Query an Active Directory Organizational Unit

Posted on 2004-09-16
Last Modified: 2008-01-09

How can I query the active directory organization unit for users.

Thanks for the help, Nauman.
Question by:nauman_ahmed
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 2
  • +1
LVL 33

Expert Comment

ID: 12078641
Depends on what you need to do, do you just need to get all the users in that OU? or query for a particular user in a particular OU?

You'd start out with a DirectorySearcher, that is instantiated something like this.

Dim oRootDSE As DirectoryEntry = New DirectoryEntry("LDAP://rootDSE")
sDomain = CStr(oRootDSE.Properties("defaultNamingContext")(0))

Dim entry as DirectoryEntry = New DirectoryEntry("LDAP://" & sDomain & ",OU=SOME_OU")
Dim searcher As DirectorySearcher = New DirectorySearcher(entry)

LVL 25

Author Comment

ID: 12078719
Thanks for the reply michael.

I need to grab the list of users from the organizational unit.

LVL 25

Author Comment

ID: 12078773
I am trying to connect to the domain controller using IP address. However cannot make LDAP://,OU=ADMIN_USERS work. LDAP:// is working fine.

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 33

Accepted Solution

raterus earned 400 total points
ID: 12078858
I think I missed a "/", sorry


if that doesn't work, you might try this

Dim entry as DirectoryEntry = New DirectoryEntry("LDAP://")
DirectoryEntry ou = entry.Children.Find("OU=ADMIN_USERS");


Assisted Solution

by:Volkan Vardar
Volkan Vardar earned 100 total points
ID: 12083083
there is an article about this issue in
LVL 25

Author Comment

ID: 12086749
Thanks raterus. LDAP:// didnt work, but your second option worked. I have another question. This piece of code is giving me The Network path could not be found exception.  I am trying to reset user password but still dont have any luck. Its in c# but I think its easy to understand. If you have any code, please paste it. I can translate that into C#:

DirectoryEntry entry = new DirectoryEntry("LDAP://","dmain\\administrator","admin",AuthenticationTypes.Secure);
                        object native = entry.NativeObject;
                        Console.WriteLine("User authenticated.");
                        DirectoryEntry ou = entry.Children.Find("OU=ADMIN_USERS");
                        DirectorySearcher srch = new DirectorySearcher(ou);
                        srch.Filter = "samaccountname=ap_admin";
                        SearchResult search = srch.FindOne();

                        DirectoryEntry user = search.GetDirectoryEntry();
                        user.Properties["description"].Value = "abcasaasasasasa";
                        object[] obj = {"aaa"};

Thanks, Nauman.
LVL 25

Author Comment

ID: 12086825
Actually this was an authentication problem and was b/c of using AuthenticationTypes.Secure seting. AuthenticationTypes.Signing or AuthenticationTypes.Sealing worked in changing the password. Thanks for the hielp.

LVL 20

Expert Comment

ID: 12086991
You can use DirectorySearcher to query users in a organizational unit, it is much faster than other way. It returns SearchResultCollection which contains user object collection. And at each user object you can retrieve information like login name, email and many other but not password because it is write-only attribute. Password in AD is a complicated thing and there's no way to do so that I'm aware of. But you can always create a custom attribute to store user password and retrieve it back at any time.

Dim baseDN As String = "LDAP://oneCity/OU=Users,DC=oneCity,DC=com"
Dim filter As String = "(&(objectClass=user)(objectCategory=person))"
Dim searcher As DirectorySearcher


    searcher = New DirectorySearcher
    searcher.SearchRoot = New DirectoryEntry(baseDN)
    searcher.SearchScope = SearchScope.Subtree
    searcher.Filter = filter
    Dim results As SearchResultCollection = searcher.FindAll()
    For Each result As SearchResult In results
      'each SearchResult object here is a AD user class
      Dim loginName As String = CType(result.Properties("cn")(0), String)
      Dim email As String = CType(result.Properties("mail")(0), String)

Catch ex As Exception

    If Not IsNothing(searcher) Then
    End If
End Try

LVL 25

Author Comment

ID: 12089066
Thanks for the resposne ihenry. But here I am with another problem :( Things work fine on console application but and once in but after that page stopped working and it gave the following exception:

 System.Runtime.InteropServices.COMException: One or more input parameters are invalid
System.RuntimeType.InvokeDispMethod(String name, BindingFlags invokeAttr, Object target, Object[] args, Boolean[] byrefModifiers, Int32 culture, String[] namedParameters) +0
   System.RuntimeType.InvokeMember(String name, BindingFlags invokeAttr, Binder binder, Object target, Object[] args, ParameterModifier[] modifiers, CultureInfo culture, String[] namedParameters) +473
   System.Type.InvokeMember(String name, BindingFlags invokeAttr, Binder binder, Object target, Object[] args) +29
   System.DirectoryServices.DirectoryEntry.Invoke(String methodName, Object[] args) +106

The line that giving exception is user.Invoke("SetPassword",obj); The other update work fine.

I can open a separate question if you would like.

Thanks for the help, Nauman.
LVL 20

Expert Comment

ID: 12089825
what's the obj variable? SetPassword should be used like the following:
user.Invoke("SetPassword", new object[]{"" + NewPassword + ""});
LVL 20

Expert Comment

ID: 12089975
Change password using SetPassword is a bit tricky. How are you invoking the SetPassword method? what user are you binding to active directory with? and are you binding using secure channel?

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Just a quick little trick I learned recently.  Now that I'm using jQuery with abandon in my applications, I have grown tired of the following syntax:      (CODE) I suppose it just offends my sense of decency to put inline VBScript on a…
This article discusses the ASP.NET AJAX ModalPopupExtender control. In this article we will show how to use the ModalPopupExtender control, how to display/show/call the ASP.NET AJAX ModalPopupExtender control from javascript, how to show/display/cal…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question