?
Solved

Help with VBS script and extracting user info from AD

Posted on 2010-11-18
1
Medium Priority
?
1,104 Views
Last Modified: 2012-08-13
I have the script attached that I want to modify.  I am not a programmer by any stretch of the imagination.  I cannot find some of the user object attributes that I need, and the ones that I found I cannot get any output when I run the script.  I used both ADSI Edit and CSVDE -f Exportfile.csv to try and identify the attributes that I need.

I want to keep what it has so far and add the following to the script.
PswdCanBeChanged, PswdLastSetTime, PswdRequired, PswdExpires, PswdExpiresTime,AcctDisabled, AcctLockedOut, AcctExpiresTime,LastLogonTime, LastLogonServer, LogonHours , group membership
test-ad.vbs
0
Comment
Question by:asrvwiz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 71

Accepted Solution

by:
Chris Dent earned 2000 total points
ID: 34187260
I advise you use PowerShell and Quests AD CmdLets to get these if you have no existing scripting background. You can download those here:

http://www.quest.com/powershell/activeroles-server.aspx

With that, you can get an approximation of this with:
Get-QADUser | Select-Object Name, DN, PasswordLastSet, PasswordNeverExpires, PasswordExpires, 
    AccountIsDisabled, AccountIsLockedOut, AccountExpires, LastLogon, MemberOf |
  Export-Csv "SomeFile.csv" -NoTypeInformation

Open in new window

If you must stick with VbScript then not all of the fields you've defined are helpful.

PswdCanBeChanged - Must enumerate account security. Not trivially available.
PswdLastSetTime - PwdLastSet: Needs conversion in VbScript interface
PswdRequired - No such field
PswdExpires - You can pull Never Expires from userAccountControl
PswdExpiresTime - Based on PwdLastSet plus expiry value (set in domain policy)
AcctDisabled - From userAccountControl
AcctLockedOut - From userAccountControl
AcctExpiresTime - accountExpirationDate: Needs conversion in the VbScript interface
LastLogonTime - LastLogon: Needs conversion in VbScript interface. Note: Value is *not* replicated between Domain Controllers
LastLogonServer - No such field
LogonHours - Complex hexadecimal array
group membership - MemberOf (DN of each group the user belongs to, except Primary Group)

Chris
0

Featured Post

Veeam Task Manager for Hyper-V

Task Manager for Hyper-V provides critical information that allows you to monitor Hyper-V performance by displaying real-time views of CPU and memory at the individual VM-level, so you can quickly identify which VMs are using host resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses
Course of the Month13 days, 13 hours left to enroll

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question