OZO Unified AD JSON Schema

On my publications page you will find several PowerShell scripts for making your Active Directory life easier. The scripts that use a JSON configuration file leverage this unified schema, allowing you to create a single JSON file that represents critical elements of your AD environment.

Schema

{
    "ADComputers":[
        {
            "ComputerName":"",
            "Path":""
        }
    ],
    "ADContacts":[
        {
            "FirstName":"",
            "LastName":"",
            "EmailAddress":"",
            "Path":"",
            "TelephoneNumber":""
        }
    ],
    "ADDFSNFolderPermissions":[
        {
            "Description":"",
            "DFSNFolders":[""],
            "Identities":[""]
        }
    ],
    "ADDFSNRootPermissions":[
        {
            "Description":"",
            "DFSNRoots":[""],
            "Identities":[""]
        }
    ],
    "ADDFSRPermissions":[
        {
            "Description":"",
            "DFSRGroups":[""],
            "Identities":[""]
        }
    ],
    "ADGPOPermissions":[
        {
            "Description":"",
            "GPONames":[],
            "GroupNames":[""],
            "Permissions":[""]
        }
    ],
    "ADGroups":[
        {
            "Name":"",
            "Path":"",
            "Scope":0,
            "Members":[]
        }
    ],
    "ADOrganizationalUnits":[
        {
            "Name":"",
            "Path":""
        }
    ],
    "ADOUDelegations":[
        {
            "Description":"",
            "Identities":[],
            "Permissions":[],
            "OUs":[]
        }
    ],
    "ADUsers":[
        {
            "Surname":"",
            "GivenName":"",
            "Division":"",
            "Title":"",
            "EmployeeID":0,
            "SamAccountName":"",
            "Password":"",
            "Path":""
        }
    ]
}

Definition

Root Node

KeyValueRequired
ADComputersA list of computers to create. See ADComputers, below.FALSE
ADContactsA list of contacts to create. See ADContacts, below.FALSE
ADDefaultObjectsOUsA dictionary of object types and their default OUs.FALSE
ADDFSNFolderPermissionsA list of DFSN folders to delegate. See ADDFSNFolderPermissions, below.FALSE
ADDFSNRootPermissionsA list of DFSN roots to delegate. See ADDFSNRootPermissions, below.FALSE
ADDFSRPermissionsA list of DFSR permissions to apply. See ADDFSRPermissions, below.FALSE
ADGPOPermissionsA list of GPO permissions to apply. See ADGPOPermissions, below.FALSE
ADGroupPolicyObjectsA list of group policy objects to create. See ADGroupPolicyObjects, below.FALSE
ADGroupsA list of groups to create. See ADGroups, below.FALSE
ADOrganizationalUnitsA list of organizational units to create. See ADOrganizationalUnits, below.FALSE
ADOUDelegationsA list of delegations to create. See ADOUDelegations, below.FALSE
ADUsersA list of users to create. See ADUsers, below.FALSE

ADComputers

KeyValueRequired
ComputerNameThe name of the computer object.TRUE
PathThe organizational unit where the computer should be created.TRUE

ADContacts

keyValueRequired
FirstNameThe contact first name.TRUE
LastNameThe contact last name.TRUE
EmailAddressThe contact email address.TRUE
PathThe organizational unit where the contact should be created.TRUE
TelephoneNumberThe contact telephone number.TRUE

ADDefaultObjectsOUs

KEYValueRequired
GroupsThe OU that should contain AD domain built in groups.TRUE
UsersThe OU that should contain AD domain built in users.TRUE

ADDFSNFolderPermissions

KeyValueRequired
DescriptionA brief description of the DFSN permission.TRUE
DFSNFoldersA list of the folders where the permissions will be applied.TRUE
IdentitiesA list of AD users and group to whom the permissions will be applied.TRUE

ADDFSNRootPermissions

KeyValueRequired
DescriptionA brief description of the DFSN permission.TRUE
DFSNRootsA list of the folders where the permissions will be applied.TRUE
IdentitiesA list of AD users and group to whom the permissions will be applied.TRUE

ADDFSRPermissions

KeyValueRequired
DescriptionA brief description of the DFSR permission.TRUE
DFSRGroupsA list of the DFS replication groups where the permissions will be applied.TRUE
IdentitiesA list of AD users and group to whom the permissions will be applied.TRUE

ADGPOPermissions

KeyValueRequired
DescriptionA brief description of the GPO permission.TRUE
GPONamesA list of GPO names where the permissions will be applied.TRUE
GroupNamesA list of AD groups to whom the permissions will be applied.TRUE
PermissionsA list of the permissions to apply. Valid permissions are GpoRead, GpoApply, GpoEdit, and GpoEditDeleteModifySecurity.TRUE

ADGroupPolicyObjects

KeyValueRequired
NameThe name for the group policy object.TRUE
LinksA list of OUs where the policy should be linked.TRUE

ADGroups

KeyValueRequired
NameThe group name.TRUE
PathThe OU where the group should be created.TRUE
ScopeThe group GroupScope.TRUE
GroupsOther [parent] groups where this groups should be a member.TRUE

ADOrganizationalUnits

KeyValueRequired
NameThe organizational unit name.TRUE
PathThe organizational unit where the new OU should be created.TRUE

ADOUDelegations

KeyValueRequired
DescriptionA brief description of the delegation.TRUE
IdentitiesA list of users and groups to whom the delegation will be applied.TRUE
PermissionsThe permissions that will be applied for the user to the OU. See Permissions (below) for valid values.TRUE
OUsA list of OU distinguished names where the delegation will be applied.TRUE

ADUsers

KeyValueRequired
SurnameThe user last name.TRUE
GivenNameThe user first name.TRUE
DivisionThe user division.TRUE
TitleThe user title.TRUE
EmployeeIDThe user employee ID.TRUE
SamAccountNameThe user SamAccountName.TRUE
PasswordThe user password in plain text.TRUE
PathThe organizational unit where the user should be created.TRUE
GroupsA list of groups where this user should be a member.TRUE