CodeBAdminCLI.exe is the command-line tool for administrators. It links card serials to users as a second factor in Active Directory (/add2fa), stores encrypted credential tokens in AD (/add2ad) or as files (/add2fs), lists and removes assignments, and changes a user’s AD password while updating the stored token (/changepw). It needs a valid licence.
Overview
The CLI automates what the GUI linkers do, so one admin workstation can enrol cards for the whole company from a script. It works against Active Directory and local accounts. Download: CodeBAdminCLI.zip (also on the downloads page).
Run CodeBAdminCLI.exe /help (or /h, /?) for the built-in help.
Syntax
CodeBAdminCLI.exe /command [/parameter value] …
- Switches start with
/,-or--. - A value can follow after a space, a colon or an equals sign:
/pin 1234,/pin:1234and/pin=1234are the same. - Several commands can be given in one call; they run in this order:
/clearad,/add2fa,/changepw,/add2ad,/add2fs,/deletecard,/list2fa,/list2facards,/list2adcards.
Commands
| Command | What it does | Needs |
|---|---|---|
/add2faalias /2fa | Adds a card serial as a second factor to the user in AD. Command-line equivalent of LinkNFC2AD.exe. | /user, /cardserial |
/add2adalias /2ad | Adds (or updates) the encrypted credential token in AD, as LinkNFCCard.exe does with “Store Data in AD”. Run it again with another serial to add another card. | /user, /password, /cardserial |
/add2fsalias /softtoken | Creates the encrypted soft token as a file (<SERIAL>.b64) in the data folder, as LinkNFCCard.exe does without AD. | /user, /password, /cardserial |
/list2facards | Lists all card serials assigned as a second factor to a user. | /user |
/list2adcards | Lists all card serials that can log the user on (tokens stored in AD). | /user |
/list2fa | Reverse lookup: which user a card serial is assigned to. | /cardserial |
/deletecard | Cleanup: removes the card from the 2FA records and from the credential tokens (in AD and in the data folder). | /cardserial; /user for the AD part |
/changepw | Changes the AD password of the user and updates the soft token stored in AD, so card logon keeps working. | /user, /password (current), /newpassword |
/clearadalias /cad | Removes all CodeB card links and token data from the user’s AD object. | /user |
Parameters
| Parameter | Meaning | Default / notes |
|---|---|---|
/user-u | The user (sAMAccountName) being managed. | May also be given as DOMAIN\user; the domain part then replaces /domain. |
/domain-d | The logon domain of the user. | — |
/cardserial/serial, /s | The UID of the NFC card (hex). | — |
/password/pass, -p | The user’s password; for /changepw the current password. | Required for /add2ad, /add2fs, /changepw. |
/newpassword/newpass, /npwd | The new password for /changepw. | — |
/pin | The PIN for logon with this card. | When omitted: the configured default PIN (DefaultSerialPIN, normally 0000 = card-only logon). |
/action-a | What happens when the card is removed: 1 lock screen, 2 log off. | 0 = nothing; any other value counts as 0. |
/datafolder | Where /add2fs writes the token file. | Must be a path containing \. Default: the DataFolder registry value, else C:\ProgramData\CodeB\. |
/note | A comment stored with the soft token. | — |
Examples
:: 1. link a card to a user as second factor in AD
CodeBAdminCLI.exe /add2fa /user stefan /domain CodeB /serial AAFFBBCC
:: 2. store the encrypted credential token in AD (card + PIN 1234)
CodeBAdminCLI.exe /add2ad /user stefan /domain CodeB /password letmein /serial AAFFBBCC /pin:1234
:: ... and a second card for the same user
CodeBAdminCLI.exe /add2ad /user stefan /domain CodeB /password letmein /serial CCDDEEFF /pin:0155
:: 3. create a soft token file on a share, lock the screen on card removal
CodeBAdminCLI.exe /add2fs /user CodeB\stefan /password letmein /serial AAFFBBCC /action 1 /datafolder \\server\codeb\
:: 4. list all second-factor cards of a user
CodeBAdminCLI.exe /list2facards /user stefan /domain CodeB
:: 5. which user owns this card?
CodeBAdminCLI.exe /list2fa /serial AAFFBBFF
:: 6. remove a card everywhere (lost card)
CodeBAdminCLI.exe /deletecard /cardserial AAFFBBFF /user stefan
Password rotation without breaking card logon
/changepw sets the new AD password and updates the encrypted soft token stored for the user in AD in the same call. Card logon keeps working — no re-enrolment and no window in which the stored password is outdated.
CodeBAdminCLI.exe /changepw /user testuser /domain codeb /password oldalibaba /newpassword newalibaba
Bulk enrolment from a CSV file
Example PowerShell loop over a CSV with the columns User,Domain,Serial,Pin. It links each card as a second factor and reports failures by exit code. Adapt it to /add2ad if the token itself should be stored in AD (then a password column is needed).
# cards.csv: User,Domain,Serial,Pin
$cli = "C:\Tools\CodeB\CodeBAdminCLI.exe"
Import-Csv .\cards.csv | ForEach-Object {
& $cli /add2fa /user $_.User /domain $_.Domain /serial $_.Serial
if ($LASTEXITCODE -ne 0) { Write-Warning "$($_.User): exit code $LASTEXITCODE" }
}
Exit codes
| Code | Meaning |
|---|---|
0 | Finished (also after /help). Read the console output for the result of each command. |
1 | Invalid command line (unknown switch or missing value). |
1002 | The PC is in a domain but no domain controller answered: the Active Directory steps were not done (the tool says so). Run the command again with a connection to the domain. |
9999 | Not licensed. The tool prints “Software is not licensed. Contact info@aloaha.com” and does nothing. |
| other | A command failed; the console output names the command. |
Security notes
- Passwords given on the command line can end up in shell history, script files and process lists. Run the CLI on a protected admin workstation, read passwords from a secure source in your script and delete temporary CSV files afterwards.
- With AD storage, only the
altSecurityIdentitiespermission is needed (see storage); no local administrator rights are required on the target PCs. - A card linked with the default PIN (
0000unlessDefaultSerialPINsays otherwise) logs on with the tap alone. Use/pinwhen you want card + PIN.
Frequently asked questions
Does CodeBAdminCLI need local administrator rights?
Not for Active Directory operations when the AD permission on altSecurityIdentities is delegated correctly. Writing soft tokens into a protected local data folder needs rights on that folder.
Can I enrol hundreds of cards from a CSV file?
Yes. Loop over the CSV in PowerShell and call CodeBAdminCLI.exe /add2ad or /add2fa per row — see the bulk example. Check the exit code of each call.
Is the card serial the same as the number printed on the card?
Not necessarily. The CLI expects the card UID in hexadecimal as the reader reports it, for example 042C69DA562280. LinkNFCCard.exe shows the UID when the card is placed on the reader.