Solved

How I do enumerate users of a group in a nested OU

Posted on 2010-09-16
2
958 Views
Last Modified: 2012-06-21
Goal: Setup Mailbox Mgr (Exchange 2003) to manage size of mailboxes using custom search/ldap query for members of a group where the group is in a nested OU

Issue: My ldap query below only returns users if the group is in a NON-nested OU -

(objectCategory=user)(memberOf=CN=GROUP,OU=OU,DC=DOMAIN,DC=com)

How can i alter my ldap query so it will return members of a security group in a nested OU so i dont have to change my AD layout - Below is how I have the layout

domain
   OU
       OU
          Group
0
Comment
Question by:SHAX
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 33693223
The DN or your group should be something like  CN=group,OU=nestedOU1,OU=nestedOU2,DC=domain,DC=com.  I'll test later but it should pick it up
 
Thanks
Mike
0
 

Author Comment

by:SHAX
ID: 33700961
that worked - it appears the sub OU goes 1st and the parent OU is 2nd - you got me on the right track -

Thanks -
0

Featured Post

Is Your DevOps Pipeline Leaking?

Is your CI/CD pipeline a hodge-podge of randomly connected tools? You’ve likely got a tool to fix one problem & then a different tool to fix another, resulting in a cluster of tools with overlapping functionality. Learn how to optimize your pipeline with Gartner's recommendations

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question