Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Script not working to query a certain query

Posted on 2014-02-17
3
Medium Priority
?
310 Views
Last Modified: 2014-02-17
I am trying to query users in AD and only receive output that have a certain group that start with 'IT-'

I am not getting anything in the output, any reasons why?



Const ADS_SCOPE_SUBTREE = 2

Set objFSO = CreateObject("Scripting.FileSystemObject")
strDomain = "dc=domain,dc=com"
strUsers = "c:\Users.txt"

Set objOutput = objFSO.CreateTextFile("c:\output.txt")

aryUsers = Split(objFSO.OpenTextFile(strUsers).ReadAll, vbNewLine)
For Each strUser In aryUsers
  Set objConnection = CreateObject("ADODB.Connection")
  Set objCommand = CreateObject("ADODB.Command")
  objConnection.Provider = "ADsDSOObject"
  objConnection.Open "Active Directory Provider"
  Set objCommand.ActiveConnection = objConnection
  objCommand.Properties("Page Size") = 1000
  objCommand.Properties("Searchscope") = ADS_SCOPE_SUBTREE
  objCommand.CommandText = _
    "SELECT ADsPath FROM 'LDAP://" & strDomain & "' WHERE objectCategory='user' " & _
        "AND samAccountName = '" & strUser & "'"
  
  Set objRecordSet = objCommand.Execute
  objRecordSet.MoveFirst
  If Not objRecordSet.EOF Then 
    Do Until objRecordSet.EOF
      strADsPath = objRecordSet.Fields("ADsPath").Value
      Set objUser = GetObject(strADsPath)
      objOutput.WriteLine objUser.Name & " is a member of the following groups:"
     For Each strGroup In objUser.memberOf
     If mid(strGroup,4,4)="IT-" Then  
      Set objGroup = GetObject("LDAP://" & strGroup)
      objOutput.WriteLine objGroup.CN
    End If
 Next
      objOutput.WriteLine
      objRecordSet.MoveNext
    Loop
  Else 
     objOutput.WriteLine strUser & " does not have an AD account!"
  End If

Next

objOutput.Close
Set objOutput = Nothing
Set objGroup = Nothing
Set objUser = Nothing
Set objFSO = Nothing

Open in new window

0
Comment
Question by:mystikal1000
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 23

Accepted Solution

by:
yo_bee earned 2000 total points
ID: 39865478
Have you confirmed that you are catching the IT- part of the string.

If CN=IT-xxxxx

I would think if you are starting at the 4 character which is I of IT-, but it looks like you are only comparing 3 characters not 4.
if that is the case you probably not going to get any true results.

I would try to parse the Group name and with your MID function and see what the output is.
0
 
LVL 1

Author Comment

by:mystikal1000
ID: 39865644
Whoops, thanks!
0
 
LVL 23

Expert Comment

by:yo_bee
ID: 39865675
Here is an alt method.

Replace Line 29-33
Set colGroups = ObjUser.Groups
For Each objGroup in ColGroups

     If mid(strGroup,1,3)="IT-" Then  
            objOutput.WriteLine objGroup.CN

Open in new window


    Do Until objRecordSet.EOF
      strADsPath = objRecordSet.Fields("ADsPath").Value
      Set objUser = GetObject(strADsPath)
      objOutput.WriteLine objUser.Name & " is a member of the following groups:"
Set colGroups = ObjUser.Groups
For Each objGroup in ColGroups

     If mid(strGroup,1,3)="IT-" Then  
            objOutput.WriteLine objGroup.CN
    End If

Open in new window

0

Featured Post

How Blockchain Is Impacting Every Industry

Blockchain expert Alex Tapscott talks to Acronis VP Frank Jablonski about this revolutionary technology and how it's making inroads into other industries and facets of everyday life.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question