Get-QADUser Properties

 

fromEntry
:
TRUE
givenName
:
Partha
codePage
:
0
tokenGroupsGlobalAndUniversal
:
010500000000000515000000905322E864F8431A87ADAEDA01020000
objectCategory
:
'CN=Person,CN=Schema,CN=Configuration,DC=contoso,DC=com'
canonicalName
:
contoso.com/Partha Das
dSCorePropagationData
:
01/01/1601 00:00:00
uSNChanged
:
127060
instanceType
:
4
nTSecurityDescriptor
:
 
logonCount
:
0
structuralObjectClass
:
top,person,organizationalPerson,user
name
:
Partha Das
badPasswordTime
:
0
sDRightsEffective
:
15
pwdLastSet
:
0
allowedAttributes
:
shadowFlag,shadowExpire,shadowInactive,shadowWarning,shadowMax,shadowMin,shadowLastChange,loginShell,unixHomeDirectory,gecos,gidNumber,uidNumber,msDFSR-ComputerReferenceBL,msDFSR-MemberReferenceBL,msSFU30PosixMemberOf,msSFU30NisDomain,msSFU30N
 
 
ame,labeledURI,subSchemaSubEntry,modifyTimeStamp,createTimeStamp,structuralObjectClass,userPKCS12,preferredLanguage,thumbnailLogo,thumbnailPhoto,middleName,departmentNumber,carLicense,jpegPhoto,audio,pager,mobile,secretary,homePhone,manager,ph
 
 
oto,roomNumber,mail,textEncodedORAddress,uid,userSMIMECertificate,msDS-cloudExtensionAttribute20,msDS-cloudExtensionAttribute19,msDS-cloudExtensionAttribute18,msDS-cloudExtensionAttribute17,msDS-cloudExtensionAttribute16,msDS-cloudExtensionAtt
 
 
ribute15,msDS-cloudExtensionAttribute14,msDS-cloudExtensionAttribute13,msDS-cloudExtensionAttribute12,msDS-cloudExtensionAttribute11,msDS-cloudExtensionAttribute10,msDS-cloudExtensionAttribute9,msDS-cloudExtensionAttribute8,msDS-cloudExtension
 
 
Attribute7,msDS-cloudExtensionAttribute6,msDS-cloudExtensionAttribute5,msDS-cloudExtensionAttribute4,msDS-cloudExtensionAttribute3,msDS-cloudExtensionAttribute2,msDS-cloudExtensionAttribute1,msDS-TDOEgressBL,msDS-TDOIngressBL,msDS-ValueTypeRef
 
 
erenceBL,msDS-GeoCoordinatesLongitude,msDS-GeoCoordinatesLatitude,msDS-GeoCoordinatesAltitude,msDS-AllowedToActOnBehalfOfOtherIdentity,msDS-IsPrimaryComputerFor,msDS-PrimaryComputer,msDS-MembersOfResourcePropertyListBL,msDS-ClaimSharesPossible
 
 
ValuesWithBL,msTSSecondaryDesktops,msTSPrimaryDesktop,msDS-EnabledFeatureBL,msDS-LastKnownRDN,msDS-LocalEffectiveRecycleTime,msDS-LocalEffectiveDeletionTime,isRecycled,msDS-HostServiceAccountBL,msDS-OIDToGroupLinkBl,msPKI-CredentialRoamingToke
 
 
ns,msDS-NcType,msDS-ResultantPSO,msDS-PSOApplied,msTSLSProperty02,msTSLSProperty01,msTSManagingLS4,msTSLicenseVersion4,msTSExpireDate4,msTSManagingLS3,msTSLicenseVersion3,msTSExpireDate3,msTSManagingLS2,msTSLicenseVersion2,msTSExpireDate2,msDS
 
 
#NAME?
 
 
s,msTSBrokenConnectionAction,msTSReconnectionAction,msTSMaxIdleTime,msTSMaxConnectionTime,msTSMaxDisconnectionTime,msTSRemoteControl,msTSAllowLogon,msTSHomeDrive,msTSHomeDirectory,msTSProfilePath,msDS-RevealedListBL,msDS-FailedInteractiveLogon
 
 
CountAtLastSuccessfulLogon,msDS-FailedInteractiveLogonCount,msDS-LastFailedInteractiveLogonTime,msDS-LastSuccessfulInteractiveLogonTime,msDS-NC-RO-Replica-Locations-BL,msDS-SupportedEncryptionTypes,msDS-AuthenticatedAtDC,msDS-AuthenticatedToAc
 
 
countlist,msDS-PhoneticDisplayName,msDS-PhoneticCompanyName,msDS-PhoneticDepartment,msDS-PhoneticLastName,msDS-PhoneticFirstName,msDS-IsPartialReplicaFor,msDS-IsDomainFor,msDS-IsFullReplicaFor,msDS-KrbTgtLinkBl,msDS-RevealedDSAs,msDS-Secondary
 
 
KrbTgtNumber,msRADIUS-SavedFramedIpv6Route,msRADIUS-FramedIpv6Route,msRADIUS-SavedFramedIpv6Prefix,msRADIUS-FramedIpv6Prefix,msRADIUS-SavedFramedInterfaceId,msRADIUS-FramedInterfaceId,unixUserPassword,msPKIAccountCredentials,msPKIDPAPIMasterKe
 
 
ys,msPKIRoamingTimeStamp,msDS-SourceObjectDN,msDS-PrincipalName,msDRM-IdentityCertificate,msDS-ObjectReferenceBL,msDs-masteredBy,msDS-TasksForAzRoleBL,msDS-OperationsForAzRoleBL,msDS-TasksForAzTaskBL,msDS-OperationsForAzTaskBL,msDS-MembersForA
 
 
zRoleBL,msDS-NonMembersBL,msDS-AllowedToDelegateTo,msIIS-FTPDir,msIIS-FTPRoot,msDS-KeyVersionNumber,msDS-ReplValueMetaData,msDS-ReplAttributeMetaData,msDS-NCReplOutboundNeighbors,msDS-NCReplInboundNeighbors,msDS-NCReplCursors,lastLogonTimestam
 
 
p,msDS-Approx-Immed-Subordinates,msDS-User-Account-Control-Computed,msDS-Site-Affinity,msDS-Cached-Membership-Time-Stamp,msDS-Cached-Membership,msCOM-UserPartitionSetLink,msCOM-UserLink,msCOM-PartitionSetLink,tokenGroupsGlobalAndUniversal,mS-D
 
 
S-CreatorSID,masteredBy,mS-DS-ConsistencyChildCount,mS-DS-ConsistencyGuid,otherWellKnownObjects,dSCorePropagationData,accountNameHistory,sDRightsEffective,tokenGroupsNoGCAcceptable,tokenGroups,proxiedObjectName,msRASSavedFramedRoute,msRASSaved
 
 
FramedIPAddress,msRASSavedCallbackNumber,msRADIUSServiceType,msRADIUSFramedRoute,msRADIUSFramedIPAddress,msRADIUSCallbackNumber,msNPSavedCallingStationID,msNPCallingStationID,msNPAllowDialin,mSMQSignCertificatesMig,mSMQDigestsMig,mSMQDigests,m
 
