Why is the “Domain users” group missing from this Powershell AD Query?How to list all Active Directory...

Critique vs nitpicking

Does an Eldritch Knight's Weapon Bond protect him from losing his weapon to a Telekinesis spell?

How do I prevent a homebrew Grappling Hook feature from trivializing Tomb of Annihilation?

Is there a file that always exists and a 'normal' user can't lstat it?

Am I correct in stating that the study of topology is purely theoretical?

Plausible reason to leave the Solar System?

Reading Mishnayos without understanding

Is there a way to store 9th-level spells in a Glyph of Warding or similar method?

How to write cases in LaTeX?

Is there a verb that means to inject with poison?

Taking headphones when quitting job

Has any human ever had the choice to leave Earth permanently?

Can we "borrow" our answers to populate our own websites?

Coworker asking me to not bring cakes due to self control issue. What should I do?

Crack the bank account's password!

Categorical Unification of Jordan Holder Theorems

Why is that max-Q doesn't occur in transonic regime?

Count repetitions of an array

A fantasy book with seven white haired women on the cover

I have trouble understanding this fallacy: "If A, then B. Therefore if not-B, then not-A."

Broad Strokes - missing letter riddle

Why is it that Bernie Sanders is always called a "socialist"?

What makes papers publishable in top-tier journals?

What species should be used for storage of human minds?



Why is the “Domain users” group missing from this Powershell AD Query?


How to list all Active Directory Users and their group membershipPowershell query lastlogondate (lastlogontimestamp) returning mostly blank values (not matching the ADSIedit value for corresponding user attribute)PowerShell Script to Move ADUser to appropriate group based on its Department ID attributeActive Directory Users and Computers does not list Members of a Global GroupGet-ADUser -Properties MemberOf returns nothingBulk import to AD powershellComparing/Matching ACLsHow to get Adusers which are disabled of an defined company and shows the groups where this users are member of?Powershell script Import Users from CSV, add to group, with Success/Fail logspowershell - get from ad group user name and they group













1















I ran the following powershell script to compare a list of groups....



$dasMem = Get-ADUser -Server "<some-srv>" -Identity "<some-usr>" -Properties MemberOf | Select MemberOf
$blahx = $dasMem.MemberOf | % { $_ -replace "^CN=", "" } | % { $_ -replace ",.*$", "" } | sort
$blahx


When I got the list, I ended up with a missing group, Domain users which I believe is a standard default group, is there any reason why it's missing when I pull the script?



To be clear I was able to see the group in Active Directory Users and Computers but not from my script above.










share|improve this question



























    1















    I ran the following powershell script to compare a list of groups....



    $dasMem = Get-ADUser -Server "<some-srv>" -Identity "<some-usr>" -Properties MemberOf | Select MemberOf
    $blahx = $dasMem.MemberOf | % { $_ -replace "^CN=", "" } | % { $_ -replace ",.*$", "" } | sort
    $blahx


    When I got the list, I ended up with a missing group, Domain users which I believe is a standard default group, is there any reason why it's missing when I pull the script?



    To be clear I was able to see the group in Active Directory Users and Computers but not from my script above.










    share|improve this question

























      1












      1








      1








      I ran the following powershell script to compare a list of groups....



      $dasMem = Get-ADUser -Server "<some-srv>" -Identity "<some-usr>" -Properties MemberOf | Select MemberOf
      $blahx = $dasMem.MemberOf | % { $_ -replace "^CN=", "" } | % { $_ -replace ",.*$", "" } | sort
      $blahx


      When I got the list, I ended up with a missing group, Domain users which I believe is a standard default group, is there any reason why it's missing when I pull the script?



      To be clear I was able to see the group in Active Directory Users and Computers but not from my script above.










      share|improve this question














      I ran the following powershell script to compare a list of groups....



      $dasMem = Get-ADUser -Server "<some-srv>" -Identity "<some-usr>" -Properties MemberOf | Select MemberOf
      $blahx = $dasMem.MemberOf | % { $_ -replace "^CN=", "" } | % { $_ -replace ",.*$", "" } | sort
      $blahx


      When I got the list, I ended up with a missing group, Domain users which I believe is a standard default group, is there any reason why it's missing when I pull the script?



