---
title: "POST /user/ListUserAssociations"
method: POST
path: "/user/ListUserAssociations"
---

# POST /user/ListUserAssociations

`POST /user/ListUserAssociations`

Lists user associations for an identity provider.

## Request body

- object
  - `InstanceId` string, required — The ID of the EC2 instance, which provides user-based subscriptions.
  - `IdentityProvider` object, required — Refers to an identity provider.
    - `ActiveDirectoryIdentityProvider` object — The <code>ActiveDirectoryIdentityProvider</code> resource contains settings and other details about a specific Active Directory identity provider.
      - `DirectoryId` string — The directory ID for an Active Directory identity provider.
      - `ActiveDirectorySettings` object — The <code>ActiveDirectorySettings</code> resource contains details about the Active Directory, including network access details such as domain name and IP addresses, and the credential provider for user administration.
        - `DomainName` string — The domain name for the Active Directory.
        - `DomainIpv4List` IpV4[] — A list of domain IPv4 addresses that are used for the Active Directory.
        - `DomainIpv6List` IpV6[] — A list of domain IPv6 addresses that are used for the Active Directory.
        - `DomainCredentialsProvider` object — Points to the <code>CredentialsProvider</code> resource that contains information about the credential provider for user administration.
          - `SecretsManagerCredentialsProvider` object — Identifies the Secrets Manager secret that contains credentials needed for user administration in the Active Directory.
            - `SecretId` string — The ID of the Secrets Manager secret that contains credentials.
        - `DomainNetworkSettings` object — The <code>DomainNetworkSettings</code> resource contains an array of subnets that apply for the Active Directory.
          - `Subnets` Subnet[], required — Contains a list of subnets that apply for the Active Directory domain.
      - `ActiveDirectoryType` 'SELF_MANAGED' | 'AWS_MANAGED' — The type of Active Directory – either a self-managed Active Directory or an Amazon Web Services Managed Active Directory.
      - `IsSharedActiveDirectory` boolean — Whether this directory is shared from an Amazon Web Services Managed Active Directory. The default value is false.
  - `MaxResults` integer — The maximum number of results to return from a single request.
  - `Filters` Filter[] — <p>You can use the following filters to streamline results:</p> <ul> <li> <p>Status</p> </li> <li> <p>Username</p> </li> <li> <p>Domain</p> </li> </ul>
    - `Attribute` string — The name of an attribute to use as a filter.
    - `Operation` string — The type of search (For example, eq, geq, leq)
    - `Value` string — Value of the filter.
  - `NextToken` string — A token to specify where to start paginating. This is the nextToken from a previously truncated response.

## Response `200`

Success

- ListUserAssociationsResponse
  - `InstanceUserSummaries` InstanceUserSummary[] — Metadata that describes the list user association operation.
    - `Username` string, required — The user name from the identity provider for the user.
    - `InstanceId` string, required — The ID of the EC2 instance that provides user-based subscriptions.
    - `IdentityProvider` object, required — The <code>IdentityProvider</code> resource specifies details about the identity provider.
      - `ActiveDirectoryIdentityProvider` object — The <code>ActiveDirectoryIdentityProvider</code> resource contains settings and other details about a specific Active Directory identity provider.
        - `DirectoryId` string — The directory ID for an Active Directory identity provider.
        - `ActiveDirectorySettings` object — The <code>ActiveDirectorySettings</code> resource contains details about the Active Directory, including network access details such as domain name and IP addresses, and the credential provider for user administration.
          - `DomainName` string — The domain name for the Active Directory.
          - `DomainIpv4List` IpV4[] — A list of domain IPv4 addresses that are used for the Active Directory.
          - `DomainIpv6List` IpV6[] — A list of domain IPv6 addresses that are used for the Active Directory.
          - `DomainCredentialsProvider` object — Points to the <code>CredentialsProvider</code> resource that contains information about the credential provider for user administration.
            - `SecretsManagerCredentialsProvider` object — Identifies the Secrets Manager secret that contains credentials needed for user administration in the Active Directory.
              - …
          - `DomainNetworkSettings` object — The <code>DomainNetworkSettings</code> resource contains an array of subnets that apply for the Active Directory.
            - `Subnets` Subnet[], required — Contains a list of subnets that apply for the Active Directory domain.
        - `ActiveDirectoryType` 'SELF_MANAGED' | 'AWS_MANAGED' — The type of Active Directory – either a self-managed Active Directory or an Amazon Web Services Managed Active Directory.
        - `IsSharedActiveDirectory` boolean — Whether this directory is shared from an Amazon Web Services Managed Active Directory. The default value is false.
    - `Status` string, required — The status of a user associated with an EC2 instance.
    - `InstanceUserArn` string — The Amazon Resource Name (ARN) that identifies the instance user.
    - `StatusMessage` string — The status message for users of an EC2 instance.
    - `Domain` string — The domain name of the Active Directory that contains the user information for the product subscription.
    - `AssociationDate` string — The date a user was associated with an EC2 instance.
    - `DisassociationDate` string — The date a user was disassociated from an EC2 instance.
  - `NextToken` string — The next token used for paginated responses. When this field isn't empty, there are additional elements that the service hasn't included in this request. Use this token with the next request to retrieve additional objects.

## Other responses

- `480` — ServiceQuotaExceededException
- `481` — ValidationException
- `482` — ConflictException
- `483` — ThrottlingException
- `484` — InternalServerException
- `485` — ResourceNotFoundException
- `486` — AccessDeniedException

---

[API](https://skmtc.net/aws/apis/license-manager-user-subscriptions.md) · [All operations](https://skmtc.net/aws/apis/license-manager-user-subscriptions/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/aws/license-manager-user-subscriptions/revisions/3f333914dcdb/schema)
