Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

DSQuery command with a not equal to syntax??

Posted on 2010-11-17
4
Medium Priority
?
1,597 Views
Last Modified: 2012-05-10
I have successfully run a dsquery to find accounts  with a primary group of domain users.  
 Is it possible to run a dsquery to users whos primary group is not equal to a group ID. Thank you
0
Comment
Question by:ejmeado
  • 2
  • 2
4 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 34159774
Put a not character (!) in front of the primarygroupid in your query

example  !primarygroupid=512

Thanks

Mike
0
 

Author Comment

by:ejmeado
ID: 34160069
Thank you Mike,  I tried the ! it in front of the =, the query ran without an output.  I will test it in the morining.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 34160582
Do it in front of the primary;  see my screenshot using adfind by Joe Richards  http://www.joeware.net/freetools/tools/adfind/index.htm

I first looked for all accounts who had a primarygroupid of 513   then added the not! and it only returned the account that didn't have 513 as its primary group

513 is Domain Users

Thanks

Mike
primarygroupid.png
0
 

Author Comment

by:ejmeado
ID: 34167941
Thank you, that worked a treat.
0

Featured Post

NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
Transferring FSMO roles is done when an admin wants to split roles between certain Domain Controllers or the Domain Controller holding the Roles has been forcefully demoted using dcpromo / forceremoval
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question