Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

domain accounts / groups

Status
Not open for further replies.

prinand

MIS
Jun 13, 2000
98
GB
is there a possebility to make a listing on a PDC which lists all the groups and the members in every group ?

The previous administrator created a lot of groups so it is quite a hassle tro add /remove people from groups if eg. some one gets replaced and the new guy needs the same acces as his predecessor. [sig][/sig]
 
To my knowledge there is no way you can display all. I am used to running domains which were already set (permissions, groups, etc.) a best practice I have found is. You can take the original person (the one who has quit) and copy their account to their replacement prior to disabling/deleting it. That way you don't have to search on their access to the domain. Just rename the account as opposed to deleting it until the new guys starts, that way you don't have to reapply anything for the new person. Once you create the new account you can delete the old employees...
[sig][/sig]
 
Check out SHOWGRPS in the NT Server resource kit. It will give it to you by user. You should be able to pipe a list of user logins to it and redirect the output to a file, or do it as needed by user.

Sample output from 'showgrps ELECTRIC\ataylor':

User: [ELECTRIC\ataylor], is a member of:

ELECTRIC\Domain Users
\Everyone
ELECTRIC\SCADA

[sig][/sig]
 
Try using one of these utilities, Hyena or Dameware, they both offer a soution to your problem. [sig][/sig]
 
DOH! I just started using Hyena and forgot all about it. You are correct, it has all you need to get that info. [sig][/sig]
 
I was reading a magazine article the other day that addressed showing the groups and who was a member. The utility mentioned was DumpSec (formally DumpACL) utility. It is located at Hope this helps
[sig][/sig]
 
If a new person joins your organization... simple rename the previous account with the new person's name. You then remove any groups that that person doesnt need to belong to. [sig][/sig]
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top