Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Find unused groups in Active Directory

Posted on 2004-04-15
4
961 Views
Last Modified: 2007-12-19
Are there any utilities that search for groups in active directory that are unused and  don't have any permissions assigned to them?

W2k Server.

Thanks
0
Comment
Question by:wickednz
  • 3
4 Comments
 
LVL 3

Expert Comment

by:following
ID: 10841735
Here is a link to an excellent post about searching AD for groups that have no members:

http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&selm=uWSeykPNDHA.2408%40TK2MSFTNGP10.phx.gbl&rnum=2

Although this looks like a good place to start for you, be sure to note the limitations that are described.

Hope this helps,
-jdm
0
 
LVL 3

Expert Comment

by:following
ID: 10841793
This one may be of interest to you as well:

http://www.rlmueller.net/Document%20Domain%20Groups.htm

jdm
0
 

Author Comment

by:wickednz
ID: 10854703
Thanks - those scripts could be useful but I'm more after something that can find out if a group is used anywhere on a server - eg: having directory rights
0
 
LVL 3

Accepted Solution

by:
following earned 250 total points
ID: 10859852
Aha, I'm sorry that I misunderstood the question.  In that case, the simplest way I know of to find out if a group is used anywhere on a server:

 - Run Somarsoft's freeware DumpSec utility (formerly DumpACL) on the server
 - Use the utility's built-in search capabilities to search for instances of the groups in question
 - If you find an instance of a group listed, you will be able to see on which files/folders it is being used

DumpSec (freely downloadable from http://www.systemtools.com/somarsoft) may be used to dump the permissions for the file system, printers, registry, and shares.  If you need to dump the permissions on active directory objects, use DSACLS from the Windows 2000 Support Tools (on the server CD).  Redirect its output to a text file and use an editor such as notepad to search for the groups in question.

Hope this helps,
-jdm
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This is the first one of a series of articles I’ll be writing to address technical issues that are always referred to as network problems. The network boundaries have changed, therefore having an understanding of how each piece in the network  puzzl…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

792 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question