AD User account information

Kelly Garcia
Kelly Garcia used Ask the Experts™
on
Hi All,

I need all the information Active Directory can provide on a user account:

So far i have this code:

Get-ADUser -Filter 'Name -like "*kelly*"' | select *

Open in new window


The above code, is that all the information it can provide? is there a better code i can utilise?

thank you in advance.

Kelly
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Sean Plemons Kelly, CISSPInformation Systems Security Engineer

Commented:
Hello Kay,

This TechNet article outlines how to use powershell to query AD for user information.

Directly from the article: "...this article provides an introduction to the fine art of writing Active Directory search scripts using Windows PowerShell. Does this article contain everything you’ll ever need to know about writing Active Directory search scripts? Probably not. But it does include enough information to help you get started."

I hope this helps.
E ATech Lead

Commented:
Get-ADUser: Getting Active Directory Users Data via Powershell
http://woshub.com/get-aduser-getting-active-directory-users-data-via-powershell/
PberSolutions Architect
Commented:
Add a properties * to your code:

Get-ADUser -Filter 'Name -like "*kelly*"' -properties * | select *

Open in new window

Become a Microsoft Certified Solutions Expert

This course teaches how to install and configure Windows Server 2012 R2.  It is the first step on your path to becoming a Microsoft Certified Solutions Expert (MCSE).

Senior Network Consultant / Engineer
Commented:
The select * is redundant. But Get-ADUser will not retrieve all AD attributes. The following command will only get the extended attributes listed in this table: https://social.technet.microsoft.com/wiki/contents/articles/12037.active-directory-get-aduser-default-and-extended-properties.aspx
Get-ADUser -Filter 'Name -like "*kelly*"' -properties * 

Open in new window

To get additional attributes, you will need to specify their LDAPDisplayname

Here's info on how to enumerate all the possible attributes: http://virot.eu/getting-all-possible-classes-attributes-for-a-ad-object/

But you may want to just use csvde to export the user:
CSVDE -f export.csv -r "(&(objectClass=user)(samaccountname=username))"

Open in new window

That will get the all non-null attributes.
Kelly GarciaSenior Systems Administrator

Author

Commented:
is that for any powershell command, to enumerate all information available you have to do properties * ?
Jeremy WeisingerSenior Network Consultant / Engineer

Commented:
Unfortunately no. It all depends on the cmdlet.

Glad to help. :)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial