Cross forest group nesting report

I have set the discovery for AD to collect group nestings as needed -but I need to make a report now for it.

Needs- 

Required fields Domain and Group name to input to report nested information on.

Output

Domain name, Group name, OU path to group, domain group nested name, domain of that group nesting, 

List of users in the groups that are in the other forest, that the group is nested into Forest domain local group.

ForestA, DomainlocalForestAgroup,  ForestB, DomainGlobalGroupForestBgroup - expand all group memberships found nested.

  • Interesting scenario. Forest Trust + Foreign Security Principle? 

  • Basicly yes, each domain I collect nested groups and members from foreign domains in that discovery of all the forests - would now like to pull reports on key groups that are nested and show who the effective members are of the group by showing the foreign domain group and all its members also.

  • Hello,

    Thank you for your request.   Sorry for the delay on our response.  An Enterprise Reporter team member will take a look at this request today.  We will look at the current product and determine if using existing features can accomplish your request.  If so, a custom report can be created.   

    While we investigate, please answer the following questions about your requested report: 

    To request a new custom report, please post in our Custom Reports Forum and provide the following information:

    What version of Enterprise Reporter is being used?

    What discoveries have been run?

    Is there a library report that closely matches what you require?

    What fields are required in the report?

    How does the information in the report need to be sorted?

    What parameters are required for filtering the report?

    How will this report be viewed? For example, will the report be viewed in report display, exported to CSV, or exported to PDF?

    Thank you,

    -Angela

  • Hello,

    I am looking at our Domain Groups and Members report which seems to have all the requested input and Output fields. Have you tried that report with the last parameter "How to would you like to handle nested groups and their members" and selecting the "Expand Inline including members of Domain Users groups" option?

    Thank you,

    Philip

  • Would like the report to list the groups and or user that are nested (as you know either can be nested cross forest and Ideal if we have discovered the other forest already (like we have) would like to expand that group also in the report.

  • What version of Enterprise Reporter is being used? 3.1

    What discoveries have been run? NTFS windows, NTFS NAS, AD, SQL

    Is there a library report that closely matches what you require? None that I can tell

    What fields are required in the report? Group name - Name of group that is ForeignSecurityPrincipals,  what object is nested from the other forest into this group, and its members if it is a group or if its a single account what that SAMAccount is (readable name) take a look at an example ForeignSecurityPrincipals OU when you have cross nested groups or users.

    How does the information in the report need to be sorted? Sorted by as seen in the ou is good enough -but getting it to csv we can deal with sorting there

    What parameters are required for filtering the report? Must be somehow tied to ForeignSecurityPrincipals OU

    How will this report be viewed? For example, will the report be viewed in report display, exported to CSV, or exported to PDF CSV be ideal

  • In the Reporter Library, under Active Directory, there is an existing report, Domain Groups and Members.  if you change the last parameter to "Expand Inline...", you can see all of the groups and members, recursively, for the group, including groups from foreign domains, assuming they were collected..  If you want to include additional information for the included foreign members, you can click the Add Fields button on that last parameter and include extra attributes (but only if a AD discovery was created for the foreign domain)   

    Is this what is wanted?

  • Tried the above a couple ways- but I am really trying to focus only on the group that are tied to that foreign objects OU and find the in-line on just those.

  • Hi, 

    I am working on a custom report based on new requirement to focus only on groups tied to foreign domains and will get back to you as soon as possible. 

    Thank you