Active Directory: Finding and Copying the DN of an Object using LDP.exe

If you want a graphical tool to find the DN of an Active Directory object then the free Microsoft tool LDP.exe should do the trick. The tool is included with the Windows Server OS and can be accessed from your local computer if you have the Windows Server 2003 Admin Pack or the 2008 RSAT installed.

Note: The steps below are from the 2008 R2 RSAT version of LDP, the process is very similar for the 2003 version however some of the memu names etc at a bit different.

You can do some real damage to your domain using this tool, I recommend that when you bind to the domain you user the credentials of a standard use not an administrator.

1) Open Start => run enter LDP and press OK

2) Go to Connection => connect

ldp_1.png

3) Enter the FQDN of the domain or of a domain controller and press OK

ldp_2.png

4) Go to connection Bind

ldp_3.png

5) Either select “Bind as current user” or specify some alternative credentials, then press OK.

I recommend that when you bind to the domain you use the credentials of a standard user not an administrator.

ldp_4.png

6) go to View => Tree

ldp_5.png

7) On the Tree View dialog you caa normally just press OK but if you have a large domain you may want to specify the DN of a root to reduce the load on the DC.

ldp_6.png

8) Browse down the tree on the left (double-click to expand) until you get to the object you want the DN of. Right-click the object and select Copy DN

ldp_7.png

9) Paste the DN in notepad or wherever.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.