Skip to main content
The Active Directory module (ActiveDirectory) ships with RSAT and is present by default on domain controllers. It provides Get-AD* and Set-AD* cmdlets that talk directly to LDAP — no external tool needed on a domain-joined Windows box. Unlike PowerView, these are Microsoft-signed, so they won’t trip script-block logging as suspicious.

Users

Groups

Computers

Service Accounts (MSA / gMSA)

Set-ADServiceAccount -PrincipalsAllowedToRetrieveManagedPassword replaces the entire list. Pass a single username and you wipe everyone else. Read the current value first and append to it as shown above if you need to preserve existing principals.

Objects and Attributes

Domain and Forest

Useful Filters