Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Query regarding AD import

Posted on 2008-10-04
5
Medium Priority
?
275 Views
Last Modified: 2013-12-24
Hi

We are running a Windows 2003 Active Directory forest, comprising of two domains.

The forest root is kam.com, the domains are uk.kam.com and us.kam.com

We have a new application and we'd like to import a list of users from our AD forest.

Does anyone know how to do this and what sort of permissions the account that runs the query will need?

Thanks!!
0
Comment
Question by:kam_uk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 3

Author Comment

by:kam_uk
ID: 22640599
...and if we need to import data from the forest, do we need to set the application to query a Global Cat Domain Controller, and why?
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 22641174
Depends of the format of requested data, but you can use csvde, ldifde or dsquery/dsget to export the data.

csvde -f export.csv -d "DC=uk,DC=kam,DC=com" -r "(ldap-filter-criteria)" -l "field list"
csvde -f export.csv -d "DC=uk,DC=kam,DC=com" -r "(ldap-filter-criteria)" -l "field list"
dsquery user DC=uk,DC=kam,DC=com
dsquery user DC=uk,DC=kam,DC=com|dsget user -samid

see 'csvde /?', 'ldifde /?', 'dsquery user /?', 'dsget user /?' for help of the commands
0
 
LVL 3

Author Comment

by:kam_uk
ID: 22644143
thanks...and what sort of user permissions would the account that pulls this information need?
0
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 2000 total points
ID: 22644508
No special permissions should be necessary. If user has logon access to AD-domain, he has normally also read access to the requested objects/attributes.

I forgot to mention one thing about dsquery command. You may nead to add '-limit 0' as argument to the command or you will by default only get the first 100.

0
 
LVL 3

Author Comment

by:kam_uk
ID: 22646122
...and if we need info for the entire forest, do we need to query a GC, or will any DC do?
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question