Solved

Query regarding AD import

Posted on 2008-10-04
5
265 Views
Last Modified: 2013-12-24
Hi

We are running a Windows 2003 Active Directory forest, comprising of two domains.

The forest root is kam.com, the domains are uk.kam.com and us.kam.com

We have a new application and we'd like to import a list of users from our AD forest.

Does anyone know how to do this and what sort of permissions the account that runs the query will need?

Thanks!!
0
Comment
Question by:kam_uk
  • 3
  • 2
5 Comments
 
LVL 3

Author Comment

by:kam_uk
ID: 22640599
...and if we need to import data from the forest, do we need to set the application to query a Global Cat Domain Controller, and why?
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 22641174
Depends of the format of requested data, but you can use csvde, ldifde or dsquery/dsget to export the data.

csvde -f export.csv -d "DC=uk,DC=kam,DC=com" -r "(ldap-filter-criteria)" -l "field list"
csvde -f export.csv -d "DC=uk,DC=kam,DC=com" -r "(ldap-filter-criteria)" -l "field list"
dsquery user DC=uk,DC=kam,DC=com
dsquery user DC=uk,DC=kam,DC=com|dsget user -samid

see 'csvde /?', 'ldifde /?', 'dsquery user /?', 'dsget user /?' for help of the commands
0
 
LVL 3

Author Comment

by:kam_uk
ID: 22644143
thanks...and what sort of user permissions would the account that pulls this information need?
0
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 500 total points
ID: 22644508
No special permissions should be necessary. If user has logon access to AD-domain, he has normally also read access to the requested objects/attributes.

I forgot to mention one thing about dsquery command. You may nead to add '-limit 0' as argument to the command or you will by default only get the first 100.

0
 
LVL 3

Author Comment

by:kam_uk
ID: 22646122
...and if we need info for the entire forest, do we need to query a GC, or will any DC do?
0

Join & Write a Comment

Creating and Managing Databases with phpMyAdmin in cPanel.
Never store passwords in plain text or just their hash: it seems a no-brainier, but there are still plenty of people doing that. I present the why and how on this subject, offering my own real life solution that you can implement right away, bringin…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now