 
SMQSignCertificates,canonicalName,possibleInferiors,allowedAttributesEffective,allowedAttributes,allowedChildClassesEffective,allowedChildClasses,fromEntry,uSNSource,terminalServer,fRSMemberReferenceBL,frsComputerReferenceBL,isCriticalSystemOb
 
 
ject,altSecurityIdentities,netbootSCPBL,bridgeheadServerListBL,lastKnownParent,aCSPolicyName,servicePrincipalName,userSharedFolderOther,userSharedFolder,url,otherIpPhone,ipPhone,partialAttributeDeletionList,lockoutTime,userPrincipalName,legacy
 
 
ExchangeDN,managedObjects,assistant,otherMailbox,mhsORAddress,primaryInternationalISDNNumber,primaryTelexNumber,otherMobile,otherFacsimileTelephoneNumber,userCert,showInAddressBook,partialAttributeSet,isPrivilegeHolder,wellKnownObjects,sIDHist
 
 
ory,queryPolicyBL,dynamicLDAPServer,nonSecurityMemberBL,serverReferenceBL,siteObjectBL,systemFlags,fSMORoleOwner,desktopProfile,groupPriority,groupsToIgnore,sAMAccountType,wbemPath,division,defaultClassStore,controlAccessRights,logonCount,grou
 
 
pMembershipSAM,lmPwdHistory,accountExpires,comment,rid,adminCount,revision,operatorCount,profilePath,userParameters,supplementalCredentials,securityIdentifier,primaryGroupID,preferredOU,pwdLastSet,ntPwdHistory,otherLoginWorkstations,unicodePwd
 
 
,userWorkstations,maxStorage,logonWorkstation,logonHours,scriptPath,localeID,dBCSPwd,lastLogon,lastLogoff,badPasswordTime,homeDrive,homeDirectory,flags,employeeID,countryCode,codePage,badPwdCount,userAccountControl,replUpToDateVector,replPrope
 
 
rtyMetaData,objectGUID,name,homePostalAddress,personalTitle,employeeType,employeeNumber,msExchHouseIdentifier,msExchLabeledURI,USNIntersite,wWWHomePage,networkAddress,msExchAssistantName,directReports,displayNamePrintable,garbageCollPeriod,oth
 
 
erHomePhone,uSNDSALastObjRemoved,streetAddress,extensionName,adminDescription,proxyAddresses,adminDisplayName,showInAdvancedViewOnly,company,department,co,uSNLastObjRem,uSNChanged,otherPager,ownerBL,memberOf,repsFrom,repsTo,info,objectVersion,
 
 
dSASignature,isDeleted,uSNCreated,otherTelephone,displayName,subRefs,whenChanged,whenCreated,attributeCertificateAttribute,houseIdentifier,distinguishedName,x500uniqueIdentifier,generationQualifier,initials,givenName,userCertificate,userPasswo
 
 
rd,seeAlso,preferredDeliveryMethod,destinationIndicator,registeredAddress,internationalISDNNumber,x121Address,facsimileTelephoneNumber,teletexTerminalIdentifier,telexNumber,telephoneNumber,physicalDeliveryOfficeName,postOfficeBox,postalCode,po
 
 
stalAddress,businessCategory,description,title,ou,o,street,st,l,c,serialNumber,sn,objectCategory,sAMAccountName,objectSid,nTSecurityDescriptor,instanceType,cn,objectClass
allowedChildClasses
:
ms-net-ieee-80211-GroupPolicy,nTFRSSubscriptions,classStore,ms-net-ieee-8023-GroupPolicy
objectClass
:
top,person,organizationalPerson,user
badPwdCount
:
0
msDS-PrincipalName
:
CONTOSO\pdas
replPropertyMetaData
:
01000000000000001A0000000000000000000000010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF001000000000003000000010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF001000000000004000000010000008AD
 
 
BD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF00100000000002A000000010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF001000000000001000200010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF001
 
 
00000000004EF001000000000002000200010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF00100000000000D000200010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF001000000000019010200010000008ADBD5070
 
 
30000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF001000000000001000900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF001000000000008000900040000008ADBD507030000009A886F6CF365774A8D404F5C086428CA54F001000000
 
 
000054F001000000000010000900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4FF00100000000004FF001000000000019000900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4FF00100000000004FF001000000000037000900020000008ADBD5070300000
 
 
09A886F6CF365774A8D404F5C086428CA50F001000000000050F001000000000040000900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4FF00100000000004FF00100000000005A000900020000008ADBD507030000009A886F6CF365774A8D404F5C086428CA50F001000000000050
 
 
F00100000000005E000900020000008ADBD507030000009A886F6CF365774A8D404F5C086428CA50F001000000000050F001000000000060000900030000008ADBD507030000009A886F6CF365774A8D404F5C086428CA52F001000000000052F001000000000062000900010000008ADBD507030000009A886
 
 
F6CF365774A8D404F5C086428CA4FF00100000000004FF00100000000007D000900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA51F001000000000051F001000000000092000900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF00100
 
 
000000009F000900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4FF00100000000004FF0010000000000A0000900020000008ADBD507030000009A886F6CF365774A8D404F5C086428CA50F001000000000050F0010000000000DD000900010000008ADBD507030000009A886F6CF36
 
 
5774A8D404F5C086428CA4EF00100000000004EF00100000000002E010900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF001000000000090020900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF00100000000
 
 
000E030900010000008ADBD507030000009A886F6CF365774A8D404F5C086428CA4EF00100000000004EF0010000000000
uSNCreated
:
127054
sn
:
Das
msDS-UserPasswordExpiryTimeComputed
:
0
tokenGroupsNoGCAcceptable
:
01020000000000052000000021020000,010500000000000515000000905322E864F8431A87ADAEDA01020000
msDS-User-Account-Control-Computed
:
8388608
objectGUID
:
FD2B2965E658BB46B9C710D1B0CAA712
whenCreated
:
06/22/2013 06:56:10
subSchemaSubEntry
:
'CN=Aggregate,CN=Schema,CN=Configuration,DC=contoso,DC=com'
userAccountControl
:
512
cn
:
Partha Das
countryCode
:
0
primaryGroupID
:
513
whenChanged
:
06/22/2013 06:56:10
allowedAttributesEffective
:
msTSSecondaryDesktops,msTSPrimaryDesktop,msDS-PrimaryComputer,msDS-LastKnownRDN,msDS-AllowedToActOnBehalfOfOtherIdentity,msDS-GeoCoordinatesAltitude,isRecycled,msDS-GeoCoordinatesLatitude,msDS-GeoCoordinatesLongitude,msPKI-CredentialRoamingTok
 
 
ens,msDS-NcType,msDS-cloudExtensionAttribute1,msDS-cloudExtensionAttribute2,msTSLSProperty02,msTSLSProperty01,msTSManagingLS4,msTSLicenseVersion4,msTSExpireDate4,msTSManagingLS3,msTSLicenseVersion3,msTSExpireDate3,msTSManagingLS2,msTSLicenseVe
 
