referred-to server. Setting this option
prevents a client from contacting other servers in a referral process.
Chase only subordinate referrals which are a subordinate naming context in a
directory tree. The ADSI LDAP provider always turns off this flag for paged
searches.
Chase external referrals.
Chase referrals of either the subordinate or external type.
Contains the properties on a .
Gets the property with the given name.
Specifies a collection of values for a multi-valued property.
Contains a list of schema names used for the property of a .
Gets or sets the object at the given index.
Gets the number of objects available on this entry.
Appends the value to the collection.
Appends the values to the collection.
Removes all items from the collection.
Determines if the collection contains a specific value.
Determines the index of a specific item in the collection.
Inserts an item at the specified position in the collection.
Removes an item from the collection.
Removes the item at the specified index from the collection.
Encapsulates a node in the Active Directory hierarchy
that is returned during a search through .
Retrieves the that corresponds to the , from the Active Directory
hierarchy.
Gets the path for this .
Gets a
of properties set on this object.
Contains the instances of returned during a
query to the Active Directory hierarchy through .
Gets the handle returned by IDirectorySearch::ExecuteSearch, which was called
by the DirectorySearcher that created this object
Gets a read-only collection of the properties specified on before the
search was executed.
Supports a simple ForEach-style iteration over a collection.
Gets the current element in the collection.
Advances the enumerator to the next element of the collection
and returns a Boolean value indicating whether a valid element is available.
Resets the enumerator back to its initial position before the first element in the collection.
Specifies the scope of a directory search.
Limits the search to the base object. The result contains at most one object.
Searched one level of the immediate children, excluding the base object.
Searches the whole subtree, including all the children and the base object itself.
Specifies the available options for examining security information of an object.
Initializes the search flags attribute value i.e. fetches it from
the directory, if this object is bound.
Returns a DomainController object for the DC that holds the specified FSMO role
Internal class that is used as a key in the hashtable
of directory entries
This class manages a list of directory entries
for an object that needs to bind to several
objects in AD. This maintains a cache of directory entries
and creates a new directory entry (for a given dn) only if
it doesn't already exist
Private Variables
Returns a DomainController object for the DC that holds the specified FSMO role
Helper class for dealing with struct AdsValue.
Moves the enumerator to the next value In the list.
Returns the current value of the enumerator. If GetNext() has never been called,
or if it has been called but it returned false, will throw an exception.
Returns the enumerator to the start of the sequence.
Moves the pointer to the next value In the contained IEnumVariant, and
stores the current value In currentValue.
PropertyValue as a co-class that implements the IAdsPropertyValue interface.
PropertyEntry as a co-class that implements the IAdsPropertyEntry interface.
For boolean type, the default marshaller does not work, so need to have specific marshaller. For other types, use the
default marshaller which is more efficient. There is no such interface on the type library this is the same as IAdsObjectOptions
with a different signature.
The value provided for adsObject does not implement IADs.
There is no such object on the server.
The path is invalid.
The Active Directory object located at the path {0} is not a container.
The object cannot be deleted.
There is no current child object.
The directory cannot report the number of properties.
The entry properties cannot be enumerated. Consider using the entry schema to determine what properties are available.
No current property exists.
No current value is available.
The PageSize must be greater than 0 or set to 0 for no paging.
SizeLimit must be greater than or equal to 0.
The provider does not support searching and cannot search {0}.
No current entry exists.
The {0} search filter is invalid.
The ADSVALUE with the union value {0} cannot be converted to the ADSTYPEENUM type {1}.
ADSVALUE type is invalid.
Handling of this ADSVALUE type is not yet implemented (type = {0}).
Active Directory Client is not installed on this computer.
[Not Set]
Enumerator is positioned before the first item or after the last item.
New PropertyValueCollection cannot be set into a DirectoryEntry PropertyCollection.
New properties cannot be added to a DirectoryEntry PropertyCollection.
DirectoryEntry PropertyCollection cannot be cleared.
Properties cannot be removed from a DirectoryEntry PropertyCollection.
The value for the property {0} cannot be set.
BeforeCount must be greater than or equal to 0.
AfterCount must be greater than or equal to 0.
Offset must be greater than or equal to 0.
Target percentage should be in the range of 0 to 100 inclusively.
ApproximateTotal must be greater or equal to 0.
DirectorySynchronization cannot be combined with PageSize.
VirtualListView cannot be combined with CacheResults.
When AttributeScopeQuery is specified, only SearchScope.Base is supported.
Only one type of operation can be performed in a sequence.
An unknown error occurred.
