LDAP does not enumerate all members of a AD group
Posted on 2003-11-12
We are running Windows 2000, Active Directory in native mode. We upgraded our existing NT 4 domain and migrated all the user accounts and groups (there are no more NT 4 Domain Controllers).
When I use the "Active Directory Users and Computers" snap-in to view a particular group on the Domain, I see 54 members. However, when I use Linux "ldapsearch" or even a VBS script using LDAP, I only see 27 members.
However, when I use some of my old perl scripts I used on our old NT 4 Domain and query the same group, I see all 54 members. I have searched Microsoft's KB site and the web but can not find anything that explains this discrepancy.
I would like to use VBS and LDAP to administer my AD but if it is not consistent, I'm going to have problems.