Business group managers and tenant administrators can entitle the service and the resource action to a user or a group of users. After they are entitled, they can see the service in their catalog and request the Create a test user catalog item that is included in the service. After the consumers provision the item, they can request to change the user password.



  1. Select Administration > Catalog Management > Entitlements.
  2. Click the New icon (Add).
  3. Enter Create an Active Directory user in the Name text box.
  4. Leave the Description and Expiration Date text boxes empty.
  5. Select Active from the Status drop-down menu.
  6. Select the target business group from the Business Group drop-down menu.
    For example, IT account managers.
  7. Select All Users and Groups to entitle all the members of the business group, for example, IT account managers, to create a user account.
    The users that you select can see the service and the catalog items included in the service in the catalog. They can run the change password action on the user account after it is created.
  8. Click Next.
  9. In the Entitled Services text box, enter Active Directory Test User and press Enter.
  10. In the Entitled Actions text box, enter Change the password of the Test User and press Enter.
  11. Click Finish.


You created an active entitlement so that users who are members of the IT account managers business group can create users. After the user is provisioned, they can run the change password resource action on the provisioned user account.

What to do next

Log in as user who is entitled to create an Active Directory user. On the Catalog tab, verify that the XaaS blueprint creates the user as expected. After the user is created, run the change password action from the Items tab.