Solved

how do i identify users of a domain security group and members of any nexted groups?

Posted on 2013-06-14
6
390 Views
Last Modified: 2013-06-20
how do i identify users of a domain security group and members of any nexted groups in server 2003?

Thanks
0
Comment
Question by:Jason Thomas
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 5

Expert Comment

by:MisterTwelve
ID: 39247157
0
 
LVL 1

Author Comment

by:Jason Thomas
ID: 39247159
Thanks, anyone know if there are any windows command line tools that i can use other than VB scripts
0
 
LVL 5

Assisted Solution

by:vin_shooter
vin_shooter earned 250 total points
ID: 39247230
Hi,

Check the below commands,

 1. How to find all members for a particular group
 
  dsget group "<DN of the group>" -members

1a. How to find all groups for a particular member (including nested groups)
 
  dsget user "<DN of the user>" -memberof -expand
  dsquery user -samid "username" | dsget user -memberof -expand
 

Can go through the below link for few more commands..,

http://social.technet.microsoft.com/wiki/contents/articles/2195.active-directory-dsquery-commands.aspx
0
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

 
LVL 1

Author Comment

by:Jason Thomas
ID: 39247253
Many thanks for that helps me a lot. If i run teh first command it does give me teh mebers but it also list other groups. Is there a command that will show me the mebers of the DN and members of any nexted groups that you know of?
0
 
LVL 5

Accepted Solution

by:
MisterTwelve earned 250 total points
ID: 39247255
dsquery user -samid USER | dsget user -Memberof -expand | dsget Group -samid

Replace USER for your user you need
0
 
LVL 1

Author Closing Comment

by:Jason Thomas
ID: 39261755
Thanks guys. Sorry for the late feedback.
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question