Solved

Query regarding AD import

Posted on 2008-10-04
5
270 Views
Last Modified: 2013-12-24
Hi

We are running a Windows 2003 Active Directory forest, comprising of two domains.

The forest root is kam.com, the domains are uk.kam.com and us.kam.com

We have a new application and we'd like to import a list of users from our AD forest.

Does anyone know how to do this and what sort of permissions the account that runs the query will need?

Thanks!!
0
Comment
Question by:kam_uk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 3

Author Comment

by:kam_uk
ID: 22640599
...and if we need to import data from the forest, do we need to set the application to query a Global Cat Domain Controller, and why?
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 22641174
Depends of the format of requested data, but you can use csvde, ldifde or dsquery/dsget to export the data.

csvde -f export.csv -d "DC=uk,DC=kam,DC=com" -r "(ldap-filter-criteria)" -l "field list"
csvde -f export.csv -d "DC=uk,DC=kam,DC=com" -r "(ldap-filter-criteria)" -l "field list"
dsquery user DC=uk,DC=kam,DC=com
dsquery user DC=uk,DC=kam,DC=com|dsget user -samid

see 'csvde /?', 'ldifde /?', 'dsquery user /?', 'dsget user /?' for help of the commands
0
 
LVL 3

Author Comment

by:kam_uk
ID: 22644143
thanks...and what sort of user permissions would the account that pulls this information need?
0
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 500 total points
ID: 22644508
No special permissions should be necessary. If user has logon access to AD-domain, he has normally also read access to the requested objects/attributes.

I forgot to mention one thing about dsquery command. You may nead to add '-limit 0' as argument to the command or you will by default only get the first 100.

0
 
LVL 3

Author Comment

by:kam_uk
ID: 22646122
...and if we need info for the entire forest, do we need to query a GC, or will any DC do?
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to protecting Oracle Database servers and systems, there are a ton of myths out there. Here are the most common.
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question