I am trying to get all group members from "Domain Users". When using AD Users MMC tab, I get a lot of results. When using ADSI - not. The following DOESN'T work as expected:
- looking at members attribute of the group entry via LDAP/ADSI. It returns only 56 members when there are considerably more.
- searching by memberOf (returns just a few entries)
- searching by primaryGroup (it is not a primary group)
- searching by tokenGrops (it is a constructed attribute)
any ideas appreciated.
Domain Users
? Normally, this is the case unless you change it deliberately. Also note that the primaryGroupToken forDomain Users
is 513. So, doing this LDAP query should give you all the users with primary group set toDomain Users
(&(objectCategory=person)(objectClass=user)(primaryGroupID=513))
– Harvey Kwok