DescribeUsers

Updated at:

Retrieves the username, email address, and description of a directory account.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

ecd:DescribeUsers

list

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

MaxResults

integer

No

The number of entries to return per page.

  • Valid values: 1 to 500.

  • Default value: 200.

10

NextToken

string

No

The pagination token that is used to retrieve the next page of results. Do not specify this parameter for the first request.
A non-empty NextToken value in the response indicates that more results are available. To retrieve the next page, pass the NextToken value in the next request.

caeba0bbb2be03f84eb48b699f0a****

Filter

string

No

The string for a fuzzy search on the username (EndUserId) and email (Email) fields. This parameter supports the asterisk (*) wildcard. For example, if you set this parameter to a*m, the query returns all users whose username or email starts with a and ends with m.

a*m

FilterMap

object

No

string

No

EndUserIds

array

No

An array of usernames (EndUserId) to match exactly.

string

No

The username (EndUserId) to match. The query returns information only for the user with the specified username.

alice

ExcludeEndUserIds

array

No

An array of usernames (EndUserId) to exclude from the results.

string

No

The username (EndUserId) to exclude. The query does not return information for the user with the specified username.

tony

OrgId

string

No

The ID of the organization. The query returns only the users that belong to this organization.

org-4mdgc1cocc59z****

GroupId

string

No

The ID of the user group. The query returns only the users that belong to this user group.

ug-12341234****

ShowExtras

object

No

Note

This parameter is not for public use.

any

No

The key specifies the type of extra information to return. Set the corresponding value to true to include this information in the response. Membership in user groups and organizations is returned by default. Valid keys include: - Group: The user groups that the user belongs to. - Org: The organizations that the user belongs to. - ResourcesCount: The number of assigned resources. - Properties: The user attributes.

ResourcesCount: true

FilterWithAssignedResources

object

No

Note

This parameter is not for public use.

boolean

No

The key specifies a cloud resource type. Set the value to true to return only users who are assigned this type of resource. Valid keys: - Desktop: a cloud desktop. - DesktopGroup: a shared cloud desktop. - CloudDrive: an enterprise cloud drive (the user's personal drive). - App: a cloud application.

DesktopGroup: true

IsQueryAllSubOrgs

boolean

No

Specifies whether to query users in the sub-organizations of the organization specified by OrgId. This parameter applies only if you specify OrgId.

true

FilterWithAssignedResource

object

No

Filters users based on assignments of specific cloud resources.

string

No

The key specifies a cloud resource type, and the value is a resource ID. The query returns only users assigned to that specific resource. Valid keys:

  • Desktop: A cloud desktop.

  • DesktopGroup: A shared cloud desktop.

  • CloudDrive: An enterprise cloud drive (the user's personal drive).

  • App: A cloud application.

App:aig-jfgmanbo****

Status

integer

No

The status of the user account.

ExcludeGroupId

string

No

The ID of a user group to exclude. The query returns only users who do not belong to this user group.

BusinessChannel

string

No

The business channel.

ENTERPRISE

Response elements

Element

Type

Description

Example

object

The response data.

RequestId

string

The request ID.

1CBAFFAB-B697-4049-A9B1-67E1FC5F****

NextToken

string

The token used to retrieve the next page of results. If this parameter is empty, all results have been returned.

caeba0bbb2be03f84eb48b699f0a4883

Users

array<object>

A list of convenience accounts.

array<object>

Details of a convenience account.

Id

integer

The ID of the convenience account.

4205**

EndUserId

string

The username.

alice

Email

string

The email address.

username@example.com

Phone

string

The phone number. This parameter is returned only if it is set.

1381111****

Status

integer

The status of the convenience account.

Valid values:

  • 0 :

    Enabled

  • 9 :

    Locked

0

OwnerType

string

The type of the convenience account. Valid values:

  • Administrator-activated: The administrator sets the username and password. Notifications, such as password reset requests, are sent to the administrator's email address or phone number.

