{"id":54173,"date":"2009-03-17T14:54:00","date_gmt":"2009-03-17T14:54:00","guid":{"rendered":"https:\/\/blogs.technet.microsoft.com\/heyscriptingguy\/2009\/03\/17\/hey-scripting-guy-how-can-i-search-active-directory-from-within-windows-powershell\/"},"modified":"2009-03-17T14:54:00","modified_gmt":"2009-03-17T14:54:00","slug":"hey-scripting-guy-how-can-i-search-active-directory-from-within-windows-powershell","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/scripting\/hey-scripting-guy-how-can-i-search-active-directory-from-within-windows-powershell\/","title":{"rendered":"Hey, Scripting Guy! How Can I Search Active Directory from Within Windows PowerShell?"},"content":{"rendered":"<p class=\"MsoNormal\"><span><font face=\"Calibri\"><span class=\"Apple-style-span\"><img decoding=\"async\" class=\"nearGraphic\" title=\"Hey, Scripting Guy! Question\" height=\"34\" alt=\"Hey, Scripting Guy! Question\" width=\"34\" align=\"left\" border=\"0\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/q-for-powertip.jpg\"><\/span><\/font><\/span><font face=\"Calibri\"><\/p>\n<blockquote>\n<blockquote>\n<p><span><font face=\"Calibri\">Hey Scripting Guy! It seems that searching Active Directory from within Windows PowerShell is rather easy. But what I do not get is the syntax for the query. In the past I used something that looked more like SQL that the examples you show. What gives?<\/p>\n<p><\/font><\/span><\/p>\n<p>&#8211; RH<\/p>\n<\/blockquote>\n<\/blockquote>\n<p class=\"MsoNormal\"><img decoding=\"async\" height=\"5\" alt=\"Spacer\" width=\"5\" border=\"0\" src=\"https:\/\/devblogs.microsoft.com\/scripting\/wp-content\/uploads\/sites\/29\/2019\/05\/spacer.gif\"><img decoding=\"async\" class=\"nearGraphic\" title=\"Hey, Scripting Guy! Answer\" height=\"34\" alt=\"Hey, Scripting Guy! Answer\" width=\"34\" align=\"left\" border=\"0\" src=\"https:\/\/devblogs.microsoft.com\/wp-content\/uploads\/sites\/29\/2019\/02\/a-for-powertip.jpg\"><\/p>\n<p><\/font><\/p>\n<p><font face=\"Calibri\">Hi PS,<\/font><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\"><\/font><\/span><\/p>\n<p><span><font face=\"Calibri\">I was watching the <\/font><a href=\"http:\/\/video.msn.com\/?mkt=en-us&amp;vid=94779b5c-a99a-426b-aa98-9ee72615a992&amp;playlist=videoByTag:tag:wacky%20animals:ns:Gallery:mk:us:vs:1&amp;from=MSNHP&amp;tab=m1210975590336&amp;GT1=42003\"><span><font face=\"Calibri\">Ninja bear<\/font><\/span><\/a><font face=\"Calibri\"> on MSN Video pretty cool actually. I don&#8217;t think I would want to fight him (or her &hellip; never can tell with bears). We are finally digging out from underneath the big Charlotte, North Carolina, USA snow storm and the sun if shining, there are birds singing &hellip; more like a normal southern winter &hellip; around 60 degrees or so outside (15.5 degrees Celsius using my handy <\/font><a href=\"http:\/\/www.microsoft.com\/technet\/scriptcenter\/resources\/qanda\/oct08\/hey1027.mspx\"><span><font face=\"Calibri\">temperature conversion HTA<\/font><\/span><\/a><font face=\"Calibri\">).<span>&nbsp; <\/span>So I thought what is there better to do than to watch a Ninja bear and check my <\/font><a href=\"http:\/\/blogs.technet.commailto:scripter@Microsoft.Com\"><span><font face=\"Calibri\">scripter@Microsoft.Com<\/font><\/span><\/a><font face=\"Calibri\"> email. Let&#8217;s take a look at the LDAP dialect that is used to query Active Directory. Also since this is sort of a weather holiday here in Charlotte (I mean we are digging out from under a massive snow blizzard) we will not be writing a script. However, with Windows PowerShell there are lots of things that do not require scripts. <\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">This week we are talking about searching Active Directory. The Active Directory Script Center Hub is seen <\/font><a href=\"http:\/\/www.microsoft.com\/technet\/scriptcenter\/hubs\/ad.mspx\"><span><font face=\"Calibri\">here<\/font><\/span><\/a><font face=\"Calibri\">. It has links to a number of resources related to working with Active Directory. There is a good collection of scripts that illustrate searching Active Directory in <\/font><a href=\"http:\/\/www.microsoft.com\/technet\/scriptcenter\/scripts\/ad\/search\/default.mspx\"><span><font face=\"Calibri\">this section<\/font><\/span><\/a><font face=\"Calibri\"> of the Script Center Script Repository. There are several scripts in the <\/font><a href=\"http:\/\/www.microsoft.com\/technet\/scriptcenter\/csc\/scripts\/ad\/general\/index.mspx\"><span><font