Solved

how to get AD group member count for a group with more then 5000 users

Posted on 2014-04-28
4
5,668 Views
Last Modified: 2014-04-28
Hi EE

I need to get the count for users in certain AD groups that have more then 10k users and neither of these options allow me to get the count . I don't want to modify the DC settings to expand the 5000 threshold  .  Does anyone have a work around for this ?

both of these fail .

Get-ADGroupMember "Test_Group" | Measure-Object | select count

If ([array]$users = (Get-ADGroupmember -Identity "Test_Group")) {
"Number of users in group: $($users.count)"
}
0
Comment
Question by:MilesLogan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 15

Expert Comment

by:WalkaboutTigger
ID: 40028576
Try this:

$members = Get-QADGroupMember -SizeLimit 0 'domain users' -ldap "(&(!userAccountControl:1.2.840.113556.1.4.803:=2))"
@($members).count

This does require the Quest PowerGUI from Dell, which can be found at

http://www.quest.com/powergui-freeware/
0
 
LVL 15

Accepted Solution

by:
WalkaboutTigger earned 250 total points
ID: 40028579
If you want to use native code, try

$group =[adsi]”LDAP://CN=Groupname,CN=Users,DC=domain,DC=local” 
$members = $group.psbase.invoke("Members") | foreach {$_.GetType().InvokeMember("name",'GetProperty',$null,$_,$null)} 
$members.count

Open in new window

0
 
LVL 40

Assisted Solution

by:footech
footech earned 250 total points
ID: 40028624
Here's another script bit using the adsisearcher type accelerator.  Just put in the name of your group instead of "some group" (can also use wildcards).  One note - it won't list members of the group that have that group set as the account's primary group.  If you never change this from "Domain Users" then it's not a problem.
([ADSISearcher]"(&(ObjectClass=group)(name=some group))").FindAll() | % {$_.properties.member}

Open in new window

0
 
LVL 2

Author Closing Comment

by:MilesLogan
ID: 40028742
Thank you both !! EE Rocks !
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Group policies can be applied selectively to specific devices with the help of groups. Utilising this, it is possible to phase-in group policies, over a period of time, by randomly adding non-members user or computers at a set interval, to a group f…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question