AD User account information

Hi All,

I need all the information Active Directory can provide on a user account:

So far i have this code:

Get-ADUser -Filter 'Name -like "*kelly*"' | select *

Open in new window


The above code, is that all the information it can provide? is there a better code i can utilise?

thank you in advance.

Kelly
Kelly GarciaSenior Systems AdministratorAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Sean Plemons Kelly, CISSPInformation Systems Security EngineerCommented:
Hello Kay,

This TechNet article outlines how to use powershell to query AD for user information.

Directly from the article: "...this article provides an introduction to the fine art of writing Active Directory search scripts using Windows PowerShell. Does this article contain everything you’ll ever need to know about writing Active Directory search scripts? Probably not. But it does include enough information to help you get started."

I hope this helps.
E ATech LeadCommented:
Get-ADUser: Getting Active Directory Users Data via Powershell
http://woshub.com/get-aduser-getting-active-directory-users-data-via-powershell/
PberSolutions ArchitectCommented:
Add a properties * to your code:

Get-ADUser -Filter 'Name -like "*kelly*"' -properties * | select *

Open in new window

OWASP: Forgery and Phishing

Learn the techniques to avoid forgery and phishing attacks and the types of attacks an application or network may face.

Jeremy WeisingerSenior Network Consultant / EngineerCommented:
The select * is redundant. But Get-ADUser will not retrieve all AD attributes. The following command will only get the extended attributes listed in this table: https://social.technet.microsoft.com/wiki/contents/articles/12037.active-directory-get-aduser-default-and-extended-properties.aspx
Get-ADUser -Filter 'Name -like "*kelly*"' -properties * 

Open in new window

To get additional attributes, you will need to specify their LDAPDisplayname

Here's info on how to enumerate all the possible attributes: http://virot.eu/getting-all-possible-classes-attributes-for-a-ad-object/

But you may want to just use csvde to export the user:
CSVDE -f export.csv -r "(&(objectClass=user)(samaccountname=username))"

Open in new window

That will get the all non-null attributes.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Kelly GarciaSenior Systems AdministratorAuthor Commented:
is that for any powershell command, to enumerate all information available you have to do properties * ?
Jeremy WeisingerSenior Network Consultant / EngineerCommented:
Unfortunately no. It all depends on the cmdlet.

Glad to help. :)
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Powershell

From novice to tech pro — start learning today.