• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1194
  • Last Modified:

AD Primary Group - LDAP problem

I know how to take a users PrimaryGroupID and get the Primary Group that the user belongs to.  My problem is going the other way .... for example, taking the Domain Users group and trying to determine all users in that group (even the ones that have it set as their Primary Group).

What are some ways of doing this?  Is it something like getting all User objects in a Domain, then looping through all of them seeing which objects have that group set as their Primary group?
0
249Central
Asked:
249Central
1 Solution
 
EDDYKTCommented:
?

Dim grp
Dim memberList
Dim member

Set grp = GetObject("WinNT://yourdomain/yourdomaingrpname")
Set memberList = grp.members
For Each member In memberList
  Debug.Print member.Name & "(" & member.Class & ")"
Next
0
 
dlwyatt82Commented:
Bind to the group and get the value of the "primaryGroupToken" attribute.  Then execute a search for users where "primaryGroupID = primaryGroupTokenValue":

'***************************

Set objGroup = GetObject("LDAP://CN=Whatever,DC=domain,DC=com")
objGroup.GetInfoEx Array("primaryGroupToken"), 0
intToken = objGroup.Get("primaryGroupToken")

Set objCon = CreateObject("ADODB.Connection")
Set objCmd = CreateObject("ADODB.Command")

objCon.Open "Provider=ADsDSOObject;"
Set objCmd.ActiveConnection = objCon

objCmd.CommandText = "SELECT sAMAccountName FROM 'LDAP://DC=domain,DC=com' WHERE " & _
    "objectCategory='person' AND objectClass='user' AND primaryGroupID='" & intToken & "'"

Set objRS = objCmd.Execute

Do While (Not objRS.EOF)
  WScript.Echo objRS("sAMAccountName")
  objRS.MoveNext
Loop
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now