Solved

script to query AD for all Global Security Groups that contain Nested Groups and it's name

Posted on 2013-11-26
2
429 Views
Last Modified: 2013-11-27
I need to find all names of nested groups in every global security group.
0
Comment
Question by:scfcu
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 3

Expert Comment

by:RKnebel512
ID: 39678348
So, I don't have access to an active directory server at the moment to test this out, but I thought I would pass on the information that I found.  This site seems to be explaining a similar thing to what you want.  

http://bradkingsley.com/using-powershell-to-list-group-membership-from-active-directory-ad/

The only difference is that the script on this site will pull all members of a group and not just the nested groups.  

So it will take a bit of tweaking on the script to get exactly what you want.  But it might be a start.
0
 
LVL 40

Accepted Solution

by:
Subsun earned 500 total points
ID: 39680041
Try...
Import-Module Activedirectory
Get-ADGroup -Filter * -Properties Members | 
  ?{$_.GroupScope -eq "Global" `
    -and $_.GroupCategory -eq "Security"} | % {
      $Group = $_.Name
       $_.Members | Get-ADObject |
     ? {$_.objectClass -eq "group"} | 
  Select @{N="Group";E={$Group}},@{N="Member";E={$_.Name}}
} | Export-Csv C:\temp\report.csv -nti

Open in new window

0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Windows 10 came with  a lot of built in applications, Some organisations leave them there, some will control them using GPO's. This Article is useful for those who do not want to have any applications in their image (example:me).
The viewer will learn how to dynamically set the form action using jQuery.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question