How do I LDAP active users from AD

Posted on 2010-11-17
Last Modified: 2013-12-24
Hi All,

I have a query and desperetly need some advise :)

I need to LDAP all active users from AD. I'm very fresh to LDAP scripts (I can do OU=xxx,DC=company,dc=com ;) so I'm not sure how to script the filter.
Got this so far but it is not working (&(&(objectClass=user)(OU=company Users,DC=company,DC=com)))

I thought I will add a LDAP browser image to help out.

Any help will be greately apprecaited. Thanks :)

Question by:aaromba
  • 3
  • 3

Expert Comment

ID: 34153514
(&(&(objectClass=user)(CN=company Users,DC=company,DC=com)))
LVL 70

Expert Comment

by:Chris Dent
ID: 34153720

You cannot filter based on OU within an LDAP query, you have to set a Search Root / Base for the query.


Author Comment

ID: 34154779
Thanksfor your feedback guys. Much appreciated.  

decasey, for some strange reason your query does not work. Perhaps this is my soft limitation.

Chris, I'm not sure (lack of experience in LDAP) what do you mean by set a search root / base for the query. Could you be a bit more specific please :) I'm an LDAP blond haha

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

LVL 70

Expert Comment

by:Chris Dent
ID: 34154820

What are you using to do the query? Perhaps we can provide something with a bit more context? :)


Author Comment

ID: 34160748
sorry for late reply (Perth time :)
I am using HEAT (Service Desk app) LDAP. I have attached the screenshot of how it looks. Seems that I cannot use filters in Base DN. I can filter it using Object Classes (I believe, need to test it) below)   AD!
LVL 70

Accepted Solution

Chris Dent earned 500 total points
ID: 34162291
Ahh okay, so the Search Root is the Base DN value. If you only want to return users from a specific section of AD you'd enter a value into there. It looks like it may have a browse function linked with that Add button?

If not, the format for base DN will be:

OU=Users,OU=Lander Toyota,OU=NSW,DC=yourdomain,DC=com

That means that the filter, the search, is only applied to objects within that folder (and beneath that folder).

It looks like you can add more than one Base DN, which is refreshing :)

Does that do what you need to do?


Author Comment

ID: 34163877
Ha! Chris This has worked beautifully! Thank you very much for your help mate!! Much appreciated!

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

This article explains all about SQL Server Piecemeal Restore with examples in step by step manner.
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
Video by: Steve
Using examples as well as descriptions, step through each of the common simple join types, explaining differences in syntax, differences in expected outputs and showing how the queries run along with the actual outputs based upon a simple set of dem…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now