 
rsion2,msTSExpireDate2,msDS-HABSeniorityIndex,msDS-cloudExtensionAttribute3,msTSManagingLS,msTSLicenseVersion,msTSExpireDate,msTSProperty02,msTSProperty01,msTSInitialProgram,msTSWorkDirectory,msTSDefaultToMainPrinter,msTSConnectPrinterDrives,m
 
 
sTSConnectClientDrives,msTSBrokenConnectionAction,msTSReconnectionAction,msTSMaxIdleTime,msTSMaxConnectionTime,msTSMaxDisconnectionTime,msTSRemoteControl,msTSAllowLogon,msTSHomeDrive,msTSHomeDirectory,msTSProfilePath,msDS-cloudExtensionAttribu
 
 
te4,msDS-FailedInteractiveLogonCountAtLastSuccessfulLogon,msDS-FailedInteractiveLogonCount,msDS-LastFailedInteractiveLogonTime,msDS-LastSuccessfulInteractiveLogonTime,msDS-cloudExtensionAttribute5,msDS-SupportedEncryptionTypes,msDS-Authenticat
 
 
edAtDC,msDS-cloudExtensionAttribute6,msDS-PhoneticDisplayName,msDS-PhoneticCompanyName,msDS-PhoneticDepartment,msDS-PhoneticLastName,msDS-PhoneticFirstName,msDS-cloudExtensionAttribute7,msDS-cloudExtensionAttribute8,msDS-cloudExtensionAttribut
 
 
e9,msDS-cloudExtensionAttribute10,msDS-cloudExtensionAttribute11,msDS-SecondaryKrbTgtNumber,msRADIUS-SavedFramedIpv6Route,msRADIUS-FramedIpv6Route,msRADIUS-SavedFramedIpv6Prefix,msRADIUS-FramedIpv6Prefix,msRADIUS-SavedFramedInterfaceId,msRADIU
 
 
S-FramedInterfaceId,unixUserPassword,msPKIAccountCredentials,msPKIDPAPIMasterKeys,msPKIRoamingTimeStamp,msDS-SourceObjectDN,msDS-cloudExtensionAttribute12,msDRM-IdentityCertificate,msDS-cloudExtensionAttribute13,msDS-cloudExtensionAttribute14,
 
 
msDS-cloudExtensionAttribute15,msDS-cloudExtensionAttribute16,msDS-cloudExtensionAttribute17,msDS-cloudExtensionAttribute18,msDS-cloudExtensionAttribute19,msDS-cloudExtensionAttribute20,msDS-AllowedToDelegateTo,msIIS-FTPDir,msIIS-FTPRoot,userS
 
 
MIMECertificate,uid,textEncodedORAddress,mail,roomNumber,photo,lastLogonTimestamp,manager,homePhone,msDS-Site-Affinity,msDS-Cached-Membership-Time-Stamp,msDS-Cached-Membership,msCOM-UserPartitionSetLink,secretary,mobile,pager,mS-DS-CreatorSID,
 
 
audio,mS-DS-ConsistencyChildCount,mS-DS-ConsistencyGuid,otherWellKnownObjects,dSCorePropagationData,accountNameHistory,jpegPhoto,carLicense,departmentNumber,proxiedObjectName,msRASSavedFramedRoute,msRASSavedFramedIPAddress,msRASSavedCallbackNu
 
 
mber,msRADIUSServiceType,msRADIUSFramedRoute,msRADIUSFramedIPAddress,msRADIUSCallbackNumber,msNPSavedCallingStationID,msNPCallingStationID,msNPAllowDialin,mSMQSignCertificatesMig,mSMQDigestsMig,mSMQDigests,mSMQSignCertificates,middleName,thumb
 
 
nailPhoto,thumbnailLogo,preferredLanguage,userPKCS12,labeledURI,msSFU30Name,uSNSource,terminalServer,msSFU30NisDomain,uidNumber,isCriticalSystemObject,altSecurityIdentities,gidNumber,gecos,lastKnownParent,aCSPolicyName,servicePrincipalName,use
 
 
rSharedFolderOther,userSharedFolder,url,otherIpPhone,ipPhone,partialAttributeDeletionList,lockoutTime,userPrincipalName,legacyExchangeDN,unixHomeDirectory,assistant,otherMailbox,mhsORAddress,primaryInternationalISDNNumber,primaryTelexNumber,ot
 
 
herMobile,otherFacsimileTelephoneNumber,userCert,showInAddressBook,partialAttributeSet,loginShell,wellKnownObjects,sIDHistory,shadowLastChange,dynamicLDAPServer,shadowMin,shadowMax,shadowWarning,systemFlags,fSMORoleOwner,desktopProfile,groupPr
 
 
iority,groupsToIgnore,sAMAccountType,wbemPath,division,defaultClassStore,controlAccessRights,logonCount,groupMembershipSAM,lmPwdHistory,accountExpires,comment,rid,adminCount,revision,operatorCount,profilePath,userParameters,supplementalCredent
 
 
ials,securityIdentifier,primaryGroupID,preferredOU,pwdLastSet,ntPwdHistory,otherLoginWorkstations,unicodePwd,userWorkstations,maxStorage,logonWorkstation,logonHours,scriptPath,localeID,dBCSPwd,lastLogon,lastLogoff,badPasswordTime,homeDrive,hom
 
 
eDirectory,flags,employeeID,countryCode,codePage,badPwdCount,userAccountControl,replUpToDateVector,replPropertyMetaData,objectGUID,name,homePostalAddress,personalTitle,employeeType,employeeNumber,msExchHouseIdentifier,msExchLabeledURI,USNInter
 
 
site,wWWHomePage,networkAddress,msExchAssistantName,shadowInactive,displayNamePrintable,garbageCollPeriod,otherHomePhone,uSNDSALastObjRemoved,streetAddress,extensionName,adminDescription,proxyAddresses,adminDisplayName,showInAdvancedViewOnly,c
 
 
ompany,department,co,uSNLastObjRem,uSNChanged,otherPager,shadowExpire,shadowFlag,repsFrom,repsTo,info,objectVersion,dSASignature,isDeleted,uSNCreated,otherTelephone,displayName,subRefs,whenChanged,whenCreated,attributeCertificateAttribute,hous
 
 
eIdentifier,distinguishedName,x500uniqueIdentifier,generationQualifier,initials,givenName,userCertificate,userPassword,seeAlso,preferredDeliveryMethod,destinationIndicator,registeredAddress,internationalISDNNumber,x121Address,facsimileTelephon
 
 
eNumber,teletexTerminalIdentifier,telexNumber,telephoneNumber,physicalDeliveryOfficeName,postOfficeBox,postalCode,postalAddress,businessCategory,description,title,ou,o,street,st,l,c,serialNumber,sn,objectCategory,sAMAccountName,objectSid,nTSec
 
 
urityDescriptor,instanceType,cn,objectClass
lastLogon
:
0
distinguishedName
:
'CN=Partha Das,DC=contoso,DC=com'
msDS-KeyVersionNumber
:
2
msDS-RevealedListBL
:
 
createTimeStamp
:
06/22/2013 06:56:10
tokenGroups
:
01020000000000052000000021020000,010500000000000515000000905322E864F8431A87ADAEDA01020000
allowedChildClassesEffective
:
ms-net-ieee-80211-GroupPolicy,nTFRSSubscriptions,classStore,ms-net-ieee-8023-GroupPolicy
sAMAccountName
:
pdas
objectSid
:
010500000000000515000000905322E864F8431A87ADAEDA60040000
lastLogoff
:
0
modifyTimeStamp
:
06/22/2013 06:56:10
displayName
:
Partha Das
sAMAccountType
:
805306368
msDS-ReplAttributeMetaData
:
'<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>objectCategory</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>userPrincipalName</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>sAMAccountType</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>sAMAccountName</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>lmPwdHistory</pszAttributeName>
 
