Solved

*** more than 5k in the group*** Count how many active directory group members for more than one AD group

Posted on 2016-09-01
8
112 Views
Last Modified: 2016-09-02
Hi SubSun or all ..  forgot to mention the group contains more than 5000 users in the group so the script below times out.
Can someone help me modify this ?

Import-Module Activedirectory
GC C:\group.txt | %{
      New-Object PSobject -Property @{
      Group = $_
      UserCount = (Get-ADGroupMember $_ -Recursive | Measure).Count
      }
}| Select Group,UserCount
0
Comment
Question by:MilesLogan
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 40

Expert Comment

by:Subsun
ID: 41781481
Do you have full rights on all the groups members of this groups which you are checking? Try to run the script with a domain admin account and see if it gives same error.

Or is it a multi domain environment? Do you have groups from other domain as member of the group which you are checking?
0
 
LVL 2

Author Comment

by:MilesLogan
ID: 41781671
Hi SubSun

Tested with my DA account from a DC and it also failed with the error below .
This was just one group in the text file with over 5000 accounts .

Get-ADGroupMember : The size limit for this request was exceeded
At C:\PS\GetGroupCount.ps1:5 char:15
+     UserCount = (Get-ADGroupMember $_ -Recursive | Measure).Count
+                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (MyGroup:ADGroup) [Get-ADGroupMember], ADException
    + FullyQualifiedErrorId : ActiveDirectoryServer:8227,Microsoft.ActiveDirectory.Management.Commands.GetADGroupMember

weird is this does work with the same group over 5000 accounts with or without the DA account.
(Get-ADGroup MyGroup -properties *).member.count

All groups are from the same domain .
0
 
LVL 40

Expert Comment

by:Subsun
ID: 41781719
You need to modify the MaxGroupOrMemberEntries to more than 5000

Ref : https://technet.microsoft.com/en-us/library/dd391908(WS.10).aspx

If that's not possible then, I can try to write a workaround code..


Or do you have quest AD PowerShell module?
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 2

Author Comment

by:MilesLogan
ID: 41781809
I can't modify the MaxGroupOrMemberEntries  .. toooooooo many approvals required ..

Yes , I have the quest AD PoweShell Module .
0
 
LVL 40

Accepted Solution

by:
Subsun earned 500 total points
ID: 41781819
Ok try this from Quest AD PoweShell Module and see if it works..
Add-PSSnapin Quest* 
 GC C:\group.txt | %{
       New-Object PSobject -Property @{
       Group = $_
       UserCount = (Get-QADGroupMember $_ -Type 'user' -Indirect | Measure).Count
       }
 }| Select Group,UserCount

Open in new window

0
 
LVL 2

Author Comment

by:MilesLogan
ID: 41781919
this worked but I got the warning message about only being able to retrieve the first 1000 results , so it does not give me the total number .


.. increase the size limi using the -Sizelimit parameter or set the default size limit using the Set-QASPSSnapinSettings ..
0
 
LVL 40

Expert Comment

by:Subsun
ID: 41781925
Change line 5 to following..
       UserCount = (Get-QADGroupMember $_ -Type 'user' -Indirect -Sizelimit 0 | Measure).Count

Open in new window

0
 
LVL 2

Author Closing Comment

by:MilesLogan
ID: 41782029
Thanks man .. definitely slower than the one liner but it will work .. thanks !
0

Featured Post

MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question