> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/search-and-reports/active-directory-entities/domain.md).

# Domain

<table><thead><tr><th width="268">Field</th><th>Type</th><th width="166">Possible Operators</th><th>Description</th></tr></thead><tbody><tr><td><strong>Guid</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>A unique identifier that is a combination of GUID of selected <code>Scan</code> and Active Directory <code>ObjectGUID</code> of the object.</td></tr><tr><td><strong>FSName</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Fully Qualified Domain Name of the Domain.</td></tr><tr><td><strong>ObjectSid</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Active Directory security identifier of object. (<strong>Ldap Display Name</strong>: objectSid)</td></tr><tr><td><strong>Name</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Name of the specified object. (<strong>Ldap Display Name</strong>: name)</td></tr><tr><td><strong>DistinguishedName</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Active Directory distinguished name of the object. (<strong>Ldap Display Name</strong>: distinguishedName)</td></tr><tr><td><strong>FSMORoleOwner</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Flexible Single-Master Operation: The distinguished name of the DC where the schema can be modified. (<strong>Ldap Display Name</strong>: fSMORoleOwner)</td></tr><tr><td><strong>WhenChanged</strong></td><td>DATE</td><td><code>SMALLER</code>, <code>LARGER</code>, <code>BETWEEN</code>, <code>EQUAL</code></td><td>The date when this object was last changed. (<strong>Ldap Display Name</strong>: whenChanged)</td></tr><tr><td><strong>MsDSMachineAccountQuota</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td>The number of computer accounts that a user is allowed to create in a domain. (<strong>Ldap Display Name</strong>: ms-DS-MachineAccountQuota)</td></tr><tr><td><strong>WhenCreated</strong></td><td>DATE</td><td><code>SMALLER</code>, <code>LARGER</code>, <code>BETWEEN</code>, <code>EQUAL</code></td><td>The date when this object was created. (<strong>Ldap Display Name</strong>: whenCreated)</td></tr><tr><td><strong>LockoutThreshold</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td>The number of invalid logon attempts that are permitted before the account is locked out. (<strong>Ldap Display Name</strong>: lockoutThreshold)</td></tr><tr><td><strong>DomainMode</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>The operating mode of the domain. (<a href="https://learn.microsoft.com/en-us/dotnet/api/system.directoryservices.activedirectory.domainmode?view=windowsdesktop-7.0">Field reference</a>)</td></tr><tr><td><strong>MinPwdLength</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td>The minimum number of characters that a password must contain. (<strong>Ldap Display Name</strong>: minPwdLength)</td></tr><tr><td><strong>DomainModeLevel</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td>The operating mode level of the domain. (<a href="https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/6dd88965-8feb-4369-ae7e-075985da8071">Field Reference</a>)</td></tr><tr><td><strong>risk</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td>The risk score of the object that calculated based on vulnerability counts and severities.</td></tr><tr><td><strong>IsEnumerable</strong></td><td>BOOLEAN</td><td><code>N/A</code></td><td>Indicates the FSProtect enumeration status of the domain.</td></tr><tr><td><strong>PwdProperties</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td>A bitfield to indicate complexity and storage restrictions. (<strong>Ldap Display Name</strong>: pwdProperties) (<a href="https://learn.microsoft.com/en-us/windows/win32/adschema/a-pwdproperties">Field Reference</a>)</td></tr><tr><td><strong>IsRecycleBinEnabled</strong></td><td>BOOLEAN</td><td><code>N/A</code></td><td>Indicates whether the recycle bin is activated for the domain.</td></tr><tr><td><strong>IsRootDomain</strong></td><td>BOOLEAN</td><td><code>N/A</code></td><td>Indicates whether the domain is the root of the forest.</td></tr><tr><td><strong>PwdHistoryLength</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td>The number of old passwords to save. (<strong>Ldap Display Name</strong>: pwdHistoryLength)</td></tr><tr><td><strong>InfrastructureRoleOwner</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Domain controller that holds the infrastructure owner role.</td></tr><tr><td><strong>RidRoleOwner</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Domain controller that holds the relative identifier (RID) master role for this domain.</td></tr><tr><td><strong>NetbiosName</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>The name of the object to be used over NetBIOS. (<strong>Ldap Display Name</strong>: nETBIOSName)</td></tr><tr><td><strong>PdcRoleOwner</strong></td><td>TEXT</td><td><code>LIKE</code>,<code>NOT_LIKE EQUAL</code>,<code>NOT_EQUAL</code>,<code>IS_EMPTY</code></td><td>Domain controller that holds the primary domain controller (PDC) for this domain.</td></tr><tr><td><strong>ExposurePoint</strong></td><td>NUMBER</td><td><code>EQUAL</code>, <code>BETWEEN</code>, <code>SMALLER</code>, <code>LARGER</code>, <code>SMALLER_EQUAL</code>, <code>LARGER_EQUAL</code></td><td><strong>ExposurePoint</strong>: A numerical value indicating the level of risk or exposure.</td></tr></tbody></table>
