> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Active Directory

> Capturing the directory itself – with domain and credentials, and with the decision on personal data and extended attributes.

The *Active Directory* module captures the directory itself – not the systems in
it. It addresses no individual targets: the wizard requires the domain
and an account allowed to read it, nothing else.

The wizard shows four steps for this module:

*Basics* › *Domain* › *Schedule* › *Summary*

All but *Domain* are the same for every module – see
[Creating a Scan Job](/docs/en/scan/create-inventory). A connected
[gateway](/docs/en/scan/gateway-install) is required.

## Domain and credentials

The *Domain* step takes the *Domain* first and the Windows credentials
below it. If the domain field is visible, it must be filled.

You choose the credentials in a searchable picker. In first position stands the
entry that lets the scan run under the gateway service's account. Two rows above
it create a new entry: *New credentials…* a reusable one, *One-time credentials…*
one that applies to this job only.

<Note>
  *Active Directory* and *Windows (AD)* are the two modules where credentials are
  **not** enforced: the step can be passed without an entry. Whether the scan then
  succeeds depends on which account the gateway service runs under in your network.
  For the first job an explicitly stored account is advisable.
</Note>

## Limiting what is captured

This module brings two options. They stand in the *Active Directory Options*
section behind the *Customize* button in the *Domain* step. If values are set, the addition *active* stands next to the button.

| Option | Factory setting |
| - | - |
| *Do Not Collect Personal Data* | off |
| *Do Not Collect Extended Attributes* | off |

<Warning>
  Both options are **off**. A job captures personal data and extended
  attributes of the directory until you deselect that explicitly. The decision is
  made in the wizard, not later on the captured data.
</Warning>

## Related modules

* **Windows (AD)** fetches the systems from the same directory instead of
  capturing the directory – see [Windows](/docs/en/scan/windows). The two jobs
  complement each other.
* **Windows DNS**, **Windows DHCP** and **DFS** can have their targets searched
  for in Active Directory instead of having them typed in.
* **NTFS Security** discovers its servers through the directory and needs domain
  and credentials for that as well – see
  [NTFS permissions](/docs/en/scan/ntfs-analysis).

## Related

Which types this scan produces is under
[Directory and Network Services](/docs/en/assets/directory-services). How you watch
the job afterwards is in [Managing Jobs](/docs/en/scan/manage-jobs).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.