Solved

List AD groups that contain nested groups

Posted on 2010-11-23
6
813 Views
Last Modified: 2012-05-10
Need a script to list only the AD groups that contain groups.  Would like to have an option to include or exclude listing all group members.  Output needs to show full AD path where the main group and nested groups are located.

Thanks
0
Comment
Question by:Carl Webster
  • 3
  • 2
6 Comments
 
LVL 27

Expert Comment

by:KenMcF
ID: 34198886
If you are able to use the quest cmdlets from your other question you can try this

to get group memebrs you can add this

get-qadgroupmember $g | select name
$groups = get-qadgroup -searchroot "OU=Groups,dc=Domain,dc=Local" | where{$_.memberof -ne ""} 
foreach ($Group in $Groups){
write-host $group.name
$grp = get-qadmemberof $Group
foreach ($g in $grp){
write-host `t $g.dn
}}

Open in new window

0
 
LVL 4

Expert Comment

by:Vishal Patel
ID: 34204107
You can use AD Manager Plus (A ManageEngine tool, free to try) for the purpose.
0
 
LVL 36

Author Comment

by:Carl Webster
ID: 34232373
I am now on this network and it is a 2000 AD system and all the DCs are running 2000 SP4.

Anyone have a VBScript I could use to list which of their 416 AD groups contain groups?
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 27

Accepted Solution

by:
KenMcF earned 500 total points
ID: 34232490
I do nopt have a vbscript but could create one if needed later.
You could try to use ADFind or just a query in ADUC

(&(objectcategory=group)(memberof=*))

adfind -default -f "&(objectcategory=group)(memberof=*)" dn

you could also get the members from ADFind or you could output the list from ADFInd to a test and use vbscript to get all the members

http://www.activexperts.com/activmonitor/windowsmanagement/adminscripts/usersgroups/groups/#EnumGroupmembership.htm
0
 
LVL 36

Author Comment

by:Carl Webster
ID: 34232582
I can't find out how in 2000's ADUC how to do a search to list only groups that contain groups.

I was able to use ADFind to list all the groups.  ADFind says there are 479 groups and ADUC says there are 416.  I'll trust ADFind and Joe.

Just tried your ADFind line and it worked.  Gave me a list of 62 groups.  Let me verify a random sample.
0
 
LVL 36

Author Comment

by:Carl Webster
ID: 34232630
I guess this will work.  Your "adfind -default -f "&(objectcategory=group)(memberof=*)" dn" gives me a list of groups that contain groups or groups that are members of other groups.

i.e. Domain Admins contains other groups but GroupABC has no members but is a member of GroupXYZ.  WHen I look at GroupXYZ it shows GroupABC as a member.  

That should work for this purpose.

Thanks
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is the result of a quest to better understand Task Scheduler 2.0 and all the newer objects available in vbscript in this version over  the limited options we had scripting in Task Scheduler 1.0.  As I started my journey of knowledge I f…
If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now