Thanks Paul.
 
That works great :)
 
Yann

Paul Williams <[EMAIL PROTECTED]> a écrit :
Perform an AND query.
 
In ADFIND, this looks like this:
 
adfind -default -bit -f "&(objectCategory=person)(userAccountControl:AND:=65536)" cn
 
 
If you want to use ADUC, or something else, you'll need to use this:
 
(&(objectCategory=person)(useraccountcontrol:1.2.840.113556.1.4.803:=65536))
 
 
--Paul
 
----- Original Message -----
From: Yann
Sent: Monday, October 09, 2006 4:43 PM
Subject: [ActiveDir] finding users that password never expire.

Hello all,
 
I had to do dump in AD all users whose password never expires.
I used the saved queries with this custom ldap query :
useraccountcontrol=66048 which corresponds to NORMAL_ACCOUNT & DONT_EXPIRE_PASSWORD properties flag.
BUT i found that this search was not complete, because some users have other properties flag such as
UF_ACCOUNTDISABLE | UF_NORMAL_ACCOUNT | UF_DONT_EXPIRE_PASSWD or UF_ACCOUNTDISABLE | UF_NORMAL_ACCOUNT | UF_DONT_EXPIRE_PASSWD | UF_NOT_DELEGATED ... :(
 
So the question is:
How to search for user accounts that have at least the DONT_EXPIRE_PASSWORD property flag set to their useraccountcontrol ?
Is there a way to do it with a custom ldap query ?
 
Thanks,
 
Yann

Découvrez un nouveau moyen de poser toutes vos questions quel que soit le sujet ! Yahoo! Questions/Réponses pour partager vos connaissances, vos opinions et vos expériences. Cliquez ici.


Yahoo! Mail réinvente le mail ! Découvrez le nouveau Yahoo! Mail et son interface révolutionnaire.

Reply via email to