Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

How do i get all users that belongs to a group (nestled?

Posted on 2008-10-06
7
366 Views
Last Modified: 2013-12-24
Hello!
I'm having a problem getting all users that belong to a group in AD, I want all users even the ones from the "subgroups" (nestled?).

Im using Visual Studio 2005  (.net 2.0) and Active Directory 2003. I know that I have to use some recursive method but I dont know where to begin.

Cheers Ola
0
Comment
Question by:Ola_Adolfsson
  • 5
  • 2
7 Comments
 
LVL 70

Accepted Solution

by:
Chris Dent earned 125 total points
ID: 22648318

Hey again Ola,

I thought this was the same as your last question for a moment :)

It's almost the same as the last, the difference is we need to introduce object class checking before we recurse through the members.

And we need to introduce a limitation that I didn't raise last time:

The Primary group on an account is not reflected in either the memberOf or member attributes instead it is set by primaryGroupToken on the group and primaryGroupID on the user. Normally this only means we have to worry about Domain Users, but in some cases the Primary Group is changed. Is chasing down membership and nested membership of the Primary group a requirement?

Here's the first sample, by recursion. It's not exactly fast.

Chris
        private void button1_Click_1(object sender, EventArgs e)
        {
            String baseGroup = "CN=Some Group,OU=Imported,OU=Groups,DC=corp,DC=monitise,DC=net";
 
            label1.Text = "";
            GetMembers(baseGroup);
        }
 
        protected void GetMembers(string objectDN)
        {
            DirectoryEntry currentObject = new DirectoryEntry("LDAP://" + objectDN);
 
            foreach (object groupMember in currentObject.Properties["member"])
            {
                String groupMemberDN = groupMember.ToString();
                DirectoryEntry memberObject = new DirectoryEntry("LDAP://" + groupMemberDN);
                if (memberObject.Properties["objectClass"][1].ToString() == "group")
                {
                    GetMembers(groupMemberDN);
                }
                else
                {
                    label1.Text = label1.Text + groupMemberDN + "\n";
                }
            }
        }

Open in new window

0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 22648347

And this version covers the pure LDAP version, in the same way as before this is limited to Windows 2003 SP1 and above (but is much less complex).

Chris
        private void button1_Click(object sender, EventArgs e)
        {
            String domainGroup = "CN=Some Group,OU=Imported,OU=Groups,DC=corp,DC=monitise,DC=net";
 
            DirectoryEntry domainRoot = new DirectoryEntry();
            String filter = "(memberOf:1.2.840.113556.1.4.1941:=" + domainGroup + ")";
            DirectorySearcher domainSearch = new DirectorySearcher(domainRoot, filter);
 
            SearchResultCollection domainSearchResults = domainSearch.FindAll();
 
            label1.Text = "";
            foreach (SearchResult domainSearchResult in domainSearchResults)
            {
                label1.Text = label1.Text + domainSearchResult.Properties["distinguishedName"][0].ToString();
                label1.Text = label1.Text + "\n";
            }
        }

Open in new window

0
 

Author Comment

by:Ola_Adolfsson
ID: 22648858
Hello again Sage ;)
I tried your first solution and it works fine. But I want only the users, now I get users and computers;).
I guess that I can check the ["objectClass"] if its a computer but is there a better way? Which of these solutions do you recommend?

Cheers Ola
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 70

Expert Comment

by:Chris Dent
ID: 22648933

The second one would allow immediate filtering, it's by far the simpler of the two so if you can use that one I do advise it.

It we take that one as an example all we'd have to do is extend the filter to this:

            String filter = "(&(objectClass=computer)(memberOf:1.2.840.113556.1.4.1941:=" + domainGroup + "))";

For the first we're stuck with checking the objectClass or performing a new search (which may actually be quicker / neater), let me have a quick check on that.

Chris
0
 

Author Comment

by:Ola_Adolfsson
ID: 22649826
Hi Chris!
Does the second solution provide nestled search?

Cheers Ola
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 22650537

It does, yes. All of the above do :)

Let me just pop the last version together so you can try each out. It just reduces the number of connections to AD (at the moment it's one per group member).

Chris
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 22650847

Hmm okay, here's the update. I'm still not convinced about the speed of the search, it seems slow. If the OID based query works for you I'd stick with that (that's the one with "1.2.840.113556.1.4.1941" in it).

Otherwise, this is a modification on the recursive method. Fewer connections to AD, but each carries a higher cost, it doesn't really give us much of a performance gain (if any). It could well be that it's just a limitation of my ability to program despite being an admin.

Chris
        private void button1_Click(object sender, EventArgs e)
        {
            String baseGroup = "CN=Some Group,OU=Groups,DC=domain,DC=com";
            // A connection to the domain root as a search base
            DirectoryEntry domainObject = new DirectoryEntry();
 
            label1.Text = "";
            GetMembers(baseGroup, domainObject);
        }
 
        protected void GetMembers(string objectDN, DirectoryEntry domainObject)
        {
            // Search to get nested groups in current group
 
            String groupFilter = "(&(objectClass=group)(memberOf=" + objectDN + "))";
            DirectorySearcher groupSearch = new DirectorySearcher(domainObject, groupFilter);
            SearchResultCollection groupResults = groupSearch.FindAll();
            
            foreach (SearchResult groupResult in groupResults)
            {
                // Recurse
                GetMembers(groupResult.Properties["distinguishedname"][0].ToString(), domainObject);
            }
 
            // Search to get members (computers) in current group
 
            String computerFilter = "((objectClass=computer)(memberOf=" + objectDN + "))";
            DirectorySearcher computerSearch = new DirectorySearcher(domainObject, computerFilter);
            SearchResultCollection computerResults = computerSearch.FindAll();
 
            foreach (SearchResult computerResult in computerResults)
            {
                label1.Text = label1.Text + computerResult.Properties["distinguishedName"][0].ToString() + "\n";
            }
        }

Open in new window

0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question