Solved

Unable to retrieve group membership of a Foreign Security Principals account

Posted on 2011-03-19
3
1,626 Views
Last Modified: 2013-12-24
I'm trying to retrieve the local  group membership (groups in my local domain) from Foreign Security Principals accounts (created after granting access to a resource to an account from a trusted domain) via VBScript.  I'm using the code below but no matter what I do I'm not seeing the group membership.  The code works fine with a normal account.

Set objGroup = GetObject("LDAP://CN=S-1-5-21-466423297-1915321860-2068054413-25636,CN=ForeignSecurityPrincipals,DC=mydomain,DC=root")

arrGroups = objGroup.memberOf

I can see the membership when I look in the AD Users and Computers console.

Any ideas?
0
Comment
Question by:LonPete67
3 Comments
 
LVL 51

Accepted Solution

by:
Netman66 earned 250 total points
ID: 36385399
If memory serves me, the memberOf attribute is non-existent for Foreign Security Principals - thus no results.

Since these SIDs/GUIDs are objects representing groups/principals in your trusted domain(s), you need to enumerate them to a real domain/group (or user) then go after the memberOf of that result.



0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 37475334
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As technology users and professionals, we’re always learning. Our universal interest in advancing our knowledge of the trade is unmatched by most industries. It’s a curiosity that makes sense, given the climate of change. Within that, there lies a…
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will teach you the core code needed to finalize the addition of a watermark to your image. The viewer will use a small PHP class to learn and create a watermark.

773 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question