 
<dwVersion>2</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127056</usnOriginatingChange>
 
 
<usnLocalChange>127056</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>accountExpires</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127055</usnOriginatingChange>
 
 
<usnLocalChange>127055</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>objectSid</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>supplementalCredentials</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127057</usnOriginatingChange>
 
 
<usnLocalChange>127057</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>primaryGroupID</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127055</usnOriginatingChange>
 
 
<usnLocalChange>127055</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>pwdLastSet</pszAttributeName>
 
 
<dwVersion>3</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127058</usnOriginatingChange>
 
 
<usnLocalChange>127058</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>ntPwdHistory</pszAttributeName>
 
 
<dwVersion>2</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127056</usnOriginatingChange>
 
 
<usnLocalChange>127056</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>unicodePwd</pszAttributeName>
 
 
<dwVersion>2</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127056</usnOriginatingChange>
 
 
<usnLocalChange>127056</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>logonHours</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127055</usnOriginatingChange>
 
 
<usnLocalChange>127055</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>dBCSPwd</pszAttributeName>
 
 
<dwVersion>2</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127056</usnOriginatingChange>
 
 
<usnLocalChange>127056</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>countryCode</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127055</usnOriginatingChange>
 
 
<usnLocalChange>127055</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>codePage</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127055</usnOriginatingChange>
 
 
<usnLocalChange>127055</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>userAccountControl</pszAttributeName>
 
 
<dwVersion>4</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127060</usnOriginatingChange>
 
 
<usnLocalChange>127060</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>name</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>nTSecurityDescriptor</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>displayName</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>whenCreated</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>instanceType</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>givenName</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>sn</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>cn</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
','<DS_REPL_ATTR_META_DATA>
 
 
<pszAttributeName>objectClass</pszAttributeName>
 
 
<dwVersion>1</dwVersion>
 
 
<ftimeLastOriginatingChange>2013-06-22T06:56:10Z</ftimeLastOriginatingChange>
 
 
<uuidLastOriginatingDsaInvocationID>6c6f889a-65f3-4a77-8d40-4f5c086428ca</uuidLastOriginatingDsaInvocationID>
 
 
<usnOriginatingChange>127054</usnOriginatingChange>
 
 
<usnLocalChange>127054</usnLocalChange>
 
 
<pszLastOriginatingDsaDN>CN=NTDS Settings,CN=WIN-5Q4IM0060DO,CN=Servers,CN=IND-BLR,CN=Sites,CN=Configuration,DC=contoso,DC=com</pszLastOriginatingDsaDN>
 
 
</DS_REPL_ATTR_META_DATA>
 
 
'
msDS-Approx-Immed-Subordinates
:
0
accountExpires
:
9.22337E+18
userPrincipalName
:
pdas@contoso.com
accountNameHistory
:
 
aCSPolicyName
:
 
adminCount
:
 
adminDescription
:
 
adminDisplayName
:
 
altSecurityIdentities
:
 
assistant
:
 
attributeCertificateAttribute
:
 
audio
:
 
bridgeheadServerListBL
:
 
businessCategory
:
 
c
:
 
carLicense
:
 
co
:
 
comment
:
 
company
:
 
controlAccessRights
:
 
dBCSPwd
:
 
defaultClassStore
:
 
department
:
 
departmentNumber
:
 
description
:
 
desktopProfile
:
 
destinationIndicator
:
 
directReports
:
 
displayNamePrintable
:
 
division
:
 
dSASignature
:
 
dynamicLDAPServer
:
 
employeeID
:
 
employeeNumber
:
 
employeeType
:
 
extensionName
:
 
facsimileTelephoneNumber
:
 
flags
:
 
frsComputerReferenceBL
:
 
fRSMemberReferenceBL
:
 
fSMORoleOwner
:
 
garbageCollPeriod
:
 
gecos
:
 
generationQualifier
:
 
gidNumber
:
 
groupMembershipSAM
:
 
groupPriority
:
 
groupsToIgnore
:
 
homeDirectory
:
 
homeDrive
:
 
homePhone
:
 
homePostalAddress
:
 
houseIdentifier
:
 
info
:
 
initials
:
 
internationalISDNNumber
:
 
ipPhone
:
 
isCriticalSystemObject
:
 
isDeleted
:
 
isPrivilegeHolder
:
 
isRecycled
:
 
jpegPhoto
:
 
l
:
 
labeledURI
:
 
lastKnownParent
:
 
lastLogonTimestamp
:
 
legacyExchangeDN
:
 
lmPwdHistory
:
 
localeID
:
 
lockoutTime
:
 
loginShell
:
 
logonHours
:
 
logonWorkstation
:
 
mail
:
 
managedObjects
:
 
manager
:
 
masteredBy
:
 
maxStorage
:
 
memberOf
:
 
mhsORAddress
:
 
middleName
:
 
mobile
:
 
mS-DS-ConsistencyChildCount
:
 
mS-DS-ConsistencyGuid
:
 
mS-DS-CreatorSID
:
 
msCOM-PartitionSetLink
:
 
msCOM-UserLink
:
 
msCOM-UserPartitionSetLink
:
 
msDFSR-ComputerReferenceBL
:
 
msDFSR-MemberReferenceBL
:
 
msDRM-IdentityCertificate
:
 
msDS-AllowedToActOnBehalfOfOtherIdentity
:
 
msDS-AllowedToDelegateTo
:
 
msDS-AuthenticatedAtDC
:
 
msDS-AuthenticatedToAccountlist
:
 
msDS-Cached-Membership
:
 
msDS-Cached-Membership-Time-Stamp
:
 
msDS-ClaimSharesPossibleValuesWithBL
:
 
msDS-cloudExtensionAttribute1
:
 
msDS-cloudExtensionAttribute10
:
 
msDS-cloudExtensionAttribute11
:
 
msDS-cloudExtensionAttribute12
:
 
msDS-cloudExtensionAttribute13
:
 
msDS-cloudExtensionAttribute14
:
 
msDS-cloudExtensionAttribute15
:
 
msDS-cloudExtensionAttribute16
:
 
msDS-cloudExtensionAttribute17
:
 
msDS-cloudExtensionAttribute18
:
 
msDS-cloudExtensionAttribute19
:
 
msDS-cloudExtensionAttribute2
:
 
msDS-cloudExtensionAttribute20
:
 
msDS-cloudExtensionAttribute3
:
 
msDS-cloudExtensionAttribute4
:
 
msDS-cloudExtensionAttribute5
:
 
msDS-cloudExtensionAttribute6
:
 
msDS-cloudExtensionAttribute7
:
 
