Viewing and updating an AWS Managed Microsoft AD group's
details
Use the following procedure to view or update an AWS Managed Microsoft AD group's details with user and group management or AWS Directory Service Data in either the AWS Management Console, AWS CLI, or AWS Tools for PowerShell.
Viewing an AWS Managed Microsoft AD group's detail
You can view or update a group's details in the AWS Management Console, AWS CLI, or AWS Tools for PowerShell.
Before you begin either procedure, you need to complete the following:
-
To use user and group management or AWS Directory Service Data CLI, it must be enabled. For more information, see Enable user and group management or Directory Service Data.
-
You can only enable this feature from the Primary AWS Region for your directory. For more information, see Primary vs additional Regions.
-
You'll need the necessary IAM permissions to use AWS Directory Service Data. For more information, see AWS Directory Service API permissions: Actions, resources, and conditions reference. To get started granting permissions to your users and workloads, you can use AWS managed policies like AWSDirectoryServiceDataFullAccess or AWSDirectoryServiceDataReadOnlyAccess. For more information, see Security best practices in IAM.
You can view an AWS Managed Microsoft AD group's details in the AWS Management Console.
To view AWS Managed Microsoft AD group's details with the AWS Management Console
-
Open the AWS Directory Service console at https://console.aws.amazon.com/directoryservicev2/
. -
From the navigation pane, choose Active Directory, and then choose Directories. You're directed to the Directories screen where you can view a list of directories in your AWS Region.
-
Choose a directory. You're directed to the Directory details screen.
-
Choose Group. The tab shows a list of groups in your AWS Region.
-
Choose a group. To find groups, enter the group name in the search box under the Groups section. You're directed to the Group details screen. The Group details screen shows the following information:
-
Member tab lists the users and child groups that are members of your group.
-
Parent groups tab lists the parent groups that your group is a member of.
-
Properties tab lists the group properties (such as primary information like group name, group display name, etc.).
-
Updating an AWS Managed Microsoft AD group's details
Use the following procedure to update an AWS Managed Microsoft AD group's details with user and group management or AWS Directory Service Data in either the AWS Management Console, AWS CLI, or AWS Tools for PowerShell.
Before you begin either procedure, you need to complete the following:
To use user and group management or AWS Directory Service Data CLI, it must be enabled. For more information, see Enable user and group management or Directory Service Data.
-
You can only enable this feature from the Primary AWS Region for your directory. For more information, see Primary vs additional Regions.
-
You'll need the necessary IAM permissions to use AWS Directory Service Data. For more information, see AWS Directory Service API permissions: Actions, resources, and conditions reference. To get started granting permissions to your users and workloads, you can use AWS managed policies like AWSDirectoryServiceDataFullAccess or AWSDirectoryServiceDataReadOnlyAccess. For more information, see Security best practices in IAM.
You can update a group's details with the AWS Management Console. For more information, see AWS Directory Service Data attributes and Group type and group scope
To update an AWS Managed Microsoft AD group's details with the AWS Management Console
-
Open the AWS Directory Service console at https://console.aws.amazon.com/directoryservicev2/
. -
From the navigation pane, choose Active Directory, and then choose Directories. You're directed to the Directories screen where you can view a list of directories in your AWS Region.
-
Choose a directory. You're directed to the Directory details screen.
-
Choose Group. The tab shows a list of groups in your AWS Region.
-
Choose a group. To find groups, enter the group name in the search box under the Groups section. You're directed to the Group details screen.
-
To edit users and child groups that are members of your group, choose Members. From this tab, you can add and remove users and child groups from your group. For more information, see Adding and removing members to groups and groups to groups.
-
To edit parent groups that your group is a member of, choose Parent groups. From this tab, you can add and remove your group from parent groups. For more information, see Adding and removing members to groups and groups to groups.
-
To edit your group properties, choose Properties, and then choose Edit. Or choose Actions, and then choose Edit group. Make and review your updates, and then choose Save.