Solved

Export ForeignSecurityPrincipals container foreign SIDs into readable name

Posted on 2009-04-09
9
1,497 Views
Last Modified: 2012-05-06
Hi

Anyone know if there is a script where you can export the foreign SID in the ForeignSecurityPrincipals container and at the same time to dump the MemberOf of those SIDs to a file.
The memberof should be the group in our domain where the user SID a member of.

Cheers
Bry
0
Comment
Question by:bryan oakley-wiggins
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
9 Comments
 

Author Comment

by:bryan oakley-wiggins
ID: 24106047
I am currently using this bit of code (thanks to Americom) on a single SID

On Error Resume Next
 
Set objGroup = GetObject _
  ("LDAP://CN=S-1-5-21-57989841-1972579041-682003330-365065,CN=ForeignSecurityPrincipals,DC=company,DC=co,DC=uk")
objGroup.GetInfo
 
arrMemberOf = objGroup.GetEx("memberOf")
 
WScript.Echo "I'm a member of:"
For Each strMember in arrMemberOf
  WScript.echo strMember
Next


I would like to target the whole container and exoort to .csv or similar.

Cheers
Bry
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 24106234
I'll try and test later but give adfind by MVP Joe Richards a try
http://www.joeware.net/freetools/tools/adfind/index.htm
adfind -fsps objectsid memberof -csv >  c:\FSPDump.csv
See if that FSPDump.csv file on your C drive is what you need.
 Thanks
Mike
 
0
 

Author Comment

by:bryan oakley-wiggins
ID: 24107531
Hi mkline71

that's awesome..! Thanks very much for that bit of info :-)

I will research but off the top of your head, would you happen to know how I may <sidtoname> in the adfind process and have the .csv populated with the 'friendly' names?

Again, many thanks for your reply.
Cheers
Bry

0
How our DevOps Teams Maximize Uptime

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us. Read the use case whitepaper.

 
LVL 57

Expert Comment

by:Mike Kline
ID: 24109023
I'll try and test later when I get home, I'll let you know.
Thanks
Mike
0
 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24117565
Just add in the field you want to output as well such as displayname or name.

adfind -fsps displayname name objectsid memberof -csv >  c:\FSPDump.csv
0
 
LVL 23

Expert Comment

by:Stacy Spear
ID: 24117659

adfind displayname name objectsid memberof -csv > dumpfile.csv
 
Not sure what the -fsps switches are but didn't work for me.

Open in new window

0
 

Author Comment

by:bryan oakley-wiggins
ID: 24175286
Hi darkstar3d

thanks for your response - Apologies for delay in getting back, been out of the office.
I'll be back in on Monday to try further tests and update.

Cheers
Bry
0
 

Author Closing Comment

by:bryan oakley-wiggins
ID: 31568459
hi

What I done to dump out the friendly name is the following:
adfind -sc fspdmp objectsid memberof -csv > c:\dumpfile2.csv

Works for me now

I'll award points to MKLINE71 as this was the pointer that got me the solution and was pretty much close..!.

Thanks also to darkstar3d for the response - Much appreciated.

Cheers
Bry
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 24217809
Man good call, I should have gotten
-sc fspdmp
Joe has so many shortcuts that it is hard to keep track sometimes :)
Thanks
Mike
http://adisfun.blogspot.com/
 
0

Featured Post

Space-Age Communications Transitions to DevOps

ViaSat, a global provider of satellite and wireless communications, securely connects businesses, governments, and organizations to the Internet. Learn how ViaSat’s Network Solutions Engineer, drove the transition from a traditional network support to a DevOps-centric model.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ADFS trust for Skype 4 29
VB script for outlook to copy mail to OneNote 2 42
How to create a registry Subkey containing the hostname 7 38
Setting up two DCs 4 47
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question