Solved

Powershell - size limit error

Posted on 2013-10-22
8
2,461 Views
Last Modified: 2013-10-22
Hi EE

SubSun helped me with the script below that compares members of two groups . It works great on small groups but if they are over a certain amount which I dont know .. I get the error below .. the groups I am trying to compare have 20k users .

Any ideas what I need to modify ?

Function Compare-Member ($Source,$Group) {
      $DN = (Get-AdGroup $Source).DistinguishedName
      "Working on group $Group"
      $result = Get-ADGroupMember $Group | % {
      If (!(Get-ADUser $_.SamAccountName -properties memberOf |
            ? {$_.memberOf -Match $DN})){$_.SamAccountName}
      }
      If ($result){
      "Missing Members"
      $result
      }
      Else{
      "All NUIDs Match !"
      }
}

Compare-Member Test_1 TEST_4


ERROR below ..

PS E:\Projects\Groups> .\CompareABGroups.ps1
Working on group TEST_4
Get-ADGroupMember : The size limit for this request was exceeded
At E:\Projects\Groups\CompareABGroups.ps1:5 char:12
+     $result = Get-ADGroupMember $Group | % {
+               ~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (TEST_4:ADGroup) [Get-ADGroupMember], ADException
    + FullyQualifiedErrorId : The size limit for this request was exceeded,Microsoft.ActiveDirectory.Management.Commands.GetADGroupMember
0
Comment
Question by:MilesLogan
  • 4
  • 3
8 Comments
 
LVL 40

Expert Comment

by:Subsun
ID: 39592383
How many members you have in the group is it above 5000?
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 39592389
0
 
LVL 2

Author Comment

by:MilesLogan
ID: 39592444
Hi Subsun .. yes .. both groups have over 5000
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 40

Expert Comment

by:Subsun
ID: 39592485
Try to replace Get-ADGroupMember $Group

With
Get-ADGroup $Group -Properties Members | Select-Object -ExpandProperty Members | Get-ADObject | ?{$_.ObjectClass -eq "user"}

Open in new window


Function Compare-Member ($Source,$Group) {
      $DN = (Get-AdGroup $Source).DistinguishedName
      "Working on group $Group"
      $result = Get-ADGroup $Group -Properties Members | 
		Select-Object -ExpandProperty Members | 
			Get-ADObject | 
				?{$_.ObjectClass -eq "user"} | % {
      If (!(Get-ADUser $_.SamAccountName -properties memberOf |
            ? {$_.memberOf -Match $DN})){$_.SamAccountName}
      }
      If ($result){
      "Missing Members"
      $result
      }
      Else{
      "All NUIDs Match !"
      }
}

Open in new window

0
 
LVL 2

Author Comment

by:MilesLogan
ID: 39592561
Hi SubSun

I received the error below .

Get-ADUser : Cannot validate argument on parameter 'Identity'. The argument is null. Supply a non-null argument and try the command again.
At E:\Projects\groups\CompareABGroups.ps1:8 char:24
+       If (!(Get-ADUser $_.SamAccountName -properties memberOf |
+                        ~~~~~~~~~~~~~~~~~
    + CategoryInfo          : InvalidData: (:) [Get-ADUser], ParameterBindingValidationException
    + FullyQualifiedErrorId : ParameterArgumentValidationError,Microsoft.ActiveDirectory.Management.Commands.GetADUser
0
 
LVL 40

Expert Comment

by:Subsun
ID: 39592582
In line 8 change Get-ADUser $_.SamAccountName

to

Get-ADUser $_.DistinguishedName
0
 
LVL 40

Accepted Solution

by:
Subsun earned 500 total points
ID: 39592586
Or try...
Function Compare-Member ($Source,$Group) {
      $DN = (Get-AdGroup $Source).DistinguishedName
      "Working on group $Group"
      $result = Get-ADGroup $Group -Properties Members | 
		Select-Object -ExpandProperty Members | 
			Get-ADObject -properties Samaccountname | 
				?{$_.ObjectClass -eq "user"} | % {
      If (!(Get-ADUser $_.SamAccountName -properties memberOf |
            ? {$_.memberOf -Match $DN})){$_.SamAccountName}
      }
      If ($result){
      "Missing Members"
      $result
      }
      Else{
      "All NUIDs Match !"
      }
}

Open in new window

0
 
LVL 2

Author Closing Comment

by:MilesLogan
ID: 39592870
That was it ! thank you !
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A procedure for exporting installed hotfix details of remote computers using powershell
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question