Wednesday 8 April 2020

get ad security groups applied to an AD user

$id = [Security.Principal.WindowsIdentity]("username")
$groups = $id.Groups | foreach-object {$_.Translate([Security.Principal.NTAccount])}
$groups | select *

to find specific group:

$id = [Security.Principal.WindowsIdentity]("username")
$groups = $id.Groups | foreach-object {$_.Translate([Security.Principal.NTAccount])}
$groups | findstr /i "vpn"


to find members of a particular group in AD
Get-adgroupmember -identity "domain admins" -Recursive | Select-Object name, objectclass

No comments:

Post a Comment