# Working in Out of Date Enviroment

**URL:** <https://forums.powershell.org/t/working-in-out-of-date-enviroment/11786>\
**Category:** PowerShell Help\
**Created:** [December 12, 2018, 1:51pm UTC](https://forums.powershell.org/t/working-in-out-of-date-enviroment/11786 "2018-12-12T13:51:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stevelovespowershell](https://avatars.discourse-cdn.com/v4/letter/s/b4bc9f/32.png) [@stevelovespowershell](https://forums.powershell.org/u/stevelovespowershell)\
**Post date:** [December 12, 2018, 1:51pm UTC](https://forums.powershell.org/t/working-in-out-of-date-enviroment/11786/1 "2018-12-12T13:51:22Z")

</div>

I work for a Managed Service Provider and we just took on a client with a very messed up environment. The issue I am trying to work through now is that they are running a Native Mode 2003 AD and the most up-to-date DC’s in the environment are 2008 \<Not R2\> What do I need to install, short of updating the AD or Rebuilding it from scratch, do I need to be able to run an AD PowerShell Module to do some Recon on this AD. I really want to Export the GPO’s with out right clicking on each one. I want to do a lot of things that I would do on a more up-to-date AD but I am not sure how to get an AD PowerShell Module to work in this environment. I do not believe that just putting up a Jump Box with RSAT Tools on it and PowerShell 5.1 will work with a 2003 AD Will it???

Thank

Steve

---

<div class="post-metadata">

**Author:** ![sam-boutros](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/sam-boutros/32/5_2.png) [@sam-boutros](https://forums.powershell.org/u/sam-boutros)\
**Post date:** [December 12, 2018, 2:49pm UTC](https://forums.powershell.org/t/working-in-out-of-date-enviroment/11786/2 "2018-12-12T14:49:39Z")

</div>

You can use PowerShell to leverage existing Dot Net functions to query AD and report on whatever you need.  
For example this one liner gets a list of domain controllers:

```
[system.directoryservices.activedirectory.Forest]::GetCurrentForest().domains.domaincontrollers | 
            select Forest,Name,CurrentTime,OSVersion,Roles,Domain,IPAddress,SiteName
```

or leverage LDAP to query AD via PowerShell. For example this lists enabled computer objects:

```
$adsi = [adsisearcher]"objectcategory=computer"
$adsi.PageSize = 1000000 
$adsi.filter = "(&(objectClass=Computer)(!userAccountControl:1.2.840.113556.1.4.803:=2))" # To return only the enabled computer objects
$adsi.FindAll() | foreach {
    $obj = $_.Properties
    [PSCustomObject][ordered]@{
        ComputerName = [string]$obj.name
        OSName = [string]$obj.operatingsystem
        DN = [string]$obj.distinguishedname
        AD_OU = [string](($obj.distinguishedname) -replace '^CN=[\w\d-_]+,\w\w=','' -replace ',OU=','/' -replace ',DC=.*')
        LastLogon = (([datetime]::FromFileTime([string]$obj.lastlogon)).ToShortDateString())
        ADCreated = ($obj.whencreated).ToShortDateString()
    }
}
```

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:34pm UTC](https://forums.powershell.org/t/working-in-out-of-date-enviroment/11786/3 "2024-05-16T20:34:07Z")

</div>


