Solved

DSQUERY to list all users in OU including AD attributes

Posted on 2011-09-15
5
1,937 Views
Last Modified: 2012-11-20
I'm looking to generate a list of users in a given OU (and all sub-OUs) which includes the following attributes:

cn, legacyExchangeDN, mail

I would like to dump this to a file (CSV or text). I'm guessing this could be done using a combination dsquery/dsget command, but I'm having trouble putting together the correct syntax.
0
Comment
Question by:TWCMIL
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 10

Accepted Solution

by:
wdurrett earned 500 total points
ID: 36546386
Here is a pwershell script I use.  You can change the fields to get the info you need.

Change the $file name and the $SearchRoot to suit your needs.

 
# Basic information to run the script
$File = 'some_output_filecsv'
$SearchRoot = "LDAP://OU=someOU,DC=domain,DC=com"
 
## Filter to find the things we want
$Filter = "(objectClass=User)"
 
# Connect to the search root
$SearchRootDE = New-Object System.DirectoryServices.DirectoryEntry($SearchRoot)
 
# Set up the search
$Searcher = New-Object System.DirectoryServices.DirectorySearcher($SearchRootDE, $Filter)
$intProp = $Searcher.PropertiesToLoad.Add("name")
$intProp = $Searcher.PropertiesToLoad.Add("mail")
$intProp = $Searcher.PropertiesToLoad.Add("physicalDeliveryOfficeName")
$intProp = $Searcher.PropertiesToLoad.Add("title")
 
 
# Get the results
$Results = $Searcher.FindAll()
 
# Sort through the results and save them in an array
$Users = @()
ForEach ($Result in $Results) {
  $Users += $Result.Properties | Select-Object `
        @{n="name";e={$_.name}}, `
        @{n="mail";e={$_.mail}}, `
        @{n="physicalDeliveryOfficeName";e={$_.physicaldeliveryofficename}}, `
	@{n="title";e={$_.title}}
}
 
# Write the array to a file
$Users |  Export-CSV -Path $File

Open in new window

0
 
LVL 1

Author Comment

by:TWCMIL
ID: 36550551
I got half of what I was looking for, the cn and mail fields were returned, but the legacyExchangeDN and displayName fields come back blank. Here's how I modified it:

# Basic information to run the script
$File = 'user_extract.csv'
$SearchRoot = "LDAP://OU=Users,DC=domain,DC=com"
 
## Filter to find the things we want
$Filter = "(objectClass=User)"
 
# Connect to the search root
$SearchRootDE = New-Object System.DirectoryServices.DirectoryEntry($SearchRoot)
 
# Set up the search
$Searcher = New-Object System.DirectoryServices.DirectorySearcher($SearchRootDE, $Filter)
$intProp = $Searcher.PropertiesToLoad.Add("cn")
$intProp = $Searcher.PropertiesToLoad.Add("legacyExchangeDN")
$intProp = $Searcher.PropertiesToLoad.Add("mail")
$intProp = $Searcher.PropertiesToLoad.Add("displayName")
 
 
# Get the results
$Results = $Searcher.FindAll()
 
# Sort through the results and save them in an array
$Users = @()
ForEach ($Result in $Results) {
  $Users += $Result.Properties | Select-Object `
        @{n="cn";e={$_.cn}}, `
        @{n="legacyExchangeDN";e={$_.legacyExchangeDN}}, `
        @{n="mail";e={$_.mail}}, `
	@{n="displayName";e={$_.displayName}}
}
 
# Write the array to a file
$Users |  Export-CSV -Path $File

Open in new window


I double-checked the field names (using the Attribute Editor in ADUC) and they look right.  Am I missing something obvious?
0
 
LVL 10

Assisted Solution

by:wdurrett
wdurrett earned 500 total points
ID: 36551841
Try just "name" for Display Name.

Try "legacydn" for the excahnge dn.



0
 
LVL 10

Expert Comment

by:wdurrett
ID: 36551850
You mauy also want to check out this article:

http://www.sapien.com/forums/scriptinganswers/forum_posts.asp?TID=2061

0
 
LVL 1

Author Closing Comment

by:TWCMIL
ID: 38618582
Sorry, forgot I had this question out there -- thanks for the help!
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question