List AD groups that contain nested groups

Need a script to list only the AD groups that contain groups.  Would like to have an option to include or exclude listing all group members.  Output needs to show full AD path where the main group and nested groups are located.

Thanks
LVL 37
Carl WebsterAsked:
Who is Participating?
 
KenMcFConnect With a Mentor Commented:
I do nopt have a vbscript but could create one if needed later.
You could try to use ADFind or just a query in ADUC

(&(objectcategory=group)(memberof=*))

adfind -default -f "&(objectcategory=group)(memberof=*)" dn

you could also get the members from ADFind or you could output the list from ADFInd to a test and use vbscript to get all the members

http://www.activexperts.com/activmonitor/windowsmanagement/adminscripts/usersgroups/groups/#EnumGroupmembership.htm
0
 
KenMcFCommented:
If you are able to use the quest cmdlets from your other question you can try this

to get group memebrs you can add this

get-qadgroupmember $g | select name
$groups = get-qadgroup -searchroot "OU=Groups,dc=Domain,dc=Local" | where{$_.memberof -ne ""} 
foreach ($Group in $Groups){
write-host $group.name
$grp = get-qadmemberof $Group
foreach ($g in $grp){
write-host `t $g.dn
}}

Open in new window

0
 
Vishal PatelCommented:
You can use AD Manager Plus (A ManageEngine tool, free to try) for the purpose.
0
Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

 
Carl WebsterAuthor Commented:
I am now on this network and it is a 2000 AD system and all the DCs are running 2000 SP4.

Anyone have a VBScript I could use to list which of their 416 AD groups contain groups?
0
 
Carl WebsterAuthor Commented:
I can't find out how in 2000's ADUC how to do a search to list only groups that contain groups.

I was able to use ADFind to list all the groups.  ADFind says there are 479 groups and ADUC says there are 416.  I'll trust ADFind and Joe.

Just tried your ADFind line and it worked.  Gave me a list of 62 groups.  Let me verify a random sample.
0
 
Carl WebsterAuthor Commented:
I guess this will work.  Your "adfind -default -f "&(objectcategory=group)(memberof=*)" dn" gives me a list of groups that contain groups or groups that are members of other groups.

i.e. Domain Admins contains other groups but GroupABC has no members but is a member of GroupXYZ.  WHen I look at GroupXYZ it shows GroupABC as a member.  

That should work for this purpose.

Thanks
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.