v1

latestOpenAPI 3.0.0Apache 2.0 License2026-07-141784109.3 KB

Creates a new group.

post/Groups/CreateGroup#DirectoryId

Query parameters

DirectoryIdstring required

The identifier (ID) of the directory that's associated with the group.

Request body

ClientTokenstring
<p> A unique and case-sensitive identifier that you provide to make sure the idempotency of the request, so multiple identical calls have the same effect as one single call. </p> <p> A client token is valid for 8 hours after the first request that uses it completes. After 8 hours, any request with the same client token is treated as a new request. If the request succeeds, any future uses of that token will be idempotent for another 8 hours. </p> <p> If you submit a request with the same client token but change one of the other parameters within the 8-hour idempotency window, Directory Service Data returns an <code>ConflictException</code>. </p> <note> <p> This parameter is optional when using the CLI or SDK. </p> </note>
GroupScope'DomainLocal' | 'Global' | 'Universal' | 'BuiltinLocal'

The scope of the AD group. For details, see <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#group-scope">Active Directory security group scope</a>.

GroupType'Distribution' | 'Security'

The AD group type. For details, see <a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-security-groups#how-active-directory-security-groups-work">Active Directory security group type</a>.

OtherAttributesobject

An expression that defines one or more attributes with the data type and value of each attribute.

SAMAccountNamestring required

The name of the group.

Response

Success

DirectoryIdstring

The identifier (ID) of the directory that's associated with the group.

SAMAccountNamestring

The name of the group.

SIDstring

The unique security identifier (SID) of the group.