This property is only supported on computers running Windows XP and later operating systems.
This property is not supported when targeting Windows Server 2000 domain controllers.
The target of the directory context should be an Active Directory domain controller or ADAM instance.
An error occurred when synchronizing the server.
"{0}" is an unknown ActiveDirectoryTransportType.
ActiveDirectoryTransportType.Smtp not supported.
The newly created object has not been committed to the backend store, so it cannot be deleted.
The newly created object has not been committed to the backend store, so GetDirectoryEntry cannot be called.
The Specified directory object cannot be found.
The transport "{0}" cannot be found.
The site "{0}" does not exist.
The site "{0}" is newly created and has not been committed to the backend store.
The computer is not in a site.
The subnet "{0}" is newly created and has not been committed to the backend store.
The site link "{0}" is newly created and has not been committed to the backend store.
The replication connection "{0}" is newly created and has not been committed to the backend store.
A forest trust relationship exists between "{0}" and "{1}".
A domain trust relationship exists between "{0}" and "{1}".
Cannot remove "{0}". It was not found in the specified collection.
Cannot add "{0}". It currently exists in the specified collection.
The site "{0}" does not contain a nTDSSiteSettings object.
This directory server is not in the current site.
The end time must be later than the start time.
Information about the domain could not be retrieved ({0}).
The thread or process token could not be accessed ({0}).
Information from the thread token could not be retrieved ({0}).
This computer's policy information could not be retrieved ({0}).
Failure in updating rIDAvailablePool value. New value exceeds the maximum limit.
The specified string parameter is empty.
The name specified in the directory context must be an ADAM instance.
The name specified in the directory context must be an Active Directory domain controller.
The name specified in the directory context must be the DNS name of the application partition.
The name specified in the directory context must be an Active Directory domain controller or a forest.
The name specified in the directory context must be an Active Directory domain controller or a domain.
The name specified in the directory context must be an Active Directory domain.
The name specified in the directory context must be an Active Directory forest.
The name specified in the directory context must be an ADAM configuration set.
The name specified in the directory context must be an ADAM instance or an ADAM configuration set.
The name specified in the directory context must be a global catalog.
The name specified in the directory context must be an Active Directory domain controller or an ADAM instance.
The specified name is not a forest, Active Directory domain controller, ADAM instance, or ADAM configuration set.
The directory server does not host the specified application partition.
The specified application partition does not exist.
A Directory server that hosts the specified application partition not found.
Global catalog not found in forest "{0}".
Domain controller not found in the domain "{0}".
ADAM instance not found in configuration set "{0}".
Domain controller "{0}" does not exist or cannot be contacted.
Global catalog "{0}" does not exist or cannot be contacted.
ADAM instance "{0}" does not exist or cannot be contacted.
Directory server "{0}" does not exist or cannot be contacted.
The specified domain does not exist or cannot be contacted.
The specified forest does not exist or cannot be contacted.
The specified ADAM configuration set does not exist or cannot be contacted.
The specified application partition does not exist or cannot be contacted.
Property "{0}" on object "{1}" not found.
Property "{0}" not found.
An ADAM instance could not be found.
Operation valid only for objects that exist on the backend store.
The server object name has an invalid format.
Object class must not be specified for Active Directory application partitions.
The specified distinguished name has an invalid format.
Application partition is neither an Active Directory, nor ADAM application partition.
Schema property "{0}" has an unknown syntax.
The requested mode is invalid.
No Windows Server 2003 domain controllers exist in the domain.
Domain controller data not found for the specified Active Directory domain controller.
No Windows Server 2003 domain controllers exist in the forest.
The schema object "{0}" is newly created and has not been committed to the backend store.
One or more flags are invalid.
Cannot perform this operation on a global catalog object.
The specified value cannot be removed or overwritten. It is inherited from a super class.
The Active Directory domain controller must be running Windows Server 2003 operating system or later.
Schema property with link id "{0}" not found.
Cannot perform this operation on disabled global catalog object.
This property is not supported for an ADAM application partition.
This operation is not supported for an ADAM application partition.
Current security context is not associated with an Active Directory domain or forest.
The local computer is not joined to a domain or the domain cannot be contacted.
Unable to obtain DNS hostname of Active Directory domain controller with ntdsa object name "{0}".
Unable to obtain DNS hostname or port number of ADAM instance with ntdsa object name "{0}".
Name: "{0}"
Creation of single level application partition is not supported.
Unable to obtain the site name of domain controller "{0}".
Unable to obtain the distinguished name of the site object for domain controller "{0}".