      To be clear I was able to see the group in Active Directory Users and Computers but not from my script above.







      active-directory powershell groups






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked 1 hour ago









      leeand00leeand00

      2,16564486




      2,16564486






















          1 Answer
          1






          active

          oldest

          votes


















          4














          As silly as it sounds, it's because Domain Users is not actually in the memberOf attribute. You can verify in ADUC by turning on View - Advanced Features, going to the Attributes tab on your object and opening the memberOf attribute (not the "Member Of" tab).



          The "Member Of" tab you see on an object's properties in ADUC is actually a conglomeration of the memberOf attribute and the primaryGroupID attribute. By default, users in AD get their Domain Users membership via this primaryGroupID attribute rather than an entry in memberOf. Though it's possible to change the primaryGroupID, most people don't.






          share|improve this answer























            Your Answer








            StackExchange.ready(function() {
            var channelOptions = {
            tags: "".split(" "),
            id: "2"
            };
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function() {
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled) {
            StackExchange.using("snippets", function() {
            createEditor();
            });
            }
            else {
            createEditor();
            }
            });

            function createEditor() {
            StackExchange.prepareEditor({
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader: {
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            },
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            });


            }
            });














            draft saved

            draft discarded


















            StackExchange.ready(
            function () {
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f955721%2fwhy-is-the-domain-users-group-missing-from-this-powershell-ad-query%23new-answer', 'question_page');
            }
            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            4














            As silly as it sounds, it's because Domain Users is not actually in the memberOf attribute. You can verify in ADUC by turning on View - Advanced Features, going to the Attributes tab on your object and opening the memberOf attribute (not the "Member Of" tab).



            The "Member Of" tab you see on an object's properties in ADUC is actually a conglomeration of the memberOf attribute and the primaryGroupID attribute. By default, users in AD get their Domain Users membership via this primaryGroupID attribute rather than an entry in memberOf. Though it's possible to change the primaryGroupID, most people don't.






            share|improve this answer




























              4














              As silly as it sounds, it's because Domain Users is not actually in the memberOf attribute. You can verify in ADUC by turning on View - Advanced Features, going to the Attributes tab on your object and opening the memberOf attribute (not the "Member Of" tab).



              The "Member Of" tab you see on an object's properties in ADUC is actually a conglomeration of the memberOf attribute and the primaryGroupID attribute. By default, users in AD get their Domain Users membership via this primaryGroupID attribute rather than an entry in memberOf. Though it's possible to change the primaryGroupID, most people don't.






              share|improve this answer


























                4












                4








                4







                As silly as it sounds, it's because Domain Users is not actually in the memberOf attribute. You can verify in ADUC by turning on View - Advanced Features, going to the Attributes tab on your object and opening the memberOf attribute (not the "Member Of" tab).



                The "Member Of" tab you see on an object's properties in ADUC is actually a conglomeration of the memberOf attribute and the primaryGroupID attribute. By default, users in AD get their Domain Users membership via this primaryGroupID attribute rather than an entry in memberOf. Though it's possible to change the primaryGroupID, most people don't.






                share|improve this answer













                As silly as it sounds, it's because Domain Users is not actually in the memberOf attribute. You can verify in ADUC by turning on View - Advanced Features, going to the Attributes tab on your object and opening the memberOf attribute (not the "Member Of" tab).



                The "Member Of" tab you see on an object's properties in ADUC is actually a conglomeration of the memberOf attribute and the primaryGroupID attribute. By default, users in AD get their Domain Users membership via this primaryGroupID attribute rather than an entry in memberOf. Though it's possible to change the primaryGroupID, most people don't.







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered 1 hour ago









                Ryan BolgerRyan Bolger

                13.9k23051




                13.9k23051






























                    draft saved

                    draft discarded




















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid



                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.


                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function () {
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f955721%2fwhy-is-the-domain-users-group-missing-from-this-powershell-ad-query%23new-answer', 'question_page');
                    }
                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    ORA-01691 (unable to extend lob segment) even though my tablespace has AUTOEXTEND onORA-01692: unable to...

                    Always On Availability groups resolving state after failover - Remote harden of transaction...

                    Circunscripción electoral de Guipúzcoa Referencias Menú de navegaciónLas claves del sistema electoral en...