Using DSquery to find member of in AD


Recommended Posts

I think you want to use dsget. but I don't think it will do what you are looking for. what you want are two different things. One is to scan active directory for group membership the other is to scan folders for directory accessability/permissions. This is where network design really comes into play and understanding how to build one. It sounds as if you are taking over someone elses mess and trying to figure it out, all I can say is get your clicker going. Take a look at what is being shared. You can use the perms command to be able to see what permissions x user has over the computer/server. perms is part of the 2003 resource kit which is free to dl from microsoft.

There is probably a third party tool that has the capability you are looking for, and it will more than likely cost.

How I would do it is look at the groups, find out the members of each group, find out what these members need access to. Look at the shares, see who has access to each share (this can be done by right clicking on my computer and clicking on manage, going into shared folders, then going into shares you can easily see all of the shares on one computer and you can easily manage the shares from here). It is a lot of work, but so is reading a text file and figuring out how to create said text file. Bottom line, it isn't easy, I have done this hundreds of times over (taking over a mess).

you need to pipe your commands... try something like this

dsquery user -name "*UserName*" | dsget user -memberOf

what this will do it query AD for a specific user and take the output of that and list what groups the user is a member of.

if you do dsget user /? it will give you everything you can get about the user as well.

Hope that helps

I think point sc302 was trying to make - is sure you can find the group memberships of a user, but that is not going to tell you where those groups have permissions or what they are, etc.

You might want to check out

http://technet.microsoft.com/en-us/sysinternals/bb664922.aspx

and

http://technet.microsoft.com/en-us/sysinternals/bb897332.aspx

  On 23/06/2010 at 16:12, BudMan said:

I think point sc302 was trying to make - is sure you can find the group memberships of a user, but that is not going to tell you where those groups have permissions or what they are, etc.

You might want to check out

http://technet.microsoft.com/en-us/sysinternals/bb664922.aspx

and

http://technet.microsoft.com/en-us/sysinternals/bb897332.aspx

was I not clear on that?

No you were clear, atleast to me - but I took it as the other poster did not catch the meaning of your post, atleast he made no mention that group membership will not give him what I took as what the user was after.

"permissions, directory access, groups etc."

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I gave you an upvote because you are my favorite Neowinian!
    • Alienware 34 240Hz QD-OLED Monitor: A premium ultrawide for serious gamers - save $100! by Paul Hill Are you a serious gamer looking to save money on a monitor upgrade? If so, check out this deal on the Alienware 34 240Hz QD-OLED Gaming Monitor (AW3425DW), which is discounted by 13% from $799.99 to just $699.99. This ultrawide monitor features a 3,440 x 1,440 pixel display and the screen is curved for added immersion. Two features that will stand out to competitive gamers are the 240Hz refresh rate and 0.03ms GtG response time which will minimize any lagging from input to display, making you a more lethal player. Why QD-OLED matters for gamers and creators This Alienware uses QD-OLED (Quantum Dot Organic Light Emitting Diode) technology which combines OLED’s self-emitting LEDs with the color-enhancing capabilities of quantum dots. This results in higher brightness, a wider color gamut, deeper blacks, and wide viewing angles. With the 1800R curve built into this display, whatever you’re immersed in will wrap around, making your games more absorbing, potentially reducing other distractions. There is also VESA DisplayHDR TrueBlack 400 certification and 1,000 nits peak HDR brightness on this display. Gamers using this monitor will be able to get the best quality picture from this monitor to improve the experience and their competitiveness. It’s also good for creators who want to edit images and videos as they will see the content they're editing in the best ways possible, so they can be totally sure it’s ready for publication. Design, connectivity, and user experience The Alienware 34 uses an updated Interstellar Indigo design which is more compact and uses a flat stand. This frees up desk space compared to older Alienware designs and still allows for height, tilt, and swivel adjustments and VESA mount compatibility. Regarding ports, this monitor features 2x HDMI 2.1, 1x DisplayPort 1.4, 1x USB 5Gbps Type-B upstream, 1x USB 5Gbps Type-A downstream, 1x USB-C 5Gbps downstream with 15W charging. The USB-C port is for data and charging, not video input and the lack of KVM switch could be a drawback for some. If you decide to pick up this monitor, according to PCWorld, it does not include in-built speakers so you will need to connect your own. This is not a big issue because gamers looking for a premium playing experience will not want to rely on subpar in-built speakers anyway. Is the AW3425DW the right fit for you? Given its curved display, quality QD-LED display technology, and its fast response time, this monitor is a great pick for serious gamers looking for top-tier performance and immersion. Content creators who value color accuracy will also do well in picking up this Alienware monitor. Alienware 34: $699.99 (Amazon US) / MSRP $799.99 This Amazon deal is US-specific and not available in other regions unless specified. If you don't like it or want to look at more options, check out the Amazon US deals page here. Get Prime (SNAP), Prime Video, Audible Plus or Kindle / Music Unlimited. Free for 30 days. As an Amazon Associate, we earn from qualifying purchases.
    • Needs to happen quicker IMO. Pretty dang sick of the same articles reworded five different ways and reposted. I’m sure some people like reading the typical MS tells you why Windows 11 is better article over and over or the minute by minute countdown on the EOL of Windows 10, but I’m not one of them.
  • Recent Achievements

    • Rising Star
      Phillip0web went up a rank
      Rising Star
    • One Month Later
      Epaminombas earned a badge
      One Month Later
    • One Year In
      Bert Fershner earned a badge
      One Year In
    • Reacting Well
      ChrisOdinUK earned a badge
      Reacting Well
    • One Year In
      Steviant earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      545
    2. 2
      ATLien_0
      205
    3. 3
      +FloatingFatMan
      170
    4. 4
      Michael Scrip
      150
    5. 5
      Som
      131
  • Tell a friend

    Love Neowin? Tell a friend!