  • User-activated: The administrator sets the username and the user's email address or phone number for receiving notifications. Notifications, such as cloud desktop provisioning notices that contain the initial password, are sent to the user's email address or phone number.

Valid values:

  • CreateFromManager :

    Administrator-activated

  • Normal :

    User-activated

Normal

Remark

string

The remark for the convenience account.

Test user.

OrgId

string

The ID of the organization to which the convenience account belongs.

Note

This parameter is deprecated.

org-4mdgc1cocc59z****

WyId

string

The globally unique ID of the convenience account.

41fd1254d8f7****

IsTenantManager

boolean

Indicates whether the user is a tenant administrator. If you create an administrator-activated convenience account, you must specify a tenant administrator. Notifications, such as password resets initiated by the user from a client, are sent to the email address or phone number of this tenant administrator. For more information, see Create a convenience account.

true

Groups

array<object>

The user groups that the convenience account belongs to.

object

A user group that the convenience account belongs to.

GroupId

string

The user group ID.

ug-12341234****

GroupName

string

The name of the user group.

用户组1

Orgs

array<object>

The organizations that the convenience account belongs to.

object

An organization that the convenience account belongs to.

OrgId

string

The organization ID.

org-4mdgc1cocc59z****

OrgName

string

The organization name.

部门1

OrgNamePath

string

The full path of the organization name.

Avatar

string

The URL of the user's avatar.

https://cdn.*****

Address

string

The office address of the user.

杭州市***

NickName

string

The nickname of the user.
The value is determined by the first of the following parameters that has a value, in order of precedence:

  • RealNickName

  • Remark

  • EndUserId

李**

RealNickName

string

The display name of the user.

李**

JobNumber

string

The employee ID.

A10000**

Extras

object

Additional information about the user.

AssignedResourceCount

object

The number of assigned cloud resources.

any

The supported types of cloud resources:

  • Desktop: cloud desktop.

  • DesktopGroup: shared cloud desktop.

  • CloudDrive: enterprise cloud drive (the user's personal drive).

  • APP: cloud application.

Desktop: 3

ResourcePolicyList

array<object>

object

PolicyId

string

PolicyName

string

ExternalName

string

The name of the user imported from an external source.

Note

This parameter is for internal use only.

马**

Properties

array<object>

The user properties.

object

A user property.

Key

string

The property key.

Role

Value

string

The property value.

Student

EnableAdminAccess

boolean

Indicates whether administrator access is enabled.

PasswordExpireDays

integer

PasswordExpireRestDays

integer

Examples

Success response

JSON format

{
  "RequestId": "1CBAFFAB-B697-4049-A9B1-67E1FC5F****",
  "NextToken": "caeba0bbb2be03f84eb48b699f0a4883",
  "Users": [
    {
      "Id": 0,
      "EndUserId": "alice",
      "Email": "username@example.com",
      "Phone": "1381111****",
      "Status": 0,
      "OwnerType": "Normal",
      "Remark": "Test user.",
      "OrgId": "org-4mdgc1cocc59z****",
      "WyId": "41fd1254d8f7****",
      "IsTenantManager": true,
      "Groups": [
        {
          "GroupId": "ug-12341234****",
          "GroupName": "用户组1"
        }
      ],
      "Orgs": [
        {
          "OrgId": "org-4mdgc1cocc59z****",
          "OrgName": "部门1",
          "OrgNamePath": ""
        }
      ],
      "Avatar": "https://cdn.*****",
      "Address": "杭州市***",
      "NickName": "李**",
      "RealNickName": "李**",
      "JobNumber": "A10000**",
      "Extras": {
        "AssignedResourceCount": {
          "key": "Desktop: 3"
        },
        "ResourcePolicyList": [
          {
            "PolicyId": "",
            "PolicyName": ""
          }
        ]
      },
      "ExternalName": "马**",
      "Properties": [
        {
          "Key": "Role",
          "Value": "Student"
        }
      ],
      "EnableAdminAccess": false,
      "PasswordExpireDays": 0,
      "PasswordExpireRestDays": 0
    }
  ]
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.