Solved

net group information

Posted on 2015-01-05
7
170 Views
Last Modified: 2015-01-29
There is a usefull command you can run that i thought was accurate i.e. NET GROUP groupname /domain, and it would list all members in a domain AD group, without having to load up AD users and computers. But from some testing it doesnt seem that accurate. For example I ran the command for an AD group, and also checked the group in ADUC, and for nested groups, the NET GROUP command doesnt appear to list them, just accounts. Is this "normal behaviour", or is NET GROUP not always accurate.
0
Comment
Question by:pma111
7 Comments
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 333 total points
ID: 40531117
Net group can't do that.
I bet there's a powershell alternative that can, did you already look into it?
0
 
LVL 3

Author Comment

by:pma111
ID: 40531121
can you elaborate - net group cant do what?

I have used net group to get a list of all group members, are you saying it will list accounts listed in a group, but not groups within a group?

I have access to ADUC so I can get the members there, it was just handy to use NET Group in some situations but if it doesnt give a clear picture I will swap to an alternative...
0
 
LVL 54

Expert Comment

by:McKnife
ID: 40531130
Right, it's incapable of listing groups nested there in. Look for a powershell alternative, if you don't find it googling, I will assist.
0
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

 
LVL 17

Expert Comment

by:Emmanuel Adebayo
ID: 40531131
This is usually correct
net group /dom <Groupname>
I used it so many times.

You can also use dsquery command
0
 
LVL 54

Accepted Solution

by:
McKnife earned 333 total points
ID: 40531135
http://serverfault.com/questions/49405/command-line-to-list-users-in-a-windows-active-directory-group provides the dsquery and powershell syntax that reads out nested groups as well.
0
 
LVL 24

Assisted Solution

by:VB ITS
VB ITS earned 167 total points
ID: 40531197
For example I ran the command for an AD group, and also checked the group in ADUC, and for nested groups, the NET GROUP command doesnt appear to list them, just accounts. Is this "normal behaviour", or is NET GROUP not always accurate.
This appears to be by design when it comes to the net group command. See the explanation for the groupname parameter in this link which states the following:
Syntax:
net group [groupname [/comment:"text"]] [/domain]

Parameters
groupname: Specifies the name of the group to add, expand, or delete. Specify a group name to view a list of users in a group only.

If you need to see members within the nested groups as well then you'll need to resort to either the dsquery command or PowerShell. Examples are provided in the link McKnife posted above.
0
 
LVL 3

Author Comment

by:pma111
ID: 40531200
emmanuel - are you saying that command will aslo list nested groups within groups??
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question