# Copying AD groups from one user to another

**URL:** <https://forums.powershell.org/t/copying-ad-groups-from-one-user-to-another/16907>\
**Category:** PowerShell Help\
**Created:** [June 23, 2021, 1:45pm UTC](https://forums.powershell.org/t/copying-ad-groups-from-one-user-to-another/16907 "2021-06-23T13:45:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kippydoo](https://avatars.discourse-cdn.com/v4/letter/k/67e7ee/32.png) [@Kippydoo](https://forums.powershell.org/u/Kippydoo)\
**Post date:** [June 23, 2021, 1:45pm UTC](https://forums.powershell.org/t/copying-ad-groups-from-one-user-to-another/16907/1 "2021-06-23T13:45:09Z")

</div>

Hi,  
I hope someone can put me in the right direction here, Im playing with some code I found, that copies AD groups from one user to another.  
So far I have this

# Import AD commands

import-Module ActiveDirectory

# Login name of user to copy FROM

$copyfrom = Read-host "Enter username to copy from: "

# Login name of user to copy TO

$pasteto = Read-host "Enter username to copy to: "

# Get membership of FROM and add to

get-ADuser -Server “[dc01.Domain.co.uk](http://dc01.Domain.co.uk)” -identity $copyfrom -properties memberof | select-object memberof -expandproperty memberof | Add-AdGroupMember -Server “[dc01.Domain.co.uk](http://dc01.Domain.co.uk)” -Members $pasteto

This is working but the issue I have, is that some groups exisit in another domain ie Domain2 and I get an error, how do I get the code to check all our domains, instead of restricting my self to one domain in the -server parameter.  
thank you in advance

---

<div class="post-metadata">

**Author:** ![jlogan3o13](https://avatars.discourse-cdn.com/v4/letter/j/e68b1a/32.png) [@jlogan3o13](https://forums.powershell.org/u/jlogan3o13)\
**Post date:** [June 23, 2021, 8:56pm UTC](https://forums.powershell.org/t/copying-ad-groups-from-one-user-to-another/16907/2 "2021-06-23T20:56:42Z")

</div>

So the memberof property includes the full path of the group, including the domain. Something like this:

> CN=Domain Admins,OU=Groups,DC=my,DC=company,DC=com

So I believe the reason it is failing is because you are specifying the -Server parameter in your Add-ADGroupMember call, limiting yourself to a single domain. As to how to fix this, there are several ways to skin the proverbial cat. My first question is are you working with a single account that has access delegated across all domains, or do you have separate credentials for each?

---

<div class="post-metadata">

**Author:** ![Kippydoo](https://avatars.discourse-cdn.com/v4/letter/k/67e7ee/32.png) [@Kippydoo](https://forums.powershell.org/u/Kippydoo)\
**Post date:** [June 24, 2021, 7:31am UTC](https://forums.powershell.org/t/copying-ad-groups-from-one-user-to-another/16907/3 "2021-06-24T07:31:32Z")

</div>

Good morning, thank you for responding to my query.  
I have one account delegated across three domains.  
Cheers 🙂

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:23pm UTC](https://forums.powershell.org/t/copying-ad-groups-from-one-user-to-another/16907/4 "2024-05-16T20:23:59Z")

</div>


