0

I have a group MySoftwareUsers in the nam.con.internal.contoso.com domain.

The software I am installing doesn't have an option to specify a location to search, it uses the root domain con.internal.contoso.com for the search base and returns nothing.

A query for NAM\MySoftwareUsers also does not work. Is there a proper syntax for this search?

con.internal.contoso.com
nam.con.internal.contoso.com
sam.con.internal.contoso.com
afr.con.internal.contoso.com
eur.con.internal.contoso.com
mes.con.internal.contoso.com
asas.con.internal.contoso.com
aus.con.internal.contoso.com
New contributor
e-Fungus is a new contributor to this site. Take care in asking for clarification, commenting, and answering. Check out our Code of Conduct.
3
  • In LDAP jargon I think you're looking for a RFC 3296 referral : " if server A holds "DC=example,DC=net" and server B hold "DC=sub,DC=example,DC=net", server A may contain a referral object named "DC=sub,DC=example,DC=net" which contains a ref attribute with value of "ldap://Server-B/DC=sub,DC=example,DC=net". -|- But I have no idea how that works and/or is configured in AD.
    – HBruijn
    Dec 1 at 15:34
  • I don't think i have access to write a full query. I just have a box to enter the group to look for members and it keeps on saying no member found. from dsquery if i type look for the group it will not find it. if y specify the sub tree it will find it in dsquery. My assumption is that if i can find it in dsquery from the root domain. it will work in the app
    – e-Fungus
    Dec 1 at 15:50
  • from dsquery if i type look for the group it will not find it. if y specify the sub tree it will find it in dsquery. In AD, you should be able to query any object in the nam child domain from the root, however it requires a global catalog query, which you aren't doing. Given that, it doesn't matter if you query for an object on the local /LDAP partition for the con parent, the object isn't there. You may get a referral though, which is probably not used. You also need to ensure that the group scope is universal, and not global or local. This is easy to verify in AD Users and Computers.
    – Greg Askew
    Dec 1 at 20:32

1 Answer 1

0

You may need to provide the fully distinguished name CN=MySoftwareUsers,CN=Users,DC=nam,DC=con,DC=internal,DC=contoso,DC=com

You must log in to answer this question.

Not the answer you're looking for? Browse other questions tagged .