Solved

Vbscript to enum groups and group memebrs from a specific OU not from Root of  AD

Posted on 2011-02-11
6
509 Views
Last Modified: 2012-06-27
I have run the script from solution:
http://www.experts-exchange.com/Programming/Languages/Visual_Basic/VB_Script/Q_24978862.html

It works great for just Distribution groups. The problem I have is that some of the groups we use for distributiol groups are Security groups. I have organized them in a ou in ad the Dn is:
OU=Groups - Distribution,DC=azle,DC=esc11,DC=net

I need to run this script to look at both dist groups and security groups.. Please Help!! thanks..
Set oRootDSE = GetObject("LDAP://RootDSE")
Set objConn = CreateObject("ADODB.Connection")
Set objComm =   CreateObject("ADODB.Command")
objConn.Provider = "ADsDSOObject"
objConn.Open "Active Directory Provider"
Set objComm.ActiveConnection = objConn
objComm.Properties("Page Size") = 1000
 
strBase   =  "<LDAP://" & oRootDSE.get("defaultNamingContext") & ">;"
strFilter = "(sAMAccountType=268435457);" 
strAttrs  = "distinguishedName,memberof,sAMAccountName;"
strScope  = "subtree"
 
objComm.CommandText = strBase & strFilter & strAttrs & strScope
Set objRS = objComm.Execute
 
objRS.MoveFirst
Do Until objRS.EOF
	Set objGroup = GetObject("LDAP://" & Replace(objRS.Fields("distinguishedName").Value,"/","\/"))
	WScript.Echo objGroup.cn & "," & memberString(objGroup)
 
	
	objRS.MoveNext
Loop
 
Set oRootDSE = Nothing
Set objConn = Nothing
Set objComm = Nothing
Set objUser = Nothing
 
 
Function memberString(objGroup)
	If Not IsEmpty(objgroup.member) Then
		For Each memberDN In objGroup.GetEx("member")
			Set objMember = GetObject("LDAP://" & memberDN)
			out = out & objmember.cn & "; "
		Next
	End If
	If Right(out,2) = "; " Then out = Left(out,Len(out)-2)
	memberString = out
End Function

Open in new window

0
Comment
Question by:AzleISD
  • 3
  • 3
6 Comments
 
LVL 4

Assisted Solution

by:IceCode
IceCode earned 500 total points
ID: 34872930
Change line 10 to: strFilter = "(&(objectCategory=group));"
0
 

Author Comment

by:AzleISD
ID: 34872995
awesome now I just need to get it to run just in the ou not the entire AD...
0
 
LVL 4

Expert Comment

by:IceCode
ID: 34873002
oh sorry, give me a few minutes.
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 

Author Comment

by:AzleISD
ID: 34873014
not a problem Thanks for the quick response!!
0
 
LVL 4

Accepted Solution

by:
IceCode earned 500 total points
ID: 34873051
I think it's just line 9 should be: strBase   =  "<LDAP://OU=Groups - distribution," & oRootDSE.get("defaultNamingContext") & ">;"
0
 

Author Closing Comment

by:AzleISD
ID: 34873640
That is is thanks for your help!
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

This script will sweep a range of IP addresses (class c only, 255.255.255.0) and report to a log the version of office installed. What it does: 1.)      Creates log file in the directory the script is run from (if it doesn't already exist) 2.)      Sweep…
[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now