Solved

LDAP search query to show group and members

Posted on 2015-01-23
4
317 Views
Last Modified: 2015-01-23
hi all

im trying to figure out a LDAP search query that will show me the group name and the members inside.
sounds fairly simple but i cant get my head around the syntax and filters..

i have the following code that finds the group name.. and this one works.

(&(objectCategory=group)(cn=SEC_Laserforms))

Open in new window


ive tried the following various queries... but with no luck, they are obviously incorrect...

Filter: (&(memberof=cn=SEC_Laserforms,dc=domain,dc=co,dc=uk))
base dn: cn=SEC_Laserforms,dc=domain,dc=co,dc=uk))
attributes: ['member']


(&(objectCategory=group)(cn=SEC_Laserforms)(objectClass=user)(sAMAccountName=*))

Open in new window


im not really sure how to put the query together so it shows me group name and the members inside that group..

is this even possible?


thanks!
0
Comment
Question by:mishcondereya
  • 2
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
Waddah Dahah earned 500 total points
Comment Utility
Hi

memberOf (in AD) is stored as a list of distinguishedNames. Your filter needs to be something like:

(&
    (objectCategory=user)
    (memberOf=cn=MyCustomGroup,ou=ouOfGroup,dc=subdomain,dc=domain,dc=com)
)

Open in new window


If you don't yet have the distinguished name, you can search for it with:

(&(objectCategory=group)(cn=myCustomGroup))

Open in new window


and return the attribute distinguishedName. Case may matter.
0
 

Author Comment

by:mishcondereya
Comment Utility
perfect!

thanks for your help, i got it working using the distinguished name... now it does what i want

(&(objectCategory=user)(memberOf=CN=SEC_Laserforms,OU=Security Groups,OU=_AD Management,OU=TEST_R1,DC=domain,DC=co,DC=uk))

Open in new window

0
 

Author Closing Comment

by:mishcondereya
Comment Utility
perfect advice

thanks
0
 
LVL 3

Expert Comment

by:Waddah Dahah
Comment Utility
Glad that i help :-)
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Batch, VBS, and scripts in general are incredibly useful for repetitive tasks.  Some tasks can take a while to complete and it can be annoying to check back only to discover that your script finished 5 minutes ago.  Some scripts may complete nearly …
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now