Skip to main content
This tool lets a Neo Agent generate and run validated Active Directory PowerShell on a domain controller, executed through your connected RMM. It’s how Neo manages on-prem and hybrid AD environments — user and computer accounts, organizational units, group membership, and infrastructure queries.
Enabled automatically when you turn on Active Directory permissions on the workflow’s Integrations tab — there’s no separate toggle in the tool list. Requires an RMM connection that can run scripts on the domain controller. See Microsoft 365 integration and on-prem setup.

What It Does

  • Create, update, disable, enable, and delete AD user accounts
  • Reset passwords and unlock accounts
  • Manage group membership — security groups, distribution groups, OUs
  • Manage computer accounts and organizational units
  • Query directory and infrastructure state
  • Trigger an Azure AD Connect (Entra Connect) sync so on-prem changes propagate to the cloud

Hybrid Environments

In a hybrid setup, configure Microsoft 365 as on-prem. Neo makes the change on your domain controller and then triggers an Entra Connect sync, so a password reset or group change made on-prem shows up in the cloud automatically — no separate cloud action needed. If a company has both directories but no AD Connect sync (identity provider type “Hybrid (no AD Connect sync)”), there is no sync to trigger — Neo instead applies identity changes to both on-prem AD and Entra ID directly, keeping the two independent directories consistent.

Safety

How to Configure

1

Connect an RMM

Connect a supported RMM that can run scripts on the domain controller.
2

Configure the on-prem environment

Follow the on-prem setup guide to point Neo at the domain controller.
3

Enable Active Directory permissions

On the workflow’s Integrations tab, set the Active Directory permission groups (users, groups, computers, OUs, infrastructure, Entra Connect sync) to Read Only or Read / Write.
4

Set approval and cmdlet limits

Decide whether writes require technician approval on each permission group. To limit the cmdlets, use the two pickers above the Active Directory permission groups:
  • Allowed cmdlets: when you pick any, the agent can run only those. Also pick the helper cmdlets its scripts need, such as Select-Object. Leave it empty to allow every supported cmdlet.
  • Blocked cmdlets: the agent can never run these, even when a permission group or the allowed list includes them.
The pickers show while at least one permission group is on.
Start with Read Only and technician approval on. Most onboarding and offboarding workflows only need a handful of cmdlets — restrict to those once you’ve seen what the agent uses.