Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

DSQUERY to list all users in OU including AD attributes

Posted on 2011-09-15
5
1,807 Views
Last Modified: 2012-11-20
I'm looking to generate a list of users in a given OU (and all sub-OUs) which includes the following attributes:

cn, legacyExchangeDN, mail

I would like to dump this to a file (CSV or text). I'm guessing this could be done using a combination dsquery/dsget command, but I'm having trouble putting together the correct syntax.
0
Comment
Question by:TWCMIL
  • 3
  • 2
5 Comments
 
LVL 10

Accepted Solution

by:
wdurrett earned 500 total points
ID: 36546386
Here is a pwershell script I use.  You can change the fields to get the info you need.

Change the $file name and the $SearchRoot to suit your needs.

 
# Basic information to run the script
$File = 'some_output_filecsv'
$SearchRoot = "LDAP://OU=someOU,DC=domain,DC=com"
 
## Filter to find the things we want
$Filter = "(objectClass=User)"
 
# Connect to the search root
$SearchRootDE = New-Object System.DirectoryServices.DirectoryEntry($SearchRoot)
 
# Set up the search
$Searcher = New-Object System.DirectoryServices.DirectorySearcher($SearchRootDE, $Filter)
$intProp = $Searcher.PropertiesToLoad.Add("name")
$intProp = $Searcher.PropertiesToLoad.Add("mail")
$intProp = $Searcher.PropertiesToLoad.Add("physicalDeliveryOfficeName")
$intProp = $Searcher.PropertiesToLoad.Add("title")
 
 
# Get the results
$Results = $Searcher.FindAll()
 
# Sort through the results and save them in an array
$Users = @()
ForEach ($Result in $Results) {
  $Users += $Result.Properties | Select-Object `
        @{n="name";e={$_.name}}, `
        @{n="mail";e={$_.mail}}, `
        @{n="physicalDeliveryOfficeName";e={$_.physicaldeliveryofficename}}, `
	@{n="title";e={$_.title}}
}
 
# Write the array to a file
$Users |  Export-CSV -Path $File

Open in new window

0
 
LVL 1

Author Comment

by:TWCMIL
ID: 36550551
I got half of what I was looking for, the cn and mail fields were returned, but the legacyExchangeDN and displayName fields come back blank. Here's how I modified it:

# Basic information to run the script
$File = 'user_extract.csv'
$SearchRoot = "LDAP://OU=Users,DC=domain,DC=com"
 
## Filter to find the things we want
$Filter = "(objectClass=User)"
 
# Connect to the search root
$SearchRootDE = New-Object System.DirectoryServices.DirectoryEntry($SearchRoot)
 
# Set up the search
$Searcher = New-Object System.DirectoryServices.DirectorySearcher($SearchRootDE, $Filter)
$intProp = $Searcher.PropertiesToLoad.Add("cn")
$intProp = $Searcher.PropertiesToLoad.Add("legacyExchangeDN")
$intProp = $Searcher.PropertiesToLoad.Add("mail")
$intProp = $Searcher.PropertiesToLoad.Add("displayName")
 
 
# Get the results
$Results = $Searcher.FindAll()
 
# Sort through the results and save them in an array
$Users = @()
ForEach ($Result in $Results) {
  $Users += $Result.Properties | Select-Object `
        @{n="cn";e={$_.cn}}, `
        @{n="legacyExchangeDN";e={$_.legacyExchangeDN}}, `
        @{n="mail";e={$_.mail}}, `
	@{n="displayName";e={$_.displayName}}
}
 
# Write the array to a file
$Users |  Export-CSV -Path $File

Open in new window


I double-checked the field names (using the Attribute Editor in ADUC) and they look right.  Am I missing something obvious?
0
 
LVL 10

Assisted Solution

by:wdurrett
wdurrett earned 500 total points
ID: 36551841
Try just "name" for Display Name.

Try "legacydn" for the excahnge dn.



0
 
LVL 10

Expert Comment

by:wdurrett
ID: 36551850
You mauy also want to check out this article:

http://www.sapien.com/forums/scriptinganswers/forum_posts.asp?TID=2061

0
 
LVL 1

Author Closing Comment

by:TWCMIL
ID: 38618582
Sorry, forgot I had this question out there -- thanks for the help!
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

792 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question