Solved

How I do enumerate users of a group in a nested OU

Posted on 2010-09-16
2
956 Views
Last Modified: 2012-06-21
Goal: Setup Mailbox Mgr (Exchange 2003) to manage size of mailboxes using custom search/ldap query for members of a group where the group is in a nested OU

Issue: My ldap query below only returns users if the group is in a NON-nested OU -

(objectCategory=user)(memberOf=CN=GROUP,OU=OU,DC=DOMAIN,DC=com)

How can i alter my ldap query so it will return members of a security group in a nested OU so i dont have to change my AD layout - Below is how I have the layout

domain
   OU
       OU
          Group
0
Comment
Question by:SHAX
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 33693223
The DN or your group should be something like  CN=group,OU=nestedOU1,OU=nestedOU2,DC=domain,DC=com.  I'll test later but it should pick it up
 
Thanks
Mike
0
 

Author Comment

by:SHAX
ID: 33700961
that worked - it appears the sub OU goes 1st and the parent OU is 2nd - you got me on the right track -

Thanks -
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange in house vs office 365 for security 6 46
query all mailbox rules 5 31
exchange 13 24
DHCP 50/50 Split Scope seems to favor 1 group 2 11
This article runs through the process of deploying a single EXE application selectively to a group of user.
How to resolve IMCEAEX NDRs in Exchange or Exchange Online related to invalid X500 addresses.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question