msDS-cloudExtensionAttribute8
:
 
msDS-cloudExtensionAttribute9
:
 
msDS-EnabledFeatureBL
:
 
msDS-FailedInteractiveLogonCount
:
 
msDS-FailedInteractiveLogonCountAtLastSuccessfulLogon
:
 
msDS-GeoCoordinatesAltitude
:
 
msDS-GeoCoordinatesLatitude
:
 
msDS-GeoCoordinatesLongitude
:
 
msDS-HABSeniorityIndex
:
 
msDS-HostServiceAccountBL
:
 
msDS-IsDomainFor
:
 
msDS-IsFullReplicaFor
:
 
msDS-IsPartialReplicaFor
:
 
msDS-IsPrimaryComputerFor
:
 
msDS-KrbTgtLinkBl
:
 
msDS-LastFailedInteractiveLogonTime
:
 
msDS-LastKnownRDN
:
 
msDS-LastSuccessfulInteractiveLogonTime
:
 
msDS-LocalEffectiveDeletionTime
:
 
msDS-LocalEffectiveRecycleTime
:
 
msDs-masteredBy
:
 
msDS-MembersForAzRoleBL
:
 
msDS-MembersOfResourcePropertyListBL
:
 
msDS-NC-RO-Replica-Locations-BL
:
 
msDS-NCReplCursors
:
 
msDS-NCReplInboundNeighbors
:
 
msDS-NCReplOutboundNeighbors
:
 
msDS-NcType
:
 
msDS-NonMembersBL
:
 
msDS-ObjectReferenceBL
:
 
msDS-OIDToGroupLinkBl
:
 
msDS-OperationsForAzRoleBL
:
 
msDS-OperationsForAzTaskBL
:
 
msDS-PhoneticCompanyName
:
 
msDS-PhoneticDepartment
:
 
msDS-PhoneticDisplayName
:
 
msDS-PhoneticFirstName
:
 
msDS-PhoneticLastName
:
 
msDS-PrimaryComputer
:
 
msDS-PSOApplied
:
 
msDS-ReplValueMetaData
:
 
msDS-ResultantPSO
:
 
msDS-RevealedDSAs
:
 
msDS-SecondaryKrbTgtNumber
:
 
msDS-Site-Affinity
:
 
msDS-SourceObjectDN
:
 
msDS-SupportedEncryptionTypes
:
 
msDS-TasksForAzRoleBL
:
 
msDS-TasksForAzTaskBL
:
 
msDS-TDOEgressBL
:
 
msDS-TDOIngressBL
:
 
msDS-ValueTypeReferenceBL
:
 
msExchAssistantName
:
 
msExchHouseIdentifier
:
 
msExchLabeledURI
:
 
msIIS-FTPDir
:
 
msIIS-FTPRoot
:
 
mSMQDigests
:
 
mSMQDigestsMig
:
 
mSMQSignCertificates
:
 
mSMQSignCertificatesMig
:
 
msNPAllowDialin
:
 
msNPCallingStationID
:
 
msNPSavedCallingStationID
:
 
msPKI-CredentialRoamingTokens
:
 
msPKIAccountCredentials
:
 
msPKIDPAPIMasterKeys
:
 
msPKIRoamingTimeStamp
:
 
msRADIUS-FramedInterfaceId
:
 
msRADIUS-FramedIpv6Prefix
:
 
msRADIUS-FramedIpv6Route
:
 
msRADIUS-SavedFramedInterfaceId
:
 
msRADIUS-SavedFramedIpv6Prefix
:
 
msRADIUS-SavedFramedIpv6Route
:
 
msRADIUSCallbackNumber
:
 
msRADIUSFramedIPAddress
:
 
msRADIUSFramedRoute
:
 
msRADIUSServiceType
:
 
msRASSavedCallbackNumber
:
 
msRASSavedFramedIPAddress
:
 
msRASSavedFramedRoute
:
 
msSFU30Name
:
 
msSFU30NisDomain
:
 
msSFU30PosixMemberOf
:
 
msTSAllowLogon
:
 
msTSBrokenConnectionAction
:
 
msTSConnectClientDrives
:
 
msTSConnectPrinterDrives
:
 
msTSDefaultToMainPrinter
:
 
msTSExpireDate
:
 
msTSExpireDate2
:
 
msTSExpireDate3
:
 
msTSExpireDate4
:
 
msTSHomeDirectory
:
 
msTSHomeDrive
:
 
msTSInitialProgram
:
 
msTSLicenseVersion
:
 
msTSLicenseVersion2
:
 
msTSLicenseVersion3
:
 
msTSLicenseVersion4
:
 
msTSLSProperty01
:
 
msTSLSProperty02
:
 
msTSManagingLS
:
 
msTSManagingLS2
:
 
msTSManagingLS3
:
 
msTSManagingLS4
:
 
msTSMaxConnectionTime
:
 
msTSMaxDisconnectionTime
:
 
msTSMaxIdleTime
:
 
msTSPrimaryDesktop
:
 
msTSProfilePath
:
 
msTSProperty01
:
 
msTSProperty02
:
 
msTSReconnectionAction
:
 
msTSRemoteControl
:
 
msTSSecondaryDesktops
:
 
msTSWorkDirectory
:
 
netbootSCPBL
:
 
networkAddress
:
 
nonSecurityMemberBL
:
 
ntPwdHistory
:
 
o
:
 
objectVersion
:
 
operatorCount
:
 
otherFacsimileTelephoneNumber
:
 
otherHomePhone
:
 
otherIpPhone
:
 
otherLoginWorkstations
:
 
otherMailbox
:
 
otherMobile
:
 
otherPager
:
 
otherTelephone
:
 
otherWellKnownObjects
:
 
ou
:
 
ownerBL
:
 
pager
:
 
partialAttributeDeletionList
:
 
partialAttributeSet
:
 
personalTitle
:
 
photo
:
 
physicalDeliveryOfficeName
:
 
possibleInferiors
:
 
postalAddress
:
 
postalCode
:
 
postOfficeBox
:
 
preferredDeliveryMethod
:
 
preferredLanguage
:
 
preferredOU
:
 
primaryInternationalISDNNumber
:
 
primaryTelexNumber
:
 
profilePath
:
 
proxiedObjectName
:
 
proxyAddresses
:
 
queryPolicyBL
:
 
registeredAddress
:
 
replUpToDateVector
:
 
repsFrom
:
 
repsTo
:
 
revision
:
 
rid
:
 
roomNumber
:
 
scriptPath
:
 
secretary
:
 
securityIdentifier
:
 
seeAlso
:
 
serialNumber
:
 
serverReferenceBL
:
 
servicePrincipalName
:
 
shadowExpire
:
 
shadowFlag
:
 
shadowInactive
:
 
shadowLastChange
:
 
shadowMax
:
 
shadowMin
:
 
shadowWarning
:
 
showInAddressBook
:
 
showInAdvancedViewOnly
:
 
sIDHistory
:
 
siteObjectBL
:
 
st
:
 
street
:
 
streetAddress
:
 
subRefs
:
 
supplementalCredentials
:
 
systemFlags
:
 
telephoneNumber
:
 
teletexTerminalIdentifier
:
 
telexNumber
:
 
terminalServer
:
 
textEncodedORAddress
:
 
thumbnailLogo
:
 
thumbnailPhoto
:
 
title
:
 
uid
:
 
uidNumber
:
 
unicodePwd
:
 
unixHomeDirectory
:
 
unixUserPassword
:
 
url
:
 
userCert
:
 
userCertificate
:
 
userParameters
:
 
userPassword
:
 
userPKCS12
:
 
userSharedFolder
:
 
userSharedFolderOther
:
 
userSMIMECertificate
:
 
userWorkstations
:
 
uSNDSALastObjRemoved
:
 
USNIntersite
:
 
uSNLastObjRem
:
 
uSNSource
:
 
wbemPath
:
 
wellKnownObjects
:
 
wWWHomePage
:
 
x121Address
:
 
x500uniqueIdentifier
:
 

Get-QADUser Full Help




NAME

    Get-QADUser
     
SYNOPSIS
    Retrieve all users in a domain or container that match the specified conditions. Supported are both Active Directory Domain Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS).
     
