deeejay icon

dsquery commands for AD

deeejay | PRO | 08/31/26 01:09:12 AM UTC (Edited) | 0 ⭐ | 504 👁️ | Never ⏰ | []
Batch |

5.05 KB

|

None

|

0 👍

/

0 👎

dsget user <UserDN> [-dn] [-samid] [-sid] [-upn] [-fn] [-mi] [-ln] [-display] [-empid] [-desc] [-office] [-tel] [-email] [-hometel] [-pager] [-mobile] [-fax] [-iptel] [-webpg] [-title] [-dept] [-company] [-mgr] [-hmdir] [-hmdrv] [-profile] [-loscr] [-mustchpwd] [-canchpwd] [-pwdneverexpires] [-disabled] [-acctexpires] [-reversiblepwd] [{-uc | -uco | -uci}] [-part <PartitionDN> [-qlimit] [-qused]]
dsget user <UserDN> [-memberof] [-expand][{-uc | -uco | -uci}]
 
Other sources: 
http://nickbeare.com/ad_cmd.html
 
Note: You can use these command line utilities after installing the AdminPak or simply copying the DS *.exe files to your computer. Suggest adding path to files to environment variables for quick access via command prompt.
 
IMPORTANT: Starting with Windows 10 October 2018 Update, add RSAT tools right from Windows 10. Just go to "Manage optional features" in Settings and click "Add a feature" to see the list of available RSAT tools.
 
User Commands
List user's DN
dsquery user -name someuser
 
List user's memberships
dsquery user -name someuser | dsget user -memberof -expand
 
List user's first name, last name, and title
dsquery user -name someuser | dsget user -samid -fn -ln -title
 
List user's telephone number
dsquery user -name someuser | dsget user -tel
 
List user's fax number
dsquery user -name someuser | dsget user -fax
 
List user's email
dsquery user -name someuser | dsget user -email
 
List user's title
dsquery user -name someuser | dsget user -title
 
List all disabled users
dsquery user "OU=someou,OU=anotherou,dc=somedomain,dc=org" -disabled
 
Check if a user is disabled
dsquery user -name someuser -disabled
 
Note: If the user is disabled, his/her DN will be displayed
List user's mailbox
dsquery * -filter "samaccountname=someuser" -attr homemdb
 
List all members in OU
dsquery user "OU=someou,OU=anotherou,dc=somedomain,dc=org"
 
Export user attributes (Takes a while to run - Press Ctrl+C to quit)
dsquery * -limit 0 -filter "&(objectClass=User)(objectCategory=Person)" -attr * >> c:\output.txt
 
List all users with "Director" in the title attribute (limit to 150 results)
dsquery * "OU=someou,OU=anotherou,dc=somedomain,DC=ORG" -filter "(&(objectCategory=Person)(objectCategory=User)(title=*Director*))" -attr name title -limit 150
 
Search for a user by first name
dsquery * -filter "(&(objectCategory=Person)(objectClass=User)(givenName=John*))" | dsget user -fn -ln -samid -title 
 
 
Computer Commands
 
List computer's DN
dsquery computer -name somedevice
 
List multiple computer's DNs
dsquery computer -name somedevice*
 
List computer's memberships
dsquery computer -name somedevice | dsget computer -memberof -expand
 
List computers with Windows XP Computers with Service Pack 2 Installed
dsquery * "OU=someou,OU=anotherou,dc=somedomain,dc=org" -filter "(&(objectCategory=computer)(operatingSystem=Windows XP Professional)(operatingSystemServicePack=Service Pack 2))"
 
List enabled computer accounts in OU
dsquery computer "OU=someou,OU=anotherou,dc=somedomain,dc=org" -limit 5000 | dsget computer -dn -disabled | find /c /i " no"
 
Reset a computer account
dsmod computer "cn=somedevice,ou=Laptops,ou=Computers,OU=someou,OU=anotherou,dc=somedomain,DC=org" -reset
 
 
Group Commands
 
List all   security groups that begin with GPO-15
dsquery group -name GPO-15*
 
List security groups with a partial name
dsquery group -name SomeName*File*
 
 
Admin Commands
 
List all AD Servers
dsquery server
 
List all DNs
dsquery partitions
 
 
Group Commands
 
Wildcard search for all groups beginning with 10_PIC
dsquery group -name 10_PIC*
 
Export member DNs of a specified group
dsget group "CN= -DragonVoiceProfiles Group,OU=Security Groups,OU=Groups,OU=someou,OU=anotherou,dc=somedomain,DC=org" -members >> sb.txt
 
Export username, firstname, lastname, title, department for members of a specified group (use -c to continue exporting if errors are found, i.e. device user accounts)
dsquery group -name 10_PICPOwerChart | dsget group -members -expand -c | dsget user -samid -fn -ln -title -dept -c >> 10_PICPOWERCHART.txt
 
List firstname, lastname, title from a specified group
dsquery group -name "AH Azure DNA Dev Team" | dsget group -members | dsget user -fn -ln -title
 
Count from list above but subtract 2 for header line and "dsget succeeded" line
dsquery group -name "AH Azure DNA Dev Team" | dsget group -members | dsget user -fn -ln -title | find /c /v ""
 
Display each group and respective members in each group
for /f "delims=" %G in ('dsquery group -name "Operational Finance PowerBI*"') do (
    echo Group: %G
    dsget group %G -members
)
 
for /f "delims=" %G in ('dsquery group -name "AH Azure*"') do (
    echo Group: %G
    dsget group %G -members
)
 
 
for /f "delims=" %G in ('dsquery group -name "AH Azure*"') do (
    for /f "tokens=2 delims==," %H in ('echo %G') do (
        echo Processing group: %H
        dsget group %G -members > "%H.txt"
    )
)
 
 
 
Find user in domain by SID
dsquery user "dc=your_domain,dc=org" | dsget user -samid -sid | find "S-1-5-21-1960408961-823518204-839522115-97681"

Comments