Using Powershell against Active Directory


When we had Windows 2003 servers, I used the Quest ActiveRoles product quite a lot to run Powershell written queries against our Active Directory.

We now have Windows 2008 R2 servers, and I understand those commands are included in the native Powershell installation?

I was wondering someone could help me with a query I had -

We have about 500 service accounts in our AD, all starting with the word "service". They are also located in the same OU (domain>Special>Service)

I would like to run a Powershell query to list all of this accounts into a text file. I would also like there to be a carriage return after each entry.

Does anyone know how I can achieve this?
Who is Participating?
mittermuellerConnect With a Mentor Commented:
Get-ADUser -Filter { CN -like "Service*" } | select name | export-csv c:\sas.csv

the 2008R2 cmdlets are real similar to the ones quest has

get-aduser -searchbase "OU=Service,OU=Special,DC=Domain,DC=local" -Filter * | select name | export-csv c:\servcieaccounts.csv
daveTechSearchConnect With a Mentor Commented:
I believe you also need to use the AD Management gateway service on at least one DC:

Tutorial on managing AD with the cmdlets (video):

Download for the web service:
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

tomd1976Author Commented:
Thanks all

With Quest, I needed to attach to a DC/GC with a user account, do I need to do that here too?
If you are running from your workstation you have a few options

1. use windows 7 or 2008R2 and add the AD module
import-module activedirectory

2. Use WinRM to remote into the DC if you have that enabled.
tomd1976Author Commented:
Thanks all, I used this and it works fine:

Get-ADUser -Filter { CN -like "Service*" } | select name | export-csv c:\sas.csv

A couple of related questions...

If I run:

Get-ADUser -Filter { CN -like "Service*" }

Then I get a list of account with the word "service" in them.  Couple of questions/;

1. Is it possible to have the search query look for entries that start with "service" rather than just contain it?

2.  The results only show certain attributes? How can I expand that to include attributes such as email address?
KenMcFConnect With a Mentor Commented:
You can use this depending on how the account are setup.

Get-ADUser -Filter { Name -like "Service*" }

To get other attribues

Get-ADUser -Filter { Name -like "Service*" } -properties mail  | select Name, mail

tomd1976Author Commented:
Perfect, thanks so much!
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.