How to Query Active Directory with PowerShell

Query Active Directory users, groups, and computers with PowerShell, select efficient filters and attributes, and troubleshoot common failures.

On this page

Active Directory is foundational in most enterprise identity stacks, and querying it efficiently is a core task for developers and identity practitioners building integrations, automating access reviews, or troubleshooting authentication issues. PowerShell provides a rich, code-driven interface to AD—modern, scriptable, and suited for both interactive exploration and automated pipelines. Understanding how to use PowerShell’s Active Directory cmdlets unlocks deep access to directory data without the complexity of older ADSI or direct LDAP code.

This guide demystifies querying Active Directory objects with PowerShell. It focuses on concrete cmdlet usage, filter syntax choices, property selection, exporting, and practical nuances—enabling developers, engineers, and operators to automate tasks and debug issues with confidence.

Link to Prerequisites: Setting Up PowerShell for Active DirectoryPrerequisites: Setting Up PowerShell for Active Directory

The ability to query Active Directory relies on the Active Directory PowerShell module. This module ships with Windows Server but can also be installed on Windows 10/11 workstations via “RSAT: Active Directory Domain Services and Lightweight Directory Tools” in Optional Features. Once installed, import the module in your session:

powershell
Import-Module ActiveDirectory

You do not need to run these commands from a domain controller. Any Windows machine that is domain-joined and has the necessary RSAT tools and permissions can query AD using PowerShell.

Link to Understanding Core AD PowerShell CmdletsUnderstanding Core AD PowerShell Cmdlets

The Active Directory module exposes AD as a set of code-friendly objects mapped to directory concepts. The most common querying cmdlets and their object parallels include:

  • Get-ADUser: Returns user objects from Active Directory.
  • Get-ADGroup: Returns group objects.
  • Get-ADGroupMember: Lists members of a specified group (users, computers, nested groups).

These cmdlets wrap traditional LDAP queries, abstracting connection details, and expose object properties as native PowerShell properties. For example:

powershell
Get-ADUser -Filter *

Returns all user objects in the domain (default property set). To target groups:

powershell
Get-ADGroup -Filter "Name -like '*Developers*'"

Enumerate group members:

powershell
Get-ADGroupMember -Identity "Developers"

Link to Query Syntax: PowerShell Filters vs LDAPFilterQuery Syntax: PowerShell Filters vs LDAPFilter

Most AD cmdlets accept both a PowerShell-style -Filter and a -LDAPFilter parameter. Understanding their differences is critical:

  • -Filter uses PowerShell’s own expression language. Example:

    -Filter "Enabled -eq $true"
    

    This is simple and intuitive for native PowerShell users.

  • -LDAPFilter accepts raw LDAP filter syntax (RFC 4515). Example:

    -LDAPFilter "(objectCategory=person)(objectClass=user)(enabled=TRUE)"
    

    LDAP filters are necessary when you have existing LDAP queries or need constructs unsupported by PowerShell filter syntax.

Key points:

  • You do not need to use LDAP syntax for most queries.
  • PowerShell filters are the default for new scripts and are easier for most developers.

Link to Practical Query Examples and Exporting ResultsPractical Query Examples and Exporting Results

Link to 1. List All Users in an OU and Export to CSV1. List All Users in an OU and Export to CSV

To retrieve all user accounts from a specific OU and export selected details:

powershell
Get-ADUser -SearchBase "OU=People,DC=example,DC=com" -Filter * -Properties DisplayName, Department |
    Select-Object DisplayName, Department |
    Export-Csv -Path People.csv -NoTypeInformation

This queries users in the “People" OU, selects DisplayName and Department, and exports the data to a CSV file.

Link to 2. Get All Enabled User Accounts2. Get All Enabled User Accounts

Return all enabled users in AD:

powershell
Get-ADUser -Filter "Enabled -eq $true"

To retrieve additional properties (for example, email):

powershell
Get-ADUser -Filter "Enabled -eq $true" -Properties EmailAddress |
    Select-Object SamAccountName, EmailAddress

Link to 3. Query a Group by Name and List Members3. Query a Group by Name and List Members

To find a group and enumerate all direct members:

powershell
Get-ADGroupMember -Identity "Engineering"

This will list all user/computer/group objects that are direct members of the “Engineering” group. For nested group expansion, use the -Recursive flag if supported.

Link to Scope, Performance, and Troubleshooting NuancesScope, Performance, and Troubleshooting Nuances

Link to Targeting Specific OUs or DomainsTargeting Specific OUs or Domains

Use the -SearchBase parameter to scope queries to a specific distinguished name (OU or container). For example:

powershell
-SearchBase "OU=Contractors,DC=example,DC=com"

For multi-domain environments or to force querying a specific Domain Controller, use the -Server parameter.

Link to Controlling Query Depth and PagingControlling Query Depth and Paging

  • -SearchScope can further refine traversal: Base, OneLevel, or Subtree (the default).
  • To handle large directories, use -ResultSetSize (to limit the results) and -ResultPageSize for paging. This is especially important in automation or reporting scripts.

Link to Property Selection and Its ImpactProperty Selection and Its Impact

By default, only a limited set of object properties is returned (such as Name, DistinguishedName, ObjectClass, ObjectGUID). To access additional attributes, specify them explicitly with -Properties:

powershell
-Properties *

Returns all attributes (use with caution for large queries).

powershell
-Properties Title, Department

Returns only specific attributes, increasing performance and reducing payload.

Link to Exporting ResultsExporting Results

PowerShell objects can be piped directly to Export-Csv for reporting, used in Select-Object for attribute shaping, or formatted with Format-Table for on-screen analysis.

Link to Common Misconceptions and Important NuancesCommon Misconceptions and Important Nuances

  • Misconception: "PowerShell AD queries only run on Domain Controllers."
    Reality: Any domain-joined workstation with RSAT and proper permissions can run these queries.
  • Misconception: "All AD properties are returned by default."
    Reality: Only a restricted set is returned; specify -Properties for more.
  • Misconception: "LDAP syntax is mandatory for filters."
    Reality: PowerShell filter syntax is primary and preferred; LDAPFilter is available for legacy cases or complex filters.

Attention to these distinctions prevents confusion and errors, especially when transitioning from legacy code or non-PowerShell LDAP tools.

Link to Further Reading and Official ResourcesFurther Reading and Official Resources

PowerShell’s Active Directory Module provides extensive, authoritative documentation for cmdlets, syntax, and advanced concepts. Refer to these for definitive parameter schemas, filtering details, and troubleshooting:

  • Active Directory PowerShell Module Overview
  • Get-ADUser (User Query Reference)
  • Get-ADGroup (Group Query Reference)
  • Get-ADGroupMember (Membership Query Reference)
  • about_ActiveDirectory (Concepts and Object Model)

These references are your primary source for technical deep dives, parameter updates, and best practices in modern AD query automation.

Link to SourcesSources