DocumentationAPI ReferenceRelease Notes
API Reference

Create user account

Required Permission(s)

  • User Accounts Management (Full control)

Notes

  • Some parameters in the UserAddModel model are dependent on the user type.
  • For Pathfinder users only: Restrict to application type users only.
Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

The user creation model containing profile and authentication information

string | null

The user type out of the available user types (BeyondInsight, EntraID, ActiveDirectory, LdapDirectory, Application)

string | null

The host name for the user (LdapDirectory user type only)

int32

The port name for the user (LdapDirectory user type only)

boolean

Determines whether the user should use SSL (Not applicable to BeyondInsight and Application type users)

string | null

Username for directory binding. If not given, attempts to use existing credentials for the directory (ActiveDirectory and LdapDirectory type users only)

string | null

Password for directory binding (required when BindUser is given, ActiveDirectory and LdapDirectory type user)

string | null

The LDAP attribute to use for creating the username (LdapDirectory user type only)

int32
string | null

Username of the user account (Not applicable to LdapDirectory type users)

string | null

The directory forest name (required when BindUser is given, ActiveDirectory type users only)

string | null

The directory domain name (ActiveDirectory user type only)

string | null

The DistinguishedName of the user to create (LdapDirectory user type only)

string | null

First name of the user (BeyondInsight user type only)

string | null

Last name of the user (BeyondInsight user type only)

string | null

The email for the user (BeyondInsight user type only)

int32

The access policy ID (Application user type only)

string | null

The password for the user (BeyondInsight user type only)

string | null

Unique ID for the EntraID app. If not given, attempts to use existing credentials for the directory (EntraID user type only). If specifying an existing credential, Credential Management – Read permission is needed. If specifying a new credential, Credential Management – Read/Write permission is also needed

string | null

The client credential (EntraID user type only)

string | null

Tenant ID of the account (EntraID user type only)

string | null

Can have values of "AzureUsGovernment", "AzurePublic", or null (EntraID user type only). If the AzureInstance value is not provided or if it’s null, the instance defaults to AzurePublic unless the credential already exists. At that point it will take on the value of the existing credential

Headers
string
enum
Defaults to application/json

Generated from available request content types

Allowed:
Responses

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json

©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.