• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1124
  • Last Modified:

Help with VBS script and extracting user info from AD

I have the script attached that I want to modify.  I am not a programmer by any stretch of the imagination.  I cannot find some of the user object attributes that I need, and the ones that I found I cannot get any output when I run the script.  I used both ADSI Edit and CSVDE -f Exportfile.csv to try and identify the attributes that I need.

I want to keep what it has so far and add the following to the script.
PswdCanBeChanged, PswdLastSetTime, PswdRequired, PswdExpires, PswdExpiresTime,AcctDisabled, AcctLockedOut, AcctExpiresTime,LastLogonTime, LastLogonServer, LogonHours , group membership
test-ad.vbs
0
asrvwiz
Asked:
asrvwiz
1 Solution
 
Chris DentPowerShell DeveloperCommented:
I advise you use PowerShell and Quests AD CmdLets to get these if you have no existing scripting background. You can download those here:

http://www.quest.com/powershell/activeroles-server.aspx

With that, you can get an approximation of this with:
Get-QADUser | Select-Object Name, DN, PasswordLastSet, PasswordNeverExpires, PasswordExpires, 
    AccountIsDisabled, AccountIsLockedOut, AccountExpires, LastLogon, MemberOf |
  Export-Csv "SomeFile.csv" -NoTypeInformation

Open in new window

If you must stick with VbScript then not all of the fields you've defined are helpful.

PswdCanBeChanged - Must enumerate account security. Not trivially available.
PswdLastSetTime - PwdLastSet: Needs conversion in VbScript interface
PswdRequired - No such field
PswdExpires - You can pull Never Expires from userAccountControl
PswdExpiresTime - Based on PwdLastSet plus expiry value (set in domain policy)
AcctDisabled - From userAccountControl
AcctLockedOut - From userAccountControl
AcctExpiresTime - accountExpirationDate: Needs conversion in the VbScript interface
LastLogonTime - LastLogon: Needs conversion in VbScript interface. Note: Value is *not* replicated between Domain Controllers
LastLogonServer - No such field
LogonHours - Complex hexadecimal array
group membership - MemberOf (DN of each group the user belongs to, except Primary Group)

Chris
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now