?
Solved

A more efficient LDAP filter

Posted on 2016-09-20
3
Medium Priority
?
113 Views
Last Modified: 2016-09-21
Each attribute here is definitely indexed, but the search takes too long.

What can I do to make it more efficient?

(&(|(mail=John.M.Doe@*)(proxyAddresses=*:John.M.Doe@*))(!(employeeID=123456)))

Open in new window

0
Comment
Question by:Dallas Smetter
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 6

Expert Comment

by:sAMAccountName
ID: 41807717
you could try using ambiguous name resolution and scoping the search to a targeted subtree.

I'm on mobile or I'd post a link, but you can easily Google " active directory anr" and get some good info
0
 
LVL 17

Accepted Solution

by:
Learnctx earned 2000 total points
ID: 41807889
The reason your response time is so horrible is you have an open ended filter in your query:

(proxyAddresses=*:John.M.Doe@*)

Open in new window


This means you will generate a hugely inefficient query. Even though the attributes are indexed, you're going to end up touching every object in the directory that has a proxyAddresses attribute populated.

Is there any reason you're not specifying the protocol? You would be better to include the protocols you're looking for. Its always better to be more specific if you want a quick result. Either that or you need another attribute which limits the query scope instead of (!(employeeID=123456)).

This should return an instant result.

(&(|(mail=John.M.Doe@*)(proxyAddresses=smtp:John.M.Doe@*)(proxyAddresses=sip:John.M.Doe@*)(proxyAddresses=notes:John.M.Doe@*))(!(employeeID=123456)))

Open in new window


you could try using ambiguous name resolution and scoping the search to a targeted subtree.

ANR is great but in this case won't work any better than just using proxyaddresses, in my opinion.

Edit: There's a good Wiki article here on the MS community Wiki http://social.technet.microsoft.com/wiki/contents/articles/22653.active-directory-ambiguous-name-resolution.aspx
1
 

Author Closing Comment

by:Dallas Smetter
ID: 41809675
Thank you!!!
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes how to use a set of graphical playing cards to create a Draw Poker game in Excel or VB6.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This Micro Tutorial demonstrates in Microsoft Excel how to consolidate your marketing data by creating an interactive charts using form controls. This creates cool drop-downs for viewers of your chart to choose from.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question