Solved

Script not working to query a certain query

Posted on 2014-02-17
3
303 Views
Last Modified: 2014-02-17
I am trying to query users in AD and only receive output that have a certain group that start with 'IT-'

I am not getting anything in the output, any reasons why?



Const ADS_SCOPE_SUBTREE = 2

Set objFSO = CreateObject("Scripting.FileSystemObject")
strDomain = "dc=domain,dc=com"
strUsers = "c:\Users.txt"

Set objOutput = objFSO.CreateTextFile("c:\output.txt")

aryUsers = Split(objFSO.OpenTextFile(strUsers).ReadAll, vbNewLine)
For Each strUser In aryUsers
  Set objConnection = CreateObject("ADODB.Connection")
  Set objCommand = CreateObject("ADODB.Command")
  objConnection.Provider = "ADsDSOObject"
  objConnection.Open "Active Directory Provider"
  Set objCommand.ActiveConnection = objConnection
  objCommand.Properties("Page Size") = 1000
  objCommand.Properties("Searchscope") = ADS_SCOPE_SUBTREE
  objCommand.CommandText = _
    "SELECT ADsPath FROM 'LDAP://" & strDomain & "' WHERE objectCategory='user' " & _
        "AND samAccountName = '" & strUser & "'"
  
  Set objRecordSet = objCommand.Execute
  objRecordSet.MoveFirst
  If Not objRecordSet.EOF Then 
    Do Until objRecordSet.EOF
      strADsPath = objRecordSet.Fields("ADsPath").Value
      Set objUser = GetObject(strADsPath)
      objOutput.WriteLine objUser.Name & " is a member of the following groups:"
     For Each strGroup In objUser.memberOf
     If mid(strGroup,4,4)="IT-" Then  
      Set objGroup = GetObject("LDAP://" & strGroup)
      objOutput.WriteLine objGroup.CN
    End If
 Next
      objOutput.WriteLine
      objRecordSet.MoveNext
    Loop
  Else 
     objOutput.WriteLine strUser & " does not have an AD account!"
  End If

Next

objOutput.Close
Set objOutput = Nothing
Set objGroup = Nothing
Set objUser = Nothing
Set objFSO = Nothing

Open in new window

0
Comment
Question by:mystikal1000
  • 2
3 Comments
 
LVL 21

Accepted Solution

by:
yo_bee earned 500 total points
Comment Utility
Have you confirmed that you are catching the IT- part of the string.

If CN=IT-xxxxx

I would think if you are starting at the 4 character which is I of IT-, but it looks like you are only comparing 3 characters not 4.
if that is the case you probably not going to get any true results.

I would try to parse the Group name and with your MID function and see what the output is.
0
 
LVL 1

Author Comment

by:mystikal1000
Comment Utility
Whoops, thanks!
0
 
LVL 21

Expert Comment

by:yo_bee
Comment Utility
Here is an alt method.

Replace Line 29-33
Set colGroups = ObjUser.Groups
For Each objGroup in ColGroups

     If mid(strGroup,1,3)="IT-" Then  
            objOutput.WriteLine objGroup.CN

Open in new window


    Do Until objRecordSet.EOF
      strADsPath = objRecordSet.Fields("ADsPath").Value
      Set objUser = GetObject(strADsPath)
      objOutput.WriteLine objUser.Name & " is a member of the following groups:"
Set colGroups = ObjUser.Groups
For Each objGroup in ColGroups

     If mid(strGroup,1,3)="IT-" Then  
            objOutput.WriteLine objGroup.CN
    End If

Open in new window

0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now