Improve company productivity with a Business Account.Sign Up

x
?
Solved

LDAP search query to show group and members

Posted on 2015-01-23
4
Medium Priority
?
2,805 Views
Last Modified: 2015-01-23
hi all

im trying to figure out a LDAP search query that will show me the group name and the members inside.
sounds fairly simple but i cant get my head around the syntax and filters..

i have the following code that finds the group name.. and this one works.

(&(objectCategory=group)(cn=SEC_Laserforms))

Open in new window


ive tried the following various queries... but with no luck, they are obviously incorrect...

Filter: (&(memberof=cn=SEC_Laserforms,dc=domain,dc=co,dc=uk))
base dn: cn=SEC_Laserforms,dc=domain,dc=co,dc=uk))
attributes: ['member']


(&(objectCategory=group)(cn=SEC_Laserforms)(objectClass=user)(sAMAccountName=*))

Open in new window


im not really sure how to put the query together so it shows me group name and the members inside that group..

is this even possible?


thanks!
0
Comment
Question by:mishcondereya
  • 2
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
Waddah Dahah earned 2000 total points
ID: 40566206
Hi

memberOf (in AD) is stored as a list of distinguishedNames. Your filter needs to be something like:

(&
    (objectCategory=user)
    (memberOf=cn=MyCustomGroup,ou=ouOfGroup,dc=subdomain,dc=domain,dc=com)
)

Open in new window


If you don't yet have the distinguished name, you can search for it with:

(&(objectCategory=group)(cn=myCustomGroup))

Open in new window


and return the attribute distinguishedName. Case may matter.
0
 

Author Comment

by:mishcondereya
ID: 40566453
perfect!

thanks for your help, i got it working using the distinguished name... now it does what i want

(&(objectCategory=user)(memberOf=CN=SEC_Laserforms,OU=Security Groups,OU=_AD Management,OU=TEST_R1,DC=domain,DC=co,DC=uk))

Open in new window

0
 

Author Closing Comment

by:mishcondereya
ID: 40566494
perfect advice

thanks
0
 
LVL 3

Expert Comment

by:Waddah Dahah
ID: 40567028
Glad that i help :-)
0

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
Transferring FSMO roles is done when an admin wants to split roles between certain Domain Controllers or the Domain Controller holding the Roles has been forcefully demoted using dcpromo / forceremoval
In this fourth video of the Xpdf series, we discuss and demonstrate the PDFinfo utility, which retrieves the contents of a PDF's Info Dictionary, as well as some other information, including the page count. We show how to isolate the page count in a…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

595 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question