face=\"Calibri\">Community Submitted Scripts Center<\/font><\/span><\/a><font face=\"Calibri\"> that also illustrate searching Active Directory. The Hey Scripting Guy! <\/font><a href=\"http:\/\/www.microsoft.com\/technet\/scriptcenter\/resources\/qanda\/ad.mspx\"><span><font face=\"Calibri\">active directory archive<\/font><\/span><\/a><font face=\"Calibri\"> is also an excellent source of information for searching Active Directory. <\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">There are a couple of options available to us when it comes to querying Active Directory from the PowerShell prompt. One is to use the [ADSISearcher] type accelerator that is available in Windows PowerShell 2.0 (currently in beta). The [ADSISearcher] type accelerator is a shortcut to the System.DirectoryServices.DirectorySearcher class. All the [ADSISearcher] type accelerator does is save us a little bit of typing. We still need to give it the appropriate constructor to actually create an instance of the class. <\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">If we do not use the [ADSISearcher] we need to use the New-Object cmdlet to create the object. We can put the New-Object command inside smooth parentheses to force the creation of the object first, and then call the <i>FindAll<\/i> method from the DirectorySearcher object. The resulting collection of <i>DirectoryEntry<\/i> objects is pipelined to the Select-Object cmdlet where the <i>Path<\/i> property is returned.<span>&nbsp; <\/span>This is seen here.<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">PS C:&gt; (New-Object DirectoryServices.DirectorySearcher &#8220;ObjectClass=user&#8221;).FindAll() | <\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">Select-object -property path<\/p>\n<p>Path<br>&#8212;-<br>LDAP:\/\/CN=Administrator,CN=Users,DC=nwtraders,DC=com<br>LDAP:\/\/CN=Guest,CN=Users,DC=nwtraders,DC=com<br>LDAP:\/\/CN=BERLIN,OU=Domain Controllers,DC=nwtraders,DC=com<br>LDAP:\/\/CN=krbtgt,CN=Users,DC=nwtraders,DC=com<br>LDAP:\/\/CN=VISTA,CN=Computers,DC=nwtraders,DC=com<br>LDAP:\/\/CN=VistaAdmin,OU=Students,DC=nwtraders,DC=com<br>List Truncated &ndash;<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">To use the [ADSISearcher] type accelerator, we still need to supply it with an appropriate constructor, which in many cases will be the search filter expressed in LDAP Search Filter Syntax. LDAP Search Filter Syntax is defined in the Internet Request For Comment RFC 2254 and is represented by Unicode strings. The search filters allow us to specify search criteria in an efficient and effective manner. Some examples of using the LDAP Search Filter Syntax are seen in Table 1.<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><b><span><font face=\"Calibri\">LDAP Search Filter Examples<\/font><\/span><\/b><b><span>&emsp;<\/span><\/b><b><span><font face=\"Calibri\">Table 1<\/p>\n<p><\/font><\/span><\/b><\/p>\n<table class=\"MsoNormalTable\" cellspacing=\"0\" cellpadding=\"0\" border=\"1\">\n<tbody>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">Search Filter<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">Description<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">ObjectClass=Computer<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All computer objects<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">ObjectClass=OrganizationalUnit<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All Organizational Unit objects<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">ObjectClass=User<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All user objects as well as all computer objects<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">ObjectCategory=User<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All User objects<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">(&amp;(ObjectCategory=User)(ObjectClass=Person))<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All User objects<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">L=Berlin<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All objects with the location of Berlin<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">Name=*Berlin*<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All objects with a name that contains Berlin<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">(&amp;(L=berlin)(ObjectCategory=OrganizationalUnit))<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All Organizational Units with the location of