[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Unable to retrieve group membership of a Foreign Security Principals account

Posted on 2011-03-19
3
Medium Priority
?
1,669 Views
Last Modified: 2013-12-24
I'm trying to retrieve the local  group membership (groups in my local domain) from Foreign Security Principals accounts (created after granting access to a resource to an account from a trusted domain) via VBScript.  I'm using the code below but no matter what I do I'm not seeing the group membership.  The code works fine with a normal account.

Set objGroup = GetObject("LDAP://CN=S-1-5-21-466423297-1915321860-2068054413-25636,CN=ForeignSecurityPrincipals,DC=mydomain,DC=root")

arrGroups = objGroup.memberOf

I can see the membership when I look in the AD Users and Computers console.

Any ideas?
0
Comment
Question by:LonPete67
2 Comments
 
LVL 51

Accepted Solution

by:
Netman66 earned 1000 total points
ID: 36385399
If memory serves me, the memberOf attribute is non-existent for Foreign Security Principals - thus no results.

Since these SIDs/GUIDs are objects representing groups/principals in your trusted domain(s), you need to enumerate them to a real domain/group (or user) then go after the memberOf of that result.



0
 
LVL 74

Expert Comment

by:Glen Knight
ID: 37475334
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
What we learned in Webroot's webinar on multi-vector protection.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses
Course of the Month19 days, 5 hours left to enroll

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question