Re: LDAP Domain Users membership list 4 people, ADUC MMC snap-in 400

Tech-Archive recommends: Fix windows errors by optimizing your registry



That sounds more like there's a problem with your code.

Have you verified it against other groups?



<jpdicicco@xxxxxxxxx> wrote in message
news:481230d9-b6e0-466b-b3b6-12cb5eb74f62@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I'm having an issue with running a report against AD. I'm trying to
build reports of group memberships via WSH (jscript), but my Domain
Users group keeps coming back with only 4 members. When I view the
group in ADUC, all of the members show up.

It seems that any LDAP access method of checking the directory (dsget,
ADSI Edit, etc.) only shows 4 members, but ADUC and `net group /domain
"domain users"` show all of the members.

I need to know the following:
1. Is Domain Users special this way or are other groups possibly
different in LDAP from their actual membership?
2. Where is the membership stored, if not in the member attribute?
3. How can I get a complete list of members programatically (jscript/
vbscript)?

Current domain and forest functional levels: Windows Server 2003

Any help would be appreciated.

Thanks in advance!

JP


.



Relevant Pages

  • Re: Prevent Users interactive login, but allow them to run batch j
    ... That user is member of "Domain Users" group. ... on Locally) But the second setting "Log on as batch job" has no effect. ... but that the account needs something else. ... Domain Users as well as Authenticated Users are made members ...
    (microsoft.public.win2000.security)
  • Re: users have gray hair in Domain Users group
    ... The members of domain users group in both of the tree domains have ... when I use the below script to enumerate the membership of the ... domain users group in each of the domains, ... any reasons why I cannot enumerate the Domain Local group? ...
    (microsoft.public.win2000.active_directory)
  • Re: simple distribution lists?
    ... list members change, someone has to go into ADUC and add/delete/reconfigure, ... > However, if you want to internal users send email to a distribution list, ... > the persons in the list are unnecessary to be domain users or contacts. ... Open outlook. ...
    (microsoft.public.windows.server.sbs)
  • Re: Can this be done without affecting current configuration
    ... group so it only belong to the nondomainuser group. ... is able to access the shared folder without problem. ... the members in the domain users group which is something I don't want. ...
    (microsoft.public.windows.server.security)
  • Re: Prevent Users interactive login, but allow them to run batch j
    ... needed for this account to run the job without being an admin. ... on Locally) But the second setting "Log on as batch job" has no ... Domain Users as well as Authenticated Users are made members ...
    (microsoft.public.win2000.security)