From: Clifford Heath Date: 2007-04-25T12:45:04+09:00 Subject: Re: Retrieving Groups from a DSQUERY Pe�a wrote: > look into "dsquery group" and "dsget group -members" It sounds like the OP already did that. > name = m.sub ",CN=Users,DC=delmonte-phil,DC=com\"", "" > name = name.sub "\"CN=", "" > name = name.sub "\\", "" This only works for users in CN=Users, even assuming that you adjust the domain name as appropriate. My solution gets the CN from any user, whether in CN=Users or not, without knowing the domain name. Hint: many organizations put their users in OU's... The CN=Users container is really only there for migration from NT4, so the domain root isn't filled up with users and computers from the migration. It's even legal to put users in a container (CN=) under an OU, though it's not advised (it's allowed because that's what CN=Users is). The only correct solution is to match the RDN component after the user's CN=, up to the start of the next RDN part, as I showed. Clifford Heath.