I need a script to get local and AD users having admin rights on a server >= Win 2008r2
The output should be something like:
type username
---- ----------------
local administrator
AD zakkojo
...
I can get local administrartors members with
powershell:
PS>Get-LocalGroupMember
ObjectClass Name PrincipalSource
----------- ---- ---------------
User DOMAIN\bak.windows ActiveDirectory
Group DOMAIN\Domain Admins ActiveDirectory
Group DOMAIN\ad_ops ActiveDirectory
User SERVENAME\Administrator Local
(win2008r2 and 2012 have no principalsource attribute)
or using batch with "net localgroup administrators"
But how can i get users in nested groups?