Solved

how do i identify users of a domain security group and members of any nexted groups?

Posted on 2013-06-14
6
388 Views
Last Modified: 2013-06-20
how do i identify users of a domain security group and members of any nexted groups in server 2003?

Thanks
0
Comment
Question by:Jason Thomas
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 5

Expert Comment

by:MisterTwelve
ID: 39247157
0
 
LVL 1

Author Comment

by:Jason Thomas
ID: 39247159
Thanks, anyone know if there are any windows command line tools that i can use other than VB scripts
0
 
LVL 5

Assisted Solution

by:vin_shooter
vin_shooter earned 250 total points
ID: 39247230
Hi,

Check the below commands,

 1. How to find all members for a particular group
 
  dsget group "<DN of the group>" -members

1a. How to find all groups for a particular member (including nested groups)
 
  dsget user "<DN of the user>" -memberof -expand
  dsquery user -samid "username" | dsget user -memberof -expand
 

Can go through the below link for few more commands..,

http://social.technet.microsoft.com/wiki/contents/articles/2195.active-directory-dsquery-commands.aspx
0
Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

 
LVL 1

Author Comment

by:Jason Thomas
ID: 39247253
Many thanks for that helps me a lot. If i run teh first command it does give me teh mebers but it also list other groups. Is there a command that will show me the mebers of the DN and members of any nexted groups that you know of?
0
 
LVL 5

Accepted Solution

by:
MisterTwelve earned 250 total points
ID: 39247255
dsquery user -samid USER | dsget user -Memberof -expand | dsget Group -samid

Replace USER for your user you need
0
 
LVL 1

Author Closing Comment

by:Jason Thomas
ID: 39261755
Thanks guys. Sorry for the late feedback.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ADFS Help 7 48
GPO reset 2 43
Active Directory Design - Best Practice 9 50
Trying to start time server on domain controller and it errors out. 14 26
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question