在AD用户导入器中,如何仅返回指定用户属性?
Hey Thomas, glad you asked—this is a common need when working with LDAP/Active Directory queries, and it’s absolutely possible to trim down the results to just the attributes you care about!
The Core Idea: Attribute Selection
Most LDAP tools (command-line, GUI, or programmatic) let you specify a list of attributes to return alongside your filter. This tells the LDAP server to only send back those specific fields instead of every attribute associated with the user objects.
Example: Command-Line Tools (e.g., ldapsearch)
If you’re using a tool like ldapsearch, you just add the attribute names you want at the end of your command. Here’s how your query would look:
ldapsearch -x -b "DC=org,DC=company,DC=com" "(&(objectCategory=user)(memberOf=CN=somegroup,OU=some,OU=thing,DC=org,DC=company,DC=com))" sAMAccountName authorizedPassword attribute1 attribute2 attribute3 attribute4 attribute5
- Replace
attribute1throughattribute5with your actual desired attribute names (e.g.,displayName,mail,department). - The
-xflag enables simple authentication, and-bsets the base DN for your search.
Example: Graphical LDAP Tools (e.g., AD Users and Computers, LDAP Browser)
For GUI tools:
- Set up your advanced filter exactly as you have now (
(&(objectCategory=user)(memberOf=CN=somegroup,...))). - Look for an option like "Select Attributes", "Columns to Display", or "Return Attributes" (the label varies by tool).
- Uncheck all attributes except
sAMAccountName,authorizedPassword, and your 5 additional fields. - Run the query—only your selected attributes will show up in the results.
A Quick Note on Permissions
Keep in mind that some attributes (like authorizedPassword/userPassword) are sensitive and may require elevated permissions to read. If you run into issues retrieving these, you might need to work with your Active Directory administrator to get the necessary access.
Hope this helps you get the streamlined results you need!
内容的提问来源于stack exchange,提问作者brillenheini

