Description
Summary of Article
Active Directory can allow thousands of users who is then actually discoverable through AO. AO has the capability to discover as many users as you have in AD. Environmentally tested up to 30K so far. There may be a configuration change that is needed in AD in order to properly pull all your users across. Please follow the Steps below in order to pull all your users
Before this step, by default you should be able to discover about 1000 users by default.
Steps
- Please Log into your Active Directory Domain Controller as the Domain Admin
- Open PowerShell as An Administrator (Right Click Powershell and Run As Administrator)
- The following are commands you run in NTDSUTIL.EXE
- ntdsutil
- LDAP Policies
- Connections
- Connect To Server <LDAP DOMAIN NAME> [eg. mydomain.com]
- Example Output:
- Binding to mydomain.com ...
Connected to mydomain.com using credentials of locally logged on user.
- q
- show values
- Example Output:
- Policy Current(New)
MaxPoolThreads 4
MaxDatagramRecv 4096
MaxReceiveBuffer 10485760
InitRecvTimeout 120
MaxConnections 5000
MaxConnIdleTime 900
MaxPageSize 1000
MaxBatchReturnMessages 0
MaxQueryDuration 120
MaxTempTableSize 10000
MaxResultSetSize 262144
MinResultSets 0
MaxResultSetsPerConn 0
MaxNotificationPerConn 5
MaxValRange 1500
ThreadMemoryLimit 0
SystemMemoryLimitPercent 0
- Set MaxPageSize to 12000
- NOTE: If you have more users, please round up to the nearest 100th [eg. 5485 users then your value should be 5500]
- Commit Changes
- show values
- Example Output:
- Policy Current(New)
MaxPoolThreads 4
MaxDatagramRecv 4096
MaxReceiveBuffer 10485760
InitRecvTimeout 120
MaxConnections 5000
MaxConnIdleTime 900
MaxPageSize 12000
MaxBatchReturnMessages 0
MaxQueryDuration 120
MaxTempTableSize 10000
MaxResultSetSize 262144
MinResultSets 0
MaxResultSetsPerConn 0
MaxNotificationPerConn 5
MaxValRange 1500
ThreadMemoryLimit 0
SystemMemoryLimitPercent 0
- q
- q
- You've just increase the discoverable window for your LDAP users!
Here's is an example of the results that you would receive with this configuration change:
Additional Information
N/A
Version Affected
ALL