[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 296
  • Last Modified:

Need a query that finds the CN name for all the users in a Forest

I am looking for a command that finds the CN Names and the OU where the USeR account is present in a forest
0
jmohan0302
Asked:
jmohan0302
1 Solution
 
Brian ChanDBACommented:
Assuming:
- you want to query AD from a SQL Server
- you know how to use OPENQUERY to achieve this. ( here is the guide if you don't:        Running Active Directory Services Queries Using MS SQL Server T-SQL OPENQUERY Command)

I am not a sysadmin so I am sure how much difference it does to between forest and AD. I have use this to query from the AD to collect user information out of it. that's the direction.

0
 
Mike KlineCommented:
a tool like adfind can also help

http://www.joeware.net/freetools/tools/adfind/index.htm

adfind -gcb -f "&(objectcategory=person)(objectclass=user)" cn


Thanks

Mike
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
Hendrik WieseCommented:
Download and install QAD Snap-ins from this site:
http://www.quest.com/activeroles-server/arms.aspx

Now run the following command:

Get-QADUser -Enabled -SizeLimit 0  -ip sAMAccountName, DN | Select name, sAMAccountName, DN |export-csv C:\ExportedUserData.csv

Open in new window

0
 
jmohan0302Author Commented:
Hi Mike,

Thanks a lot. It works fine. Could you please tell me that adifnd -gcb -f switch will run for all domains in a forest or I have to run this on all domains
0
 
jmohan0302Author Commented:
Hi Mike,

Could you please explain what this switch gcb -f will do in adfind? Thanks
0
 
Mike KlineCommented:
gcb searches the global catalog so the entire forest  more on that here

http://www.joeware.net/freetools/tools/adfind/usage.htm

-gcb          Combines -gc -null switches. i.e. Full forest search.

Thanks

Mike
0
 
jmohan0302Author Commented:
Ok. Thanks Mike. what switch I have to use If I want to find the CN for one particular domain?
0
 
Mike KlineCommented:
From each domain you could use the -default switch (instead of -gcb)

Thanks

Mike
0
 
jmohan0302Author Commented:
Hi Mike,

You mean:

adfind -default

0
 
Mike KlineCommented:
yes
0
 
jmohan0302Author Commented:
Hi Mike,

Thanks. Could you please tell me what all the things we can do with ADFIND.exe
0
 
Mike KlineCommented:
There is a ton, I'd start with looking at the shortucts Joe has in there, he also covers them on the usage page

http://www.joeware.net/freetools/tools/adfind/usage.htm

Thanks

Mike
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now