Unable to obtain the distinguished name of the computer object of domain controller "{0}".
Unable to obtain the distinguished name of the server object of domain controller "{0}".
Unable to obtain the distinguished name of the ntds settings object of domain controller "{0}".
Unable to obtain the guid of the ntds settings object of domain controller "{0}".
DirectoryContextType.Domain and DirectoryContextType.Forest are the only valid values for contextType when the name of the context is not specified.
The specified directory server must be an Active Directory domain controller.
The specified directory server must be an ADAM instance.
The system acl cannot be modified as it was not retrieved from the backend store.
The discretionary acl cannot be modified as it was not retrieved from the backend store.
A collision occurred in the forest trust relationship.
A forest trust relationship does not exist between "{0}" and "{1}".
A domain trust relationship does not exist between "{0}" and "{1}".
A forest trust relationship should not exist between "{0}" and "{1}".
The trust relationship between "{0}" and "{1}" is not "{2}".
Trust relationship with Windows NT 4.0 domain not supported.
Operation for Kerberos type trust not supported.
The provider does not support retrieval of the security descriptor in binary form.
Multiple security descriptors for an object are not supported.
ntSecurityDescriptor property exists in cache, but has no values.
Must be the name of an Active Directory domain controller.
Must be the name of an ADAM instance.
Must be in the same Active Directory forest as the name specified in the directory context.
Must be in the same ADAM Configuration Set as the name specified in the directory context.
Trust verification not supported.
Only single dimensional arrays are supported for the requested action.
Number was less than the array's lower bound in the first dimension.
Destination array was not long enough. Check destIndex and length, and the array's lower bounds.
A negative value is not permitted for the replication interval.
The value exceeds the maximum allowed for replication interval.
The value can not be represented in whole minutes.
The value exceeds the maximum allowed.
System.DirectoryServices is not supported on this platform.
Blittable version of Windows BOOL type. It is convenient in situations where
manual marshalling is required, or to avoid overhead of regular bool marshalling.
Some Windows APIs return arbitrary integer values although the return type is defined
as BOOL. It is best to never compare BOOL to TRUE. Always use bResult != BOOL.FALSE
or bResult == BOOL.FALSE .
Blittable version of Windows BOOLEAN type. It is convenient in situations where
manual marshalling is required, or to avoid overhead of regular bool marshalling.
Some Windows APIs return arbitrary integer values although the return type is defined
as BOOLEAN. It is best to never compare BOOLEAN to TRUE. Always use bResult != BOOLEAN.FALSE
or bResult == BOOLEAN.FALSE .
OBJECT_ATTRIBUTES structure.
The OBJECT_ATTRIBUTES structure specifies attributes that can be applied to objects or object handles by routines
that create objects and/or return handles to objects.
Optional handle to root object directory for the given ObjectName.
Can be a file system directory or object manager directory.
Name of the object. Must be fully qualified if RootDirectory isn't set.
Otherwise is relative to RootDirectory.
If null, object will receive default security settings.
Optional quality of service to be applied to the object. Used to indicate
security impersonation level and context tracking mode (dynamic or static).
Equivalent of InitializeObjectAttributes macro with the exception that you can directly set SQOS.
This handle can be inherited by child processes of the current process.
This flag only applies to objects that are named within the object manager.
By default, such objects are deleted when all open handles to them are closed.
If this flag is specified, the object is not deleted when all open handles are closed.
Only a single handle can be open for this object.
Lookups for this object should be case insensitive.
Create on existing object should open, not fail with STATUS_OBJECT_NAME_COLLISION.
Open the symbolic link, not its target.
SECURITY_QUALITY_OF_SERVICE structure.
Used to support client impersonation. Client specifies this to a server to allow
it to impersonate the client.
SECURITY_IMPERSONATION_LEVEL enumeration values.
[SECURITY_IMPERSONATION_LEVEL]
The server process cannot obtain identification information about the client and cannot impersonate the client.
[SecurityAnonymous]
The server process can obtain identification information about the client, but cannot impersonate the client.
[SecurityIdentification]
The server process can impersonate the client's security context on it's local system.
[SecurityImpersonation]
The server process can impersonate the client's security context on remote systems.
[SecurityDelegation]
SECURITY_CONTEXT_TRACKING_MODE
The server is given a snapshot of the client's security context.
[SECURITY_STATIC_TRACKING]
The server is continually updated with changes.
[SECURITY_DYNAMIC_TRACKING]
Length in bytes, not including the null terminator, if any.
Max size of the buffer in bytes
TOKEN_INFORMATION_CLASS enumeration.