# Get AD users from specific AD Groups and parse results

**URL:** <https://forums.powershell.org/t/get-ad-users-from-specific-ad-groups-and-parse-results/3054>\
**Category:** PowerShell Help\
**Created:** [September 3, 2014, 8:21pm UTC](https://forums.powershell.org/t/get-ad-users-from-specific-ad-groups-and-parse-results/3054 "2014-09-03T20:21:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![massimo-cavo](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/massimo-cavo/32/851_2.png) [@massimo-cavo](https://forums.powershell.org/u/massimo-cavo)\
**Post date:** [September 3, 2014, 8:21pm UTC](https://forums.powershell.org/t/get-ad-users-from-specific-ad-groups-and-parse-results/3054/1 "2014-09-03T20:21:13Z")

</div>

Hi all,

my first post here 🙂

I have a question for the scripting gurus: i need to create a report containing UNIQUE users accounts, from specific AD Groups taking into account ALSO the nested groups.

Basically i have come up with this script:

```
Import-Module ActiveDirectory

$Report= "C:\Users.csv"
remove-item $Report -Force -ErrorAction SilentlyContinue
$Groups=Get-ADGroup -Filter 'Name -like "*AAAA*" -or Name -like "*BBBB*" -or Name -eq "GROUPX"'
$Users = @(); ForEach ($Group in $Groups) {
    $Users += (Get-ADGroupMember -Identity "$($Group.Name)" -Recursive)| Where-Object { $_.objectClass -eq 'user' } | 
    Get-Aduser -Property * | Select Name, @{Name="Username";Expression={$_.samaccountname}}, Enabled, @{Name="Last access";Expression={($_.lastlogondate).ToshortDateString()}}, @{n='MemberOf';e={$_.MemberOf -replace '^(cn.*?),.*','$1'}}
}
$Users | sort Name -Unique | export-csv $Report -NoTypeInformation -Encoding unicode
```

Now i’m getting records like this:  
“Name”,“Username”,“Enabled”,“Last access”,“Member of”  
“Name, Surname”,“username”,“True/False”,“YYYY-MM-DD”,“CN=Group1 CN=Group2, CN=Group3”

I’m trying to get the CN and not the DN for the memberof property. But this is my best on it.

Do you guys have any idea how to improve this?

Thanks in advance  
Max

---

<div class="post-metadata">

**Author:** ![\_timpringle](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/_timpringle/32/276_2.png) [@\_timpringle](https://forums.powershell.org/u/_timpringle)\
**Post date:** [September 3, 2014, 8:40pm UTC](https://forums.powershell.org/t/get-ad-users-from-specific-ad-groups-and-parse-results/3054/2 "2014-09-03T20:40:49Z")

</div>

Hey Max,

Bit of indentation would be nice. 😉

Seriously though, Jeff Wouter wrote something similar in one of his blogs, which you might be able to adapt to tidy things up a bit.

[http://jeffwouters.nl/index.php/2012/06/powershell-function-to-get-all-nested-group-members-in-active-directory](http://jeffwouters.nl/index.php/2012/06/powershell-function-to-get-all-nested-group-members-in-active-directory)

Depending on the size of the AD you have, you could maybe look at doing a Get-ADGroup -identity $\_.MemberOf (think thats the right syntax) and assign that to a variable, which you then place into the @{n=‘MemberOf’…}} bit, saving you have to do the -replace bit.

cheers,

Tim

---

<div class="post-metadata">

**Author:** ![massimo-cavo](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/massimo-cavo/32/851_2.png) [@massimo-cavo](https://forums.powershell.org/u/massimo-cavo)\
**Post date:** [September 4, 2014, 1:15am UTC](https://forums.powershell.org/t/get-ad-users-from-specific-ad-groups-and-parse-results/3054/3 "2014-09-04T01:15:23Z")

</div>

> [Tim Pringle wrote:](https://powershell.org/forums/topic/get-ad-users-from-specific-ad-groups-and-parse-results/#post-18520)
> Bit of indentation would be nice. ;-)

hehe yeah sorry 🙂

I get an error if i try to put in a variable the result of Get-ADGroup -Identity $\_.MemberOf

```
Get-ADGroup : Cannot validate argument on parameter 'Identity'. The argument is null. Supply a non-null argument and tr
y the command again.
```

Anyway i was able to improve my regex to get what i needed.

If someone else needs, this is the final code 🙂

```
Import-Module ActiveDirectory

$Report= "C:\Users.csv"
remove-item $Report -Force -ErrorAction SilentlyContinue

$Groups = Get-ADGroup -Filter 'Name -like "*AAAA*" -or Name -like "*BBBB*" -or Name -eq "GROUPX"'
$Users = @()

ForEach ($Group in $Groups) {

	$Users += (Get-ADGroupMember -Identity "$($Group.Name)" -Recursive) | 
	Where-Object { $_.objectClass -eq 'user' } | 
	Get-Aduser -Property * | Select Name, @{Name="Username";Expression={$_.samaccountname}}, 
	Enabled, @{Name="Last access";Expression={($_.lastlogondate).ToshortDateString()}}, @{n='MemberOf';e={$_.MemberOf -replace "(CN=)(.*?),.*",'$2' -join ','}}
	
	}
$Users | sort Name -Unique | export-csv $Report -NoTypeInformation -Encoding unicode
```

Cheers,

Max

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:47pm UTC](https://forums.powershell.org/t/get-ad-users-from-specific-ad-groups-and-parse-results/3054/4 "2024-05-16T20:47:34Z")

</div>


