How to Get AD User’s Group Membership

To Get User's security group membership Run below command: Get-ADPrincipalGroupMembership -Identity user  | where {$_.groupCategory -eq 'Security'} |  add-adgroupmember -members USER To get all groups that a user is a member of Run below command: Get-ADPrincipalGroupMembership username | select name Name —- Domain Users Domain Computers Workstation Admins Company Users Company Developers AutomatedProcessingTeam Another command

How to Fix – Event ID: 1121 Source: NTDS

The format of the schedule attribute of the following object is unrecognizable. As per Microsoft: "The format of the specified object's Schedule attribute is not recognizable. A default schedule will be substituted. This event will continue to occur until the Schedule attribute on this object is corrected". – Have you made any changes in AD

Export list of all Active Directory Security Groups with their Members

  Learn how to easily export Active Directory Security Groups with their members to a CSV file in Windows PowerShell.   Here is a Script: $Groups = Get-ADGroup -Properties * -Filter * -SearchBase "OU=Groups,DC=corp,DC=ourcompany,DC=Com" Foreach($G In $Groups) { Write-Host $G.Name Write-Host "————-" $G.Members } Here is another Script: $Groups = Get-ADGroup -Properties * -Filter {GroupCategory -eq "Security"}

Powershell Script to Get List of Active Users with the Details like samaccountname, name, department, job tittle, email in Active Directory

  In this blog will see how to list active users with details like samaccountname, name, department, job tittle, email, etc., in Active Directory using powershell script.    A dsquery solution: dsquery * -Filter "(&(objectCategory=person)(objectClass=user))" -Attr givenName sn displayName sAMAccountName mail proxyAddresses distinguishedName > AllUsers.txt   A PowerShell solution using the AD module cmdlet: Get-ADUser

Powershell Script to Get “lastLogon Timestamp” for Specific OU and Export to CSV File

  Learn how to get lastlogon timestamp for specific OU and export to CSV by using Powershell script. A PowerShell solution using the AD module cmdlet: Get-ADUser -Filter * -SearchBase "ou=users,dc=contoso,dc=local" -ResultPageSize 0 -Prop CN,lastLogonTimestamp | Select CN,lastLogonTimestamp | Export-CSV -NoType last.csv   If you want get a date: Get-ADUser -Filter * -SearchBase "ou=users,dc=contoso,dc=local" -ResultPageSize

How to Export a Computer List from Active Directory

In this blog will see how to export a computers list from Active Directory by using Powershell script into various formats, including csv and Excel. Open the Powershell ISE → Run the below script, adjust the path for the export: Get-ADComputer -Filter * -Property * | Select-Object Name,OperatingSystem,OperatingSystemVersion,ipv4Address | Export-CSV ADcomputerslist.csv -NoTypeInformation -Encoding UTF8 Using

How to Trace the Source of a Bad Password and Account Lockout in AD

In this blog, we will see how to trace the source of a bad password and account lockout in Active Directory. Step 1: Download Account Lockout Status tool from Microsoft from You can download from here: Step 2: Now Run LockoutStatus.exe For this you need to run the .msi to extract the files and

Common Causes for Account Lockouts – Resolution and Troubleshooting Steps

In this article, we will discuss about the Common Causes for Account Lockouts and troubleshooting steps and resolutions for account lockouts. In order to avoid account lockouts, you need to check each computer on which a lockout occurred for the following reasons: Programs: Most of the programs cache credentials or keep active threads that retain