Enumerate Group Membership
With powershell you can get an insight about the nested group in the AD and enumerate group membership.
Which users are members of the Domain Admins group?
1 |
Get-ADGroupMember "Domain Admins" | ft name |
In which groups is an user a member?
1 |
Get-ADPrincipalGroupMembership user | ft name |
Is a user a nested member of the Domains Admins group?
1 |
Get-ADUser -Filter 'memberof -recursivematch "cn=domain admins,cn=users,dc=test,dc=internal"' | ft name |