I have security groups with users and computers. I want to list ONLY the users within the security groups. I am getting the list of users but also getting an error for each computer in the security group:
Get-ADUser : Cannot find an object with identity: 'CN="*
The script I am using is below:
$GroupName = Read-Host -Prompt 'Enter the Group Name'
Get-ADGroupMember -Identity $GroupName -Recursive |
Get-ADUser -Properties Name,Mail,Title,Department | Sort-Object Department,Title,Name | Format-Table Name,Mail,Title,Department -AutoSize
Instead of using
Get-ADGroupMember
useGet-ADUser
with a filter to find, recursively, all members of the group:See also Active Directory: LDAP Syntax Filters for details on LDAP_MATCHING_RULE_IN_CHAIN (
1.2.840.113556.1.4.1941
).