Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


net group information

Posted on 2015-01-05
Medium Priority
Last Modified: 2015-01-29
There is a usefull command you can run that i thought was accurate i.e. NET GROUP groupname /domain, and it would list all members in a domain AD group, without having to load up AD users and computers. But from some testing it doesnt seem that accurate. For example I ran the command for an AD group, and also checked the group in ADUC, and for nested groups, the NET GROUP command doesnt appear to list them, just accounts. Is this "normal behaviour", or is NET GROUP not always accurate.
Question by:pma111
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 56

Assisted Solution

McKnife earned 1332 total points
ID: 40531117
Net group can't do that.
I bet there's a powershell alternative that can, did you already look into it?

Author Comment

ID: 40531121
can you elaborate - net group cant do what?

I have used net group to get a list of all group members, are you saying it will list accounts listed in a group, but not groups within a group?

I have access to ADUC so I can get the members there, it was just handy to use NET Group in some situations but if it doesnt give a clear picture I will swap to an alternative...
LVL 56

Expert Comment

ID: 40531130
Right, it's incapable of listing groups nested there in. Look for a powershell alternative, if you don't find it googling, I will assist.
Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

LVL 18

Expert Comment

by:Emmanuel Adebayo
ID: 40531131
This is usually correct
net group /dom <Groupname>
I used it so many times.

You can also use dsquery command
LVL 56

Accepted Solution

McKnife earned 1332 total points
ID: 40531135
http://serverfault.com/questions/49405/command-line-to-list-users-in-a-windows-active-directory-group provides the dsquery and powershell syntax that reads out nested groups as well.
LVL 24

Assisted Solution

VB ITS earned 668 total points
ID: 40531197
For example I ran the command for an AD group, and also checked the group in ADUC, and for nested groups, the NET GROUP command doesnt appear to list them, just accounts. Is this "normal behaviour", or is NET GROUP not always accurate.
This appears to be by design when it comes to the net group command. See the explanation for the groupname parameter in this link which states the following:
net group [groupname [/comment:"text"]] [/domain]

groupname: Specifies the name of the group to add, expand, or delete. Specify a group name to view a list of users in a group only.

If you need to see members within the nested groups as well then you'll need to resort to either the dsquery command or PowerShell. Examples are provided in the link McKnife posted above.

Author Comment

ID: 40531200
emmanuel - are you saying that command will aslo list nested groups within groups??

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question