Skip to main content Announcing Tool Gateway MCP: the universal MCPRead the announcement
Live 55 Actions

AD Manager MCP Server
for AI Agents

Connect your AI agent to StackOne's AD Manager MCP server and give it 55 MCP tools out of the box. Auth, tool execution, and security all managed.

AD Manager logo
AD Manager MCP Server
Built by StackOne StackOne
DrataGPLocalyzeFlipMindtoolsScreenloop

Coverage

55 Agent Actions

Create, read, update, and delete across AD Manager — and extend your agent's capabilities with custom actions.

Authentication

Agent Tool Authentication

Per-user OAuth in one call. Your AD Manager MCP server gets session-scoped tokens with zero credentials stored on your infra.

Agent Auth →

Security

Agent Protection

Every AD Manager tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.

Prompt Injection Defense →

Performance

Max Agent Context. Min Cost.

Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every AD Manager call.

Tools Discovery →

What is the AD Manager MCP Server?

A AD Manager MCP server lets AI agents read and write AD Manager data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's AD Manager MCP server ships with 55 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, observability, and agent execution runtime. Connect it from MCP clients like Claude Desktop, Claude Code, Cursor, Goose, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.

All AD Manager MCP Tools

Every action from AD Manager's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.

Environment Variables

  • Create Environment Variable

    Add an environment variable to ADManager Plus

  • List Environment Variables

    List the environment variables configured in ADManager Plus

  • Update Environment Variable

    Update an environment variable

Organization Companies

  • Create Organization Companies

    Add organization company values to ADManager Plus

  • List Organization Companies

    List the organization company values defined in ADManager Plus

  • Delete Organization Companies

    Delete organization company values matched by a filter

Organization Departments

  • Create Organization Departments

    Add organization department values to ADManager Plus

  • List Organization Departments

    List the organization department values defined in ADManager Plus

  • Delete Organization Departments

    Delete organization department values matched by a filter

Organization Offices

  • Create Organization Offices

    Add organization office values to ADManager Plus

  • List Organization Offices

    List the organization office values defined in ADManager Plus

  • Delete Organization Offices

    Delete organization office values matched by a filter

Organization Titles

  • Create Organization Titles

    Add organization title values to ADManager Plus

  • List Organization Titles

    List the organization title values defined in ADManager Plus

  • Delete Organization Titles

    Delete organization title values matched by a filter

Computers

  • Create Computers

    Create one or more AD computer accounts

  • List Computers

    List AD computer accounts with filtering, sorting and pagination

  • Update Computers

    Update attributes of the AD computers matched by a filter

  • Move Computers

    Move one or more AD computers to another OU

  • Delete Computers

    Delete one or more AD computer accounts

Contacts

  • Create Contacts

    Create one or more AD contacts

  • List Contacts

    List AD contacts with filtering, sorting and pagination

  • Update Contacts

    Update attributes of the AD contacts matched by a filter

  • Delete Contacts

    Delete the AD contacts matched by a filter

Groups

  • Create Groups

    Create one or more AD groups

  • List Groups

    List AD groups with filtering, sorting and pagination

  • Update Groups

    Update attributes of the AD groups matched by a filter

  • Move Groups

    Move one or more AD groups to another OU

  • Delete Groups

    Delete one or more AD groups

Organizational Units

  • Create Organizational Units

    Create one or more AD organizational units

  • List Organizational Units

    List AD organizational units with filtering, sorting and pagination

  • Update Organizational Units

    Update attributes of the AD OUs matched by a filter

  • Delete Organizational Units

    Delete one or more AD organizational units

Users

  • Create Users

    Create one or more AD user accounts

  • List Users

    List AD user accounts with filtering, sorting and pagination

  • Update Users

    Update attributes of the AD users matched by a filter

  • Move Users

    Move one or more AD users to another OU

  • Delete Users

    Delete one or more AD user accounts

Other (17)

  • Add Computers To Groups

    Add one or more AD computers to groups

  • Add Users To Groups

    Add one or more AD users to groups

  • Create Workflow Requests

    Raise workflow requests for AD operations that need approval

  • List Domains

    List the AD domains configured in ADManager Plus

  • List Group Members

    List the members of one or more AD groups

  • List Orchestration Templates

    List the orchestration templates configured in ADManager Plus

  • Get Orchestration Execution Status

    Get the status of an orchestration execution

  • Update Domain Settings

    Update the ADManager Plus connection settings for an AD domain

  • Remove Computers From Groups

    Remove one or more AD computers from groups

  • Remove Users From Groups

    Remove one or more AD users from groups

  • Disable Computers

    Disable the AD computer accounts matched by a filter

  • Enable Computers

    Enable one or more disabled AD computer accounts

  • Execute Orchestration

    Run an orchestration template against the AD objects matched by a filter

  • Disable Users

    Disable one or more AD user accounts

  • Enable Users

    Enable one or more disabled AD user accounts

  • Reset User Passwords

    Reset the AD password of one or more users

  • Unlock Users

    Unlock one or more locked-out AD user accounts

Set Up Your AD Manager MCP Server in Minutes

One endpoint. Any framework. Your agent is talking to AD Manager in under 10 lines of code.

