Active Directory Group Attributes List

This page is a reference that maps the attributes of Active Directory group objects to the tabs of the Windows Server 2008 “Active Directory Users and Computers” (ADUC) interface. Each section shows a screenshot of the tab, followed by a table of which LDAP attribute each field corresponds to. Use it when writing PowerShell scripts, building LDAP queries, or mapping groups in IAM/provisioning integrations.

For the same mapping on user objects, see Active Directory Attributes List.

Source and images: SelfADSI – Attributes for AD Groups (Windows 2008)


Table of Contents


General Tab

UI FieldLDAP Attribute NameDescription
Group icon (object class)objectClassClass of the object (group)
Group icon (object category)objectCategoryCategory of the object (points to the Group class in the schema)
Group name (title)distinguishedNameFull path of the object in the directory (e.g. CN=LEXDev,CN=Users,DC=...)
Group name (title)cnCommon Name
Group name (title)nameRDN (Relative Distinguished Name) value
Group name (pre-Windows 2000)sAMAccountNamePre-Windows 2000 (NetBIOS) group name
DescriptiondescriptionDescription of the group
E-mailmailE-mail address of the group
Group scope / Group typegroupTypeScope (Domain local, Global, Universal) and type (Security, Distribution) stored in a single bit field
NotesinfoFree-text notes about the group

active directory group general tab


Members Tab

UI FieldLDAP Attribute NameDescription
MembersmemberList of DNs of the user/group/computer objects that belong to the group
(Backlink)memberOfBacklink on the user object; calculated automatically from member and cannot be written directly

active directory group members tab


Member Of Tab

UI FieldLDAP Attribute NameDescription
Member ofmemberOfList of DNs of the parent groups this group belongs to
(Backlink)memberThe matching membership entry on the other group object (this group appears in the parent’s member list)

Note the text at the bottom of the tab: the list only displays groups from the current domain and groups maintained in the Global Catalog, such as universal groups.

active directory group member of tab


Managed By Tab

This tab shows attributes of the user who manages the group, so most fields below are attributes of the manager user object, not of the group.

UI FieldLDAP Attribute NameDescription
NamemanagedByDN of the user/group managing this group (attribute on the group)
Manager can update membership listnTSecurityDescriptorWhen checked, the manager gets write permission on the member attribute
OfficephysicalDeliveryOfficeNameOffice of the manager user
StreetstreetAddressStreet address of the manager user
CitylCity
State/provincestState/province
Country/regioncoCountry name
Country/regioncTwo-letter country code (ISO 3166)
Country/regioncountryCodeNumeric country code
Telephone numbertelephoneNumberTelephone number
Fax numberfacsimileTelephoneNumberFax number

active directory group managed by tab


Object Tab

UI FieldLDAP Attribute NameDescription
Canonical name of objectcanonicalNamePath of the object in domain/OU/name form (constructed attribute)
Object classobjectClassObject class (group)
Object classobjectCategoryObject category
CreatedwhenCreatedTime the object was created
CreatedcreateTimeStampCreation time (operational attribute, same information as whenCreated)
ModifiedwhenChangedTime the object was last modified
ModifiedmodifyTimeStampLast modification time (operational attribute)
Update Sequence Numbers – CurrentuSNCreatedUpdate Sequence Number (USN) at the time the object was created
Update Sequence Numbers – OriginaluSNChangedUSN at the time of the last change (used by replication)

The screenshot also shows the Protect object from accidental deletion checkbox; it adds a Deny entry to the object’s ACL that prevents deletion.

active directory group object tab


Security Tab

UI FieldLDAP Attribute NameDescription
Group or user names / PermissionsnTSecurityDescriptorSecurity descriptor of the object: owner, DACL (who can do what) and SACL (auditing)

The whole list of users/groups and the permission checkboxes on this tab are the visual representation of a single attribute, nTSecurityDescriptor.

active directory group security tab


Attribute Editor Tab

This tab gives low-level access to all attributes of the group object. It is the functionality that the ADSI Edit tool provided in former Windows/AD versions, now built into ADUC (View > Advanced Features must be enabled to see it). It is useful but basic for viewing and editing low-level directory data; a specialized LDAP browser such as LDAP Explorer is more comfortable.

The first attributes in the list shown in the screenshot are:

LDAP Attribute NameExample Value
accountNameHistory<not set>
adminCount<not set>
adminDescription<not set>
adminDisplayName<not set>
altSecurityIdentities<not set>
cnLEXDev
controlAccessRights<not set>
description<not set>
desktopProfile<not set>
displayName<not set>
displayNamePrintable<not set>
distinguishedNameCN=LEXDev,CN=Users,DC=cerrotorre,DC=de
dSASignature<not set>
dSCorePropagationData5/8/2009 7:33:27 AM Pacific Daylight Time

active directory group attribute editor tab


Source

The screenshots and attribute mappings in this post come from the “Attributes for AD Groups (Windows 2008)” page on SelfADSI, extended with descriptions. Image rights belong to SelfADSI / CerroTorre Networking.