Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-1610: How to ldapsearch for group members greater 1500?

Auditing and Monitoring Service ,   Authentication Service ,   Mac & PC Management Service ,  

12 April,16 at 11:13 AM

Applies to:  All versions of Centrify DirectControl




Is there any way to query the membership of an AD group which has greater than 1500 members using /usr/share/centrifydc/bin/ldapsearch?




By default, Active Directory limits the value that can be retrieved from a single query to 1500.  To extract beyond this limit, it is necessary to specify a value range in the form of "member;range=low-high" such as "member,range=100-499".  An query sample for more than 1500 members will look similar to below ldapsearch command:

/usr/share/centrifydc/bin/ldapsearch -LLL -H ldap://domain.local -m -b 'CN=adgroup,OU=test.ou,OU=test,DC=domain,DC=local' '(objectclass=*)' 'member;range=0-50'

Without specifying the value range, the result will only display up to 1499.

More information regarding the range retrieval value can be found at Microsoft MSDN library

(Link provided as a courtesy)