    This cmdlet is part of the Quest ActiveRoles Server product. Use Get-QARSProductInfo to view information about ActiveRoles Server.
     
SYNTAX
    Get-QADUser [[-Identity] <IdentityParameter>] [-AccountExpiresAfter <DateTime>] [-AccountExpiresBefore <DateTime>] [-AccountNeverExpires] [-Activity <string>] [-Anr <string>] [-AttributeScopeQuery <string>] [-City <string[]>] [-Company <string[]>] [-Connection <ArsConnection>]
    [-ConnectionAccount <string>] [-ConnectionPassword <SecureString>] [-Control <hashtable>] [-CreatedAfter <DateTime>] [-CreatedBefore <DateTime>] [-CreatedOn <DateTime>] [-Credential <PSCredential>] [-Department <string[]>] [-Description <string[]>] [-Disabled] [-DisplayName <string[]>]
    [-DontConvertValuesToFriendlyRepresentation] [-DontUseDefaultIncludedProperties] [-Email <string[]>] [-Enabled] [-ExcludedProperties <string[]>] [-ExpiredFor <int>] [-Fax <string[]>] [-FirstName <string[]>] [-HomeDirectory <string[]>] [-HomeDrive <string[]>] [-HomePhone <string[]>] [-Inactive]
    [-InactiveFor <int>] [-IncludeAllProperties] [-IncludedProperties <string[]>] [-IndirectMemberOf <IdentityParameter[]>] [-Initials <string[]>] [-LastChangedAfter <DateTime>] [-LastChangedBefore <DateTime>] [-LastChangedOn <DateTime>] [-LastKnownParent <IdentityParameter>] [-LastName
    <string[]>] [-LdapFilter <string>] [-Locked] [-LogonScript <string[]>] [-Manager <IdentityParameter>] [-MemberOf <IdentityParameter[]>] [-MobilePhone <string[]>] [-Name <string[]>] [-Notes <string[]>] [-NotIndirectMemberOf <IdentityParameter[]>] [-NotLoggedOnFor <int>] [-NotMemberOf
    <IdentityParameter[]>] [-Office <string[]>] [-Pager <string[]>] [-PageSize <int>] [-PasswordNeverExpires] [-PasswordNotChangedFor <int>] [-PhoneNumber <string[]>] [-PostalCode <string[]>] [-PostOfficeBox <string[]>] [-PrimaryProxyAddress <string[]>] [-ProfilePath <string[]>]
    [-ProgressThreshold <int>] [-Proxy] [-ProxyAddress <string[]>] [-Recycled] [-ReturnPropertyNamesOnly] [-SamAccountName <string[]>] [-SearchAttributes <Object>] [-SearchRoot <IdentityParameter[]>] [-SearchScope {Base | OneLevel | Subtree}] [-SecondaryProxyAddress <string[]>] [-SecurityMask
    {None | Owner | Group | Dacl | Sacl}] [-SerializeValues] [-Service <string>] [-ShowProgress] [-SizeLimit <int>] [-StateOrProvince <string[]>] [-StreetAddress <string[]>] [-Title <string[]>] [-Tombstone] [-UseDefaultExcludedProperties <Boolean>] [-UseDefaultExcludedPropertiesExcept <string[]>]
    [-UseGlobalCatalog] [-UserPrincipalName <string[]>] [-WebPage <string[]>] [-WildcardMode <WildcardMode>] [<CommonParameters>]
     
     
DESCRIPTION
    Use this cmdlet to search an Active Directory domain or container for user accounts that meet certain search criteria, or to bind to a certain user account by DN, SID, GUID, UPN or Domain\UserName. You can search by user attributes or specify your search criteria by using an LDAP search filter.
     
    The output of the cmdlet is a collection of objects, with each object representing one of the user accounts found by the cmdlet. You can pipe the output into another cmdlet, such as Set-QADUser, to make changes to the user accounts returned by this cmdlet.
     
    The cmdlet takes a series of optional, attribute-specific parameters allowing you to search by user attributes. The attribute-specific parameters have effect if SearchRoot is specified  whereas Identity is not. If you specify SearchRoot only, then the cmdlet returns all users found in the
    SearchRoot container.
     
    You can use attribute-specific parameters to search for user accounts that have specific values of certain attributes. Thus, to find all user accounts that have the givenName attribute set to Martin, you may add the following on the command line: "-FirstName Martin". To search for user
    accounts that have a certain attribute not set specify '' (empty string) as the parameter value.
     
    If a given attribute is referred to by both the ObjectAttributes array and an attribute-specific parameter, the ObjectAttributes setting has no effect on that attribute. The cmdlet searches for the attribute value specified by the attribute-specific parameter.
     
    With more than one attribute-specific parameter supplied, the search conditions are combined by using the AND operator, so as to find the user accounts that meet all the specified conditions. Thus, if you supply both the -FirstName and -LastName parameters, the cmdlet searches for the user
    accounts that have the givenName attribute set to the FirstName parameter value and the sn attribute set to the LastName parameter value.
     
    Each of the attribute-specific parameters accepts the * wildcard character in the parameter value to match zero or more characters (case-insensitive). For instance, a* matches A, ag, Amsterdam, and does not match New York.
     
    The cmdlet has optional parameters that determine the server and the security context for the operation. Normally, the connection parameters could be omitted so far as a connection to a server is established prior to using the cmdlet. In this case, the server and the security context are
    determined by the Connect-QADService cmdlet.
     
    If you do not use Connect-QADService and have no connection established prior to using a cmdlet, then the connection settings, including the server and the security context, are determined by the connection parameters of the first cmdlet you use. Subsequent cmdlets will use those settings by
    default.
     