Berlin<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">(&amp;(ObjectCategory=OrganizationalUnit)(Name=*Berlin*))<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All Organizational Units with a name that contains Berlin<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">(&amp;(ObjectCategory=OrganizationalUnit)(Name=*Berlin*)(!L=Berlin))<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All Organizational Units with a name that contains Berlin, but do not have a location of Berlin<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">(&amp;(ObjectCategory=OrganizationalUnit)(Name=*Berlin*)(!L=*))<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All Organizational Units with a name that contains Berlin, but do not have any location specified<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td valign=\"top\" width=\"381\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">(&amp;(ObjectCategory=OrganizationalUnit)(|(L=Berlin)(L=Charlotte)))<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<td valign=\"top\" width=\"189\">\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">All Organizational Units with a location of either Berlin or Charlotte<\/p>\n<p><\/font><\/span><\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"MsoNormal\"><span><\/p>\n<p><font face=\"Calibri\">&nbsp;<\/font><\/p>\n<p><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">As seen in the examples in Table 1 there are two ways in which the search filter can be specified. The first method is a straight forward assignment filter. The attribute, the operator, and the value make up the filter. This is seen here. <\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">PS C:&gt; ([ADSISearcher]&#8221;Name=Charlotte&#8221;).FindAll() | Select Path<\/p>\n<p>Path<br>&#8212;-<br>LDAP:\/\/OU=Charlotte,DC=nwtraders,DC=com<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">If we were going to do the same thing without using the [ADSISearcher] the code we would need to use would first need to create the DirectoryServices.DirectorySearcher object and store it in a variable. We will call the variable $adsiSearcher. We then assign our filter to the filter property and call then we call the FindAll method. It would look like the following:<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">PS C:&gt; $adsiSearcher = New-Object DirectoryServices.DirectorySearcher<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">PS C:&gt; $adsiSearcher.Filter = &#8220;Name=Charlotte&#8221;<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">PS C:&gt; $adsiSearcher.FindAll() | Select path<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><\/p>\n<p><font face=\"Calibri\">&nbsp;<\/font><\/p>\n<p><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">Path<\/p>\n<p><\/font><\/span><\/p>\n<p class=\"MsoNormal\"><span><font face=\"Calibri\">&#8212;-<\/p>\n<p><\/font><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hey Scripting Guy! It seems that searching Active Directory from within Windows PowerShell is rather easy. But what I do not get is the syntax for the query. In the past I used something that looked more like SQL that the examples you show. What gives? &#8211; RH Hi PS, I was watching the Ninja [&hellip;]<\/p>\n","protected":false},"author":595,"featured_media":87096,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[7,3,8,45],"class_list":["post-54173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scripting","tag-active-directory","tag-scripting-guy","tag-searching-active-directory","tag-windows-powershell"],"acf":[],"blog_post_summary":"<p>Hey Scripting Guy! It seems that searching Active Directory from within Windows PowerShell is rather easy. But what I do not get is the syntax for the query. In the past I used something that looked more like SQL that the examples you show. What gives? &#8211; RH Hi PS, I was watching the Ninja [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/54173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/users\/595"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/comments?post=54173"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/posts\/54173\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media\/87096"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/media?parent=54173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/categories?post=54173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/scripting\/wp-json\/wp\/v2\/tags?post=54173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}