Skip to content

Directory accounts

/directory. Needs module.directory and a directory connector.

Manage Entra, Google Workspace or Active Directory accounts without leaving the service desk.

ActionNotes
Search for a userBy name or username
See assigned licencesAnd what each one is
Change a licenceAssign or remove
Lock or unlockEnable or disable sign-in
Delegate a mailboxGrant somebody access to another person’s inbox
Reset a passwordSubject to your provider’s policy

The feature that makes this defensible rather than merely convenient.

Before performing any of the above, you can link it to an existing submission or ticket, or create a new one.

“Please give Sarah access to Tom’s mailbox while he is on leave” becomes a ticket with a requester, a timestamp and an action, rather than a Teams message and a change nobody can account for six months later.

Use it. One click, and the change is accounted for instead of unexplained.

Why do this here rather than in the provider’s console

Section titled “Why do this here rather than in the provider’s console”

Three reasons, in the order they matter:

The request and the action are in one place. Somebody asks at the desk, you do it, the record is on the ticket.

The permission is narrower. A technician with directory.manage in Plugboard can do these six things. The same person with an account in the Entra admin centre can do considerably more.

It is audited here as well as there. Your identity provider has its own audit trail, and now so does your service desk, with the reason attached.

The directory connector ships with demo mode on, because the actions here are consequential and a connector that arrived live and half-configured would be worse than one that arrives safe.

Explore the workflow against sample data, then turn demo mode off. See the connector page.

Two paths exist and they are different things.

Here, through the directory connector, using your identity provider’s API. This is what a technician does at the desk.

At the kiosk, through the LDAP connector, where a person resets their own password after verifying with their card, or after a staff member approves the request.

A school can run either, both, or neither.

PermissionAllows
directory.viewSearch and read accounts
directory.manageEverything that changes something

Split these across roles. Plenty of technicians should be able to look somebody up without being able to reset their password.

Every action is written to the audit log with who did it, to whom, and what changed. That is in addition to your identity provider’s own trail, and it is the one with the reason attached.