You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过LDAP查询获取Active Directory中15分钟内创建的Windows安全组?

Got it, let's figure out how to find Windows security groups created in Active Directory in the last 15 minutes using an LDAP query. I've worked through similar scenarios before, so here's a step-by-step breakdown that should get you what you need:

Step 1: Know the Critical AD Attributes

First, we need to target two key things: security groups specifically, and groups created in the last 15 minutes. Here's what you need to know about the attributes involved:

  • objectCategory=group: Ensures we only query group objects (not users, computers, etc.)
  • groupType: A bitmask where the 0x80000000 flag marks a group as a security group (distribution groups don't have this bit set)
  • whenCreated: Stores the UTC timestamp when the group was created, in ISO 8601 format (YYYYMMDDHHMMSS.0Z)

Step 2: Calculate the 15-Minute-Old Timestamp

LDAP requires a specific UTC timestamp format for date filters. You can calculate this manually, but it's easier to automate. For example, in PowerShell:

# Generate the timestamp for 15 minutes ago in LDAP-compatible UTC format
$15MinutesAgo = [DateTime]::UtcNow.AddMinutes(-15).ToString("yyyyMMddHHmmss.0Z")

This gives you a string like 20240520141500.0Z (adjusted to your current UTC time minus 15 minutes).

Step 3: Build the LDAP Filter

Combine the attribute checks into a single filter. We use a bitwise comparison for groupType to ensure we only get security groups:

(& (objectCategory=group) (groupType:1.2.840.113556.1.4.803:=0x80000000) (whenCreated>=<YOUR_TIMESTAMP>))

Replace <YOUR_TIMESTAMP> with the value you generated in Step 2. The 1.2.840.113556.1.4.803 OID tells LDAP to check if the 0x80000000 bit is set in the groupType attribute.

Step 4: Run the Query

If you're using PowerShell (with the RSAT Active Directory module installed), here's a complete script to execute the query and return the results with creation times:

# Calculate the timestamp
$15MinutesAgo = [DateTime]::UtcNow.AddMinutes(-15).ToString("yyyyMMddHHmmss.0Z")

# Build the filter
$ldapFilter = "(& (objectCategory=group) (groupType:1.2.840.113556.1.4.803:=0x80000000) (whenCreated>=$15MinutesAgo))"

# Retrieve the groups and display their name and creation time
Get-ADGroup -LDAPFilter $ldapFilter -Properties whenCreated | Select-Object Name, whenCreated

For other tools like ldp.exe or third-party LDAP browsers, just paste the full filter (with your timestamp) into the search filter field and run the query against your AD domain.

Key Notes

  • Always use UTC time for whenCreated to avoid timezone discrepancies (AD stores this attribute in UTC by default)
  • The bitwise filter for groupType is crucial—don't just use groupType=0x80000000, because security groups often have additional bits set (like global/domain-local group flags)
  • If you need to run this on a schedule, wrap the PowerShell script in a task to automatically calculate the timestamp each time

内容的提问来源于stack exchange,提问作者Shay Young

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:12:24