Solved

Need command line function to compare two user AD entries

Posted on 2011-03-22
14
769 Views
Last Modified: 2012-05-11
I would like to do a comparison of two user entries in Active Directory.

Preferably via a commandline function
0
Comment
Question by:Christopher Schene
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 4
  • 2
  • +1
14 Comments
 
LVL 43

Accepted Solution

by:
Amit earned 167 total points
ID: 35191823
0
 

Assisted Solution

by:Christopher Schene
Christopher Schene earned 0 total points
ID: 35191866
Those are power Shell scripts?
0
 
LVL 43

Expert Comment

by:Amit
ID: 35192030
yes it is PS
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:Christopher Schene
ID: 35192208
Ok, I am complete power chart novice....have never written one single line. so i have REALLY basic questions:

1) What servers or OS can I run  power Shell on? ( I am using windows 2003, XP). I do not have the ability to update software on these systems as they are customer production systems
2) Can I run it from DOS command line? If not, how do I run it?
0
 

Author Comment

by:Christopher Schene
ID: 35192222
Oh...One other thing, I want to compare WHAT is different between the users....not just a "yes or no" they are different
0
 

Author Comment

by:Christopher Schene
ID: 35192236
"Ok, I am complete power chart novice"

of course I mean

"Ok, I am a complete power shell novice"
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35192620
You would need to install powershell on the 2003 or XP machine.  Do you have any 7/2008 boxes around?

Thanks

Mike
0
 

Author Comment

by:Christopher Schene
ID: 35193081
I would need to install it on my XP machine which I cannot via VPN to my customer.

Where do I get PS?
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 167 total points
ID: 35193372
You can download it here

http://www.microsoft.com/windowsserver2003/technologies/management/powershell/download.mspx

A lot of examples you will see here and on other forums for AD also utilize the Quest AD cmdlets http://www.quest.com/powershell/activeroles-server.aspx

Thanks

Mike
0
 
LVL 43

Expert Comment

by:Amit
ID: 35193411
0
 
LVL 5

Assisted Solution

by:xylog
xylog earned 166 total points
ID: 35193695
Dsquery user and dsget user can be used to do many ldap functions quickly and easily from the command line. For example to retrieve group memberships based on a users sam account name:

dsquery user -samid username|dsget user -memberof
0
 

Author Comment

by:Christopher Schene
ID: 35283467
increase points to 500
0
 
LVL 43

Expert Comment

by:Amit
ID: 35284734
Thanks, Check Hyena tool also
http://www.systemtools.com/hyena/index.html

It can give you lot of information and you can do the custom query.  Paid one but free for trial.
0
 

Author Closing Comment

by:Christopher Schene
ID: 35321772
All three suggestions were helpful. thanks.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question