Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

LDAP search query to show group and members

Posted on 2015-01-23
4
Medium Priority
?
2,046 Views
Last Modified: 2015-01-23
hi all

im trying to figure out a LDAP search query that will show me the group name and the members inside.
sounds fairly simple but i cant get my head around the syntax and filters..

i have the following code that finds the group name.. and this one works.

(&(objectCategory=group)(cn=SEC_Laserforms))

Open in new window


ive tried the following various queries... but with no luck, they are obviously incorrect...

Filter: (&(memberof=cn=SEC_Laserforms,dc=domain,dc=co,dc=uk))
base dn: cn=SEC_Laserforms,dc=domain,dc=co,dc=uk))
attributes: ['member']


(&(objectCategory=group)(cn=SEC_Laserforms)(objectClass=user)(sAMAccountName=*))

Open in new window


im not really sure how to put the query together so it shows me group name and the members inside that group..

is this even possible?


thanks!
0
Comment
Question by:mishcondereya
  • 2
  • 2
4 Comments
 
LVL 3

Accepted Solution

by:
Waddah Dahah earned 2000 total points
ID: 40566206
Hi

memberOf (in AD) is stored as a list of distinguishedNames. Your filter needs to be something like:

(&
    (objectCategory=user)
    (memberOf=cn=MyCustomGroup,ou=ouOfGroup,dc=subdomain,dc=domain,dc=com)
)

Open in new window


If you don't yet have the distinguished name, you can search for it with:

(&(objectCategory=group)(cn=myCustomGroup))

Open in new window


and return the attribute distinguishedName. Case may matter.
0
 

Author Comment

by:mishcondereya
ID: 40566453
perfect!

thanks for your help, i got it working using the distinguished name... now it does what i want

(&(objectCategory=user)(memberOf=CN=SEC_Laserforms,OU=Security Groups,OU=_AD Management,OU=TEST_R1,DC=domain,DC=co,DC=uk))

Open in new window

0
 

Author Closing Comment

by:mishcondereya
ID: 40566494
perfect advice

thanks
0
 
LVL 3

Expert Comment

by:Waddah Dahah
ID: 40567028
Glad that i help :-)
0

Featured Post

Creating Active Directory Users from a Text File

If your organization has a need to mass-create AD user accounts, watch this video to see how its done without the need for scripting or other unnecessary complexities.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Originally, this post was published on Monitis Blog, you can check it here . In business circles, we sometimes hear that today is the “age of the customer.” And so it is. Thanks to the enormous advances over the past few years in consumer techno…
High user turnover can cause old/redundant user data to consume valuable space. UserResourceCleanup was developed to address this by automatically deleting user folders when the user account is deleted.
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Suggested Courses

579 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question