 
PARAMETERS
    -AccountExpiresAfter <DateTime>
        Retrieve user accounts that are configured to expire after a certain date. Parameter value is a DateTime object that specifies the date you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -AccountExpiresBefore <DateTime>
        Retrieve user accounts that are configured to expire before a certain date. Parameter value is a DateTime object that specifies the date you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -AccountNeverExpires [<SwitchParameter>]
        Set the value of this parameter to 'true' if you want the cmdlet to retrieve only those user accounts that are configured to never expire.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Activity <string>
        Use this parameter to specify the line of text above the progress bar which the cmdlet displays to depict the status of the running command in case of a lengthy operation. This text describes the activity whose progress is being reported (see also ShowProgress and ProgressThreshold). If
        this parameter is omitted, the name of the cmdlet is displayed above the progress bar.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Anr <string>
        Specify a value to be resolved using ambiguous name resolution (ANR). Which attributes are included in an ANR search depends upon the Active Directory schema. Thus, in Windows Server 2003 based Active Directory, the following attributes are set for ANR by default:
         
         Display-Name (displayName)
         Given-Name (givenName)
         Legacy-Exchange-DN (legacyExchangeDN)
         ms-DS-Additional-Sam-Account-Name (msDS-AdditionalSamAccountName)
         Physical-Delivery-Office-Name (physicalDeliveryOfficeName)
         Proxy-Addresses (proxyAddresses)
         RDN (name)
         SAM-Account-Name (sAMAccountName)
         Surname (sn)
         
        For instance, when you supply 'ann*' as the value of this parameter, the cmdlet searches for objects that have ann at the beginning of the value of at least one of the attributes listed above.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -AttributeScopeQuery <string>
        Specify the LDAP display name of an attribute that has DN syntax (for example, 'memberOf'). The cmdlet enumerates the distinguished name values of the attribute on the object specified by the SearchRoot parameter, and performs the search on the objects represented by the distinguished
        names. The SearchScope parameter has no effect in this case. The object to search must be specified by using the SearchRoot parameter rather than the Identity parameter.
         
        For instance, with the value of this parameter set to 'memberOf', the cmdlet searches the collection of the groups to which the SearchRoot object belongs.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -City <string[]>
        Search by the 'l' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Company <string[]>
        Search by the 'company' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Connection <ArsConnection>
        For parameter description, see help on the Connect-QADService cmdlet.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -ConnectionAccount <string>
        For parameter description, see help on the Connect-QADService cmdlet.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -ConnectionPassword <SecureString>
        For parameter description, see help on the Connect-QADService cmdlet.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Control <hashtable>
        Use this parameter to pass request controls (in-controls) to ActiveRoles Server as part of an operation request. In ActiveRoles Server, request controls are used to send extra information along with an operation request, to control how ActiveRoles Server performs the request.
         
        The parameter value is a hash table that defines the names and values of the request controls to be passed to ActiveRoles Server. The parameter syntax is as follows:
         
            -Control @{<name> = <value>; [<name> = <value>] ...}
         
        In this syntax, each of the name-value pairs is the name and the value of a single control. For instructions on how to create and use hash tables, see topic "about_associative_array" or "about_hash_tables" in Windows PowerShell Help. For information about ActiveRoles Server request
        controls, refer to ActiveRoles Server SDK documentation.
         
        Note that this parameter only has an effect on the operations that are performed through ActiveRoles Server (connection established using the Proxy parameter); otherwise, this parameter causes an error condition in ActiveRoles Management Shell.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -CreatedAfter <DateTime>
        Specify the lower boundary of the object creation date and time by which to filter objects found. The cmdlet returns only the objects that were created after the date and time specified. Supplying both CreatedAfter and CreatedBefore bounds a time interval for the objects' creation. If you
        supply only CreatedAfter, there is no upper boundary on the date. Parameter value is a DateTime object that specifies the date and time you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -CreatedBefore <DateTime>
        Specify the upper boundary of the object creation date and time by which to filter objects found. The cmdlet returns only the objects that were created before the date and time specified. Supplying both CreatedAfter and CreatedBefore bounds a time interval for the objects' creation. If you
        supply only CreatedBefore, there is no lower boundary on the date. Parameter value is a DateTime object that specifies the date and time you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -CreatedOn <DateTime>
        Specify the object creation date by which to filter objects found, searching for objects created within the date specified. This parameter is mutually exclusive with the CreatedAfter and CreatedBefore parameters. Parameter value is a DateTime object that specifies the date you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Credential <PSCredential>
        For parameter description, see help on the Connect-QADService cmdlet.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Department <string[]>
        Search by the 'department' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Description <string[]>
        Search by the 'description' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Disabled [<SwitchParameter>]
        Supply this parameter on the command line if you want the search results produced by this cmdlet to include only those user accounts that are disabled.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -DisplayName <string[]>
        Search by the 'displayName' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -DontConvertValuesToFriendlyRepresentation [<SwitchParameter>]
        This parameter causes the cmdlet to represent the Integer8 and OctetString attribute values "as is," without converting them to a user-friendly, human-readable form. If this parameter is omitted, the cmdlet performs the following data conversions:
         
         - The values of the Integer8 attributes listed in the
           Integer8AttributesThatContainDateTimes array
           (see the parameter descriptions for the
           Get-QADPSSnapinSettings and Set-QADPSSnapinSettings
           cmdlets) are converted from IADsLargeInteger to DateTime
         
         - The values of the Integer8 attributes listed in the
           Integer8AttributesThatContainNegativeTimeSpans array
           (see the parameter descriptions for the
           Get-QADPSSnapinSettings and Set-QADPSSnapinSettings
           cmdlets) are converted from IADsLargeInteger to TimeSpan
         
         - The values of the other Integer8 attributes are
           converted from IADsLargeInteger to Int64
         
         - The values of the OctetString attributes are converted
           from byte[] to BinHex strings
         
        Note: This parameter has an effect only on the properties of the output object that have the member type of NoteProperty. Such properties are normally added to the output object in order to provide access to the attribute values of the respective directory object that are loaded to the
        local memory cache but cannot be accessed by using properties of the base object (the object for which the output object serves as a wrapper).
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -DontUseDefaultIncludedProperties [<SwitchParameter>]
        This parameter causes the cmdlet to load only a small set of attributes from the directory to the local memory cache (normally, this set is limited to objectClass and ADsPath). Other attributes are retrieved from the directory as needed when you use the cmdlet's output objects to read
        attribute values. Thus, if you want only to count the objects that meet certain conditions (rather than examine values of particular attributes), then you can use this parameter to increase performance of your search. For examples of how to use this parameter, see help on the Get-QADUser
        cmdlet.
         
        Note: If a cmdlet does not cache a particular attribute, then the output object returned by the cmdlet may not have a property that would provide access to the value of the attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Email <string[]>
        Search by the 'mail' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Enabled [<SwitchParameter>]
        Supply this parameter on the command line if you want the search results produced by this cmdlet to include only those user accounts that are enabled (not disabled).
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -ExcludedProperties <string[]>
        Use this parameter to specify the attributes that you do not want the cmdlet to retrieve from the directory and store in the memory cache on the local computer. Supply a list of the attribute LDAP display names as the parameter value. By default, the cmdlet caches a certain pre-defined set
        of attributes, which you can view or modify by using the Get-QADPSSnapinSettings or Set-QADPSSnapinSettings cmdlet, respectively. Using the ExcludedProperties parameter you can change this default behavior on an ad-hoc basis, in order to prevent certain attributes from being loaded.
        Another scenario involves the use of this parameter in conjunction with IncludeAllProperties in order to restrict the set of the cached attributes.
         
