dsquery | new in WS2003 |
Search for a specific type of object within Active Directory.
dsquery command switches [{-s Server -d Domain }] [-u UserName ] [-p { Password *}] [-desc Description ] [-q] [-r] [-gc] [-limit N ]
Any dsquery command (see below)
Various switches that go with each command (see below)
Connects to a specified server or domain to run the command (if omitted, defaults to domain controller in logon domain).
Credentials for running the command. Specify UserName as domain\ user or user@domain . If -p * , prompts for password.
Description for the object.
Runs in quiet mode to suppress standard output of command.
Performs recursive search or follows referrals during search.
Performs the search using the global catalog.
Number of results to be returned (default is 1000).
Here is a list of supported dsquery commands together with a brief description of their syntax (only the most commonly used switches are described).
Searches for computers within Active Directory. The switches here are:
Where to begin the search (default is domainroot )
Output search results by distinguished name, relative distinguished name, or SAM account name of each object
Scope of search to be entire subtree of start node, immediate children of start node, or start node only
Searches for computers with specified name (wildcards supported)
Searches for computer accounts with specified SAM account name
Searches for computer accounts that have been stale (inactive) for a certain number of weeks
Searches for computers whose password has not been modified for a certain number of weeks
Searches for disabled computer accounts
Searches for contacts within Active Directory. See dsquery computer earlier in this list for an explanation of switches.
Searches for groups within Active Directory. See dsquery computer earlier in this list for an explanation of switches.
Searches for organizational units within Active Directory. See dsquery computer earlier in this list for an explanation of switches.
Searches for partitions matching the common name PartitionCN .
Searches for quota specifications within Active Directory. The switches here are:
Specifies the starting point for the search, either the root of the domain or the distinguished name of a specified container
Output search results by distinguished name, relative distinguished name, or SAM account name of each object
The security principal to which the quota specifications queried are assigned
Searches for quota specifications matching the filter condition, for example, " =100 " or " <=75 " percent
Searches for domain controllers within Active Directory. See dsquery computer earlier in this list for an explanation of some switches. Other switches include:
Searches for domain controllers in the forest
Searches for domain controllers in the specified domain
Searches for domain controllers in the specified site
Searches for domain controllers with a specific FSMO role assigned
Searches for domain controllers that are global catalog servers
Searches for sites within Active Directory. See dsquery computer earlier in this list for an explanation of switches.
Searches for user accounts within Active Directory. See dsquery computer earlier in this list for an explanation of these switches.
Searches for objects in Active Directory by using an LDAP query.
Search for all computer accounts in the forest:
dsquery computer forestroot -o dn "CN=ESRV210D,OU=Sales,DC=mtit,DC=local" "CN=ESRV230D,CN=Computers,DC=mtit,DC=local" "CN=DESK155,OU=Sales,DC=mtit,DC=local" "CN=DESK156,OU=Sales,DC=mtit,DC=local" "CN=DESK157,OU=Sales,DC=mtit,DC=local"
Restrict search to computers whose name begins with D and which reside in the Sales OU, displaying results as SAM account names :
dsquery computer OU=Sales,DC=mtit,DC=local -o samid -name d* "DESK155$" "DESK156$" "DESK157$"
Search for the PDC Emulator in the local domain:
dsquery server -hasfsmo pdc "CN=ESRV210D,CN=Servers,CN=Default-First- Site,CN=Sites,CN=Configuration,DC=mtit,DC=local"
Display all partitions in Active Directory:
dsquery partition "DC=TAPI3Directory,DC=mtit,DC=local" "DC=DomainDnsZones,DC=mtit,DC=local" "DC=ForestDnsZones,DC=mtit,DC=local" "CN=Configuration,DC=mtit,DC=local" "DC=mtit,DC=local" "CN=Schema,CN=Configuration,DC=mtit,DC=local"
Active Directory , dsadd , dsget , dsmod , dsmove , dsrm , Groups , Users