hello guys,
we are in the process of merging two domains so now we want to compare the AD group memberships of both
first i retrieved all groups with the same name
user1… <= grp6
user2… => grp2
user3… <= grp2
user4 <= grp3
Compare-Object:
Line |
2 | … bject).name (Get-ADGroupMember $grp.InputObject -Server "domain2.com …
| ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| Cannot bind argument to parameter ‘DifferenceObject’ because it is null.
user5 => grp2
user5 <= grp1
my question is …
1- why am i getting this error?
2- does get-adgroupmember retrieve users,computers and contacts?
3- is there a better way to do this ?
I personally don’t have experiences with a multi domain environment. And I don’t have access to one to test at the moment.
First I’d recommend to use the DN or sAMAccountName for the comparison. They are unique inside one domain. And I’d write my code a little more verbose … like this:
Now … why do you export the result and import it again. You can work with the variable $equalgroups.
Is it possible that you have groups in your second domain without any members or without “names”? And again - I’d use another property than the name.
I’d say yes? Did you try? It should be easy to figure out.
That depends pretty much on your expectations. Does it do what you need? Even if there are error messages - when you know where they come from and why it still might satisfy your requirements.
finally someone replied
1st thank you for replying
thank you for the recommendation as indeed … some users might not have names so i’ll use the samaccountname property
and it turned out get-adgroupmember doesn’t get external contacts…
so i’ll try something else
That’s correct. Usually those members are irrelevant as long as it is not a distribution group. But if you need all members including contacts you can use the “Members” property of the ADGroup.
Get-ADGroup -Identity 'GroupName' -Properties Members |
Select-Object -ExpandProperty 'Members'
so what i’ll do is compare the groups that exists on both domains using the get-adgroupmember
then i’ll merge the rest of the groups from domain2 to domain 1
this should solve it
thanks alot @Olaf