        Note: If a cmdlet does not cache a particular attribute, then the output object returned by the cmdlet may not have a property that would provide access to the value of the attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -ExpiredFor <int>
        Use this parameter to retrieve accounts that remain in the expired state for at least the number of days specified by the parameter value. This parameter overrides the expiry-related inactivity condition of the Inactive or InactiveFor parameter. Thus, if the ExpiredFor value of 0 is
        supplied in conjunction with the InactiveFor value of 30, the cmdlet searches for accounts that are currently expired, or have the password age of 30 or more days, or have not been used to log on for 30 or more days.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Fax <string[]>
        Search by the 'facsimileTelephoneNumber' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -FirstName <string[]>
        Search by the 'givenName' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -HomeDirectory <string[]>
        Search by the 'homeDirectory' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -HomeDrive <string[]>
        Search by the 'homeDrive' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -HomePhone <string[]>
        Search by the 'homePhone' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Identity <IdentityParameter>
        Specify the DN, SID, GUID, UPN or Domain\UserName of the user account you want to find.
         
        The cmdlet attempts to find the user that is identified by the value of this parameter, disregarding the other parameters. If you want other parameters to have effect, do not supply any value of this parameter on the command line.
         
        Required?                    false
        Position?                    1
        Default value               
        Accept pipeline input?       true (ByValue, ByPropertyName)
        Accept wildcard characters?  false
         
    -Inactive [<SwitchParameter>]
        Supply this parameter to retrieve user accounts that meet the default inactivity conditions. You can view or change the default inactivity conditions by using the Get-QADInactiveAccountsPolicy or Set-QADInactiveAccountsPolicy cmdlet, respectively. When considering whether an account is
        inactive, the cmdlet verifies each of these values:
         
         - The number of days that the account remains in the expired state
         - The number of days that the password of the account remains unchanged
         - The number of days that the account remains unused for logon
         
        If any of these values exceeds a certain, default limit, then the account is considered inactive, and thus is retrieved by the Inactive parameter. The default limits can be overridden by supplying other account-inactivity related parameters, such as InactiveFor, ExpiredFor, NotLoggedOnFor,
        and PasswordNotChangedFor. Thus, if the NotLoggedOnFor value of 60 is supplied in conjunction with the Inactive parameter, the cmdlet searches for accounts that meet the default expiry-related or password-related inactivity condition, or have not been used to log on for 60 or more days.
         
        To retrieve only those accounts that are not inactive, use the following syntax: -Inactive:$false
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -InactiveFor <int>
        Use this parameter to retrieve user accounts that meet any of the following conditions:
         
         - The account remains in the expired state for at least the number of days specified by the parameter value
         - The account does not have its password changed for at least the number of days specified by the parameter value
         - The account has not been used to log on for at least the number of days specified by the parameter value
         
        For example, the parameter value of 30 causes the cmdlet to search for accounts that are expired for 30 or more days, or have the password age of 30 or more days, or have not been used to log on for 30 or more days.
         
        The value of this parameter overrides the default inactivity conditions, so the Inactive parameter has no effect when used together with this parameter. Similarly, the other account-inactivity related parameters such as ExpiredFor, NotLoggedOnFor and PasswordNotChangedFor override the
        corresponding conditions of this parameter. Thus, if the NotLoggedOnFor value of 60 is supplied in conjunction with the InactiveFor value of 30, the cmdlet searches for accounts that are expired for 30 or more days, or have the password age of 30 or more days, or have not been used to log
        on for 60 or more days.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -IncludeAllProperties [<SwitchParameter>]
        With this parameter, the cmdlet retrieves all attributes of the respective directory object (such as a User object), and stores the attribute values in the memory cache on the local computer. Attribute values can be read from the memory cache by using properties of the object returned by
        the cmdlet. Thus, when used in conjunction with the SerializeValues parameter, it allows an entire object to be exported from the directory to a text file. For examples of how to use this parameter, see help on the Get-QADUser or Get-QADObject cmdlet.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -IncludedProperties <string[]>
        Use this parameter to specify the attributes that you want the cmdlet to retrieve from the directory and store in the memory cache on the local computer. Supply a list of the attribute LDAP display names as the parameter value. By default, the cmdlet caches a certain pre-defined set of
        attributes, which you can view or modify by using the Get-QADPSSnapinSettings or Set-QADPSSnapinSettings cmdlet, respectively. Using the IncludedProperty parameter you can direct the cmdlet to cache some attributes in addition to the default set.
         
        Note: Caching an attribute guarantees that the value of the attribute can be read by using properties of the output object returned by the cmdlet.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -IndirectMemberOf <IdentityParameter[]>
        Retrieve objects that belong to the group or groups specified by this parameter, whether directly or because of group nesting. The cmdlet returns an object if the object has direct or indirect membership in the group specified by this parameter value.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Initials <string[]>
        Search by the 'initials' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -LastChangedAfter <DateTime>
        Specify the lower boundary of the object modification date and time by which to filter objects found. The cmdlet returns only the objects that have last changed after the date and time specified. Supplying both LastChangedAfter and LastChangedBefore bounds a time interval for the objects'
        last change. If you supply only LastChangedAfter, there is no upper boundary on the date. Parameter value is a DateTime object that specifies the date and time you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -LastChangedBefore <DateTime>
        Specify the upper boundary of the object modification date and time by which to filter objects found. The cmdlet returns only the objects that have last changed before the date and time specified. Supplying both LastChangedAfter and LastChangedBefore bounds a time interval for the objects'
        last change. If you supply only LastChangedBefore, there is no lower boundary on the date. Parameter value is a DateTime object that specifies the date and time you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -LastChangedOn <DateTime>
        Specify the object modification date by which to filter objects found, searching for objects that have last changed within the date specified. This parameter is mutually exclusive with the LastChangedAfter and LastChangedBefore parameters. Parameter value is a DateTime object that
        specifies the date you want.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -LastKnownParent <IdentityParameter>
        When searching for a deleted object by using the Tombstone parameter, specify the DN of the container the object was in before it became a tombstone. This allows you to find objects that were deleted from a particular container.
         
        Note that the lastKnownParent attribute is only set if the object was deleted on a domain controller running Windows Server 2003 or later version of Microsoft Windows Server. Therefore, it is possible that the lastKnownParent attribute value is inaccurate.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -LastName <string[]>
        Search by the 'sn' attribute.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -LdapFilter <string>
        Specify the LDAP search filter that defines your search criteria. Note that the search filter string is case-sensitive.
         
        The cmdlet disregards this parameter if an Identity value is supplied. If you want this parameter to have effect, do not supply any Identity value on the command line. Instead, supply a SearchRoot value.
         
        If you supply the LdapFilter parameter along with attribute-specific parameters, then your search returns objects that meet the conditions defined by the LDAP filter and have the specified attributes set to the specified values.
         
        Required?                    false
        Position?                    named
        Default value               
        Accept pipeline input?       false
        Accept wildcard characters?  false
         
    -Locked [<SwitchParameter>]
        Supply this parameter on the command line if you want the search results produced by this cmdlet to include only those user accounts that are locked out.
         
        Required?               &nbs