Agent Frameworks

Claude Desktop
{
  "mcpServers": {
    "stackone": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote@latest",
        "https://api.stackone.com/mcp?x-account-id=<account_id>",
        "--header",
        "Authorization: Basic <YOUR_BASE64_TOKEN>"
      ]
    }
  }
}

Check More developer MCP Servers

Workiva

266+ actions

PingOne

124+ actions

Absolute Software

119+ actions

SonarQube Cloud

102+ actions

Zoho Sprints

87+ actions

Manufact

71+ actions

Mistral AI

68+ actions

AD Manager MCP Server FAQ

Does StackOne have a AD Manager MCP server?
Yes. StackOne offers a hosted AD Manager MCP server with 55 pre-built actions, and every action is tested and QA'd by StackOne. Connect it to Claude, Cursor, and any other MCP client, or to any agent framework through the AI Action SDK. It ships with managed agent authentication, prompt injection defense, and tool discovery with server-side execution that preserve your agent's context window and keep reasoning performance.
AD Manager MCP server vs direct API integration — what's the difference?
A AD Manager MCP server and direct API integration serve different use cases. Direct API integration is for software-to-software — backend code calling AD Manager. A AD Manager MCP server is for AI agents — MCP clients like Claude and Cursor, plus framework agents built with OpenAI, LangChain, or Vercel AI — discovering and calling AD Manager at runtime. StackOne provides both.
How does AD Manager authentication work for AI agents?
AD Manager authentication for AI agents works through a StackOne Connect Session. Create one via the dashboard or the SDK — you get an auth link and ready-to-paste config for Claude Desktop, Cursor, and other MCP clients. Your user authenticates their own AD Manager account; StackOne handles token exchange, storage, and refresh. Credentials never reach the LLM, and each user is isolated via origin_owner_id.
Are AD Manager MCP tools vulnerable to prompt injection?
Yes — AD Manager MCP tools can be vulnerable to indirect prompt injection. Any tool that reads user-written content — documents, messages, tickets, records, or free-text fields — is a potential vector. StackOne Defender scans every tool response before it enters the agent's context — regex patterns in ~1ms, then a MiniLM classifier in ~4ms. 88.7% accuracy, CPU-only.
What is the context bloat of a AD Manager agent and how do I avoid it?
Context bloat happens when AD Manager tool schemas and API responses eat your AD Manager agent's memory, preventing it from reasoning effectively. A single AD Manager query can return a massive JSON response, and connecting multiple tools compounds the problem. Tools Discovery and Code Mode reduce context bloat — loading only relevant tools per query and keeping raw responses out of the agent's context.
Can I limit which actions my AD Manager agent can access?
Yes — you can limit which actions your AD Manager agent can access directly from the StackOne dashboard. Toggle actions on or off, or restrict them to specific accounts, with no code changes to your agent. Session tokens can be scoped to exact actions so if one leaks, exposure stays contained.
Can I create custom agent actions for my AD Manager MCP server?
Yes — you can create custom agent actions for your AD Manager MCP server using Connector Builder. It's an integration agent your coding assistant (Claude Code, Cursor, or Copilot) can invoke to research AD Manager's API, generate production-ready connector YAML, test against the live API, and validate before you ship.
When should I NOT use a AD Manager MCP server?
Skip a AD Manager MCP server if your integration is purely software-to-software — direct AD Manager API integration is simpler when no AI agent is involved. For deterministic, compliance-critical operations (financial transactions, regulatory reporting), direct API gives you predictable behavior without agent-driven decision-making. MCP shines when AI agents need to dynamically discover and call AD Manager actions at runtime.
What AI frameworks and AI clients does the StackOne AD Manager MCP server support?
The StackOne AD Manager MCP server supports both. MCP clients (paste-and-go apps): Claude Desktop, Claude Code, Cursor, VS Code, Goose. Agent frameworks (code SDKs you build with): OpenAI Agents SDK, Anthropic, Vercel AI, Google ADK, CrewAI, Pydantic AI, LangChain, LangGraph, Azure AI Foundry.

Put your AI agents to work

All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.