October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk3 min

How to Manage On-Premises Active Directory Groups with PowerShell

Use the ActiveDirectory PowerShell module to find groups, create them, inspect membership, add or remove members, and delete a group safely.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This guide covers on-premises Active Directory Domain Services (AD DS) using the Windows PowerShell ActiveDirectory module: finding groups, creating them, reviewing membership, adding or removing members, and deleting a group. Microsoft Entra ID is a separate directory with a separate PowerShell workflow; use Microsoft’s Manage groups in Microsoft Entra ID guide if you mean cloud groups, rather than mixing Entra cmdlets with AD DS commands.

Before you run the commands

The examples below are templates, not tested commands. Replace sample names and distinguished names with values from your domain, check the target domain or domain controller as appropriate, and use credentials with only the delegated permissions needed for the change. Microsoft’s AD cmdlet references warn that insufficient directory permissions can cause a terminating error.

As an Amazon Associate I earn from qualifying purchases.

Use the current Microsoft Learn references for the ActiveDirectory module when checking syntax and parameters. The references cited here document the cmdlets, but your organization’s naming rules, delegation, approval process, and allowed group configurations may differ.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Find an Active Directory group

Look up a known group

Get-ADGroup retrieves one or more AD groups. For a known identity, it accepts a distinguished name, GUID, SID, or SAM account name. A SAM account name is often convenient for a quick lookup:

Get-ADGroup -Identity 'Finance-Readers'

Microsoft describes this cmdlet as “Gets one or more Active Directory groups.” See the Get-ADGroup reference for the supported identity forms.

Search a bounded part of the directory

Use -Filter or -LDAPFilter to find groups by attributes. Bound a broad search with -SearchBase and, where appropriate, -SearchScope. Request non-default attributes with -Properties; the default result does not include every attribute.

Get-ADGroup -Filter "Name -like '*Finance*'" `
  -SearchBase 'OU=Groups,DC=example,DC=com' `
  -Properties Description,ManagedBy

Here, the filter matches group names containing “Finance,” and the search base limits the search to the specified organizational unit and its directory location. Substitute a distinguished name that exists in your environment.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

Create a group

New-ADGroup creates a group. Its required parameters include -Name and -GroupScope. You can also set category and metadata such as description, display name, manager, SAM account name, and the OU path where the group should be created.

Choose the group scope and category according to your directory design; there is no one scope that is right for every organization. This example previews creation of a security group in a specified OU:

New-ADGroup -Name 'Finance-Readers' `
  -SamAccountName 'Finance-Readers' `
  -GroupCategory Security `
  -GroupScope Global `
  -Path 'OU=Groups,DC=example,DC=com' `
  -Description 'Read access for Finance resources' `
  -WhatIf

-WhatIf previews the proposed operation instead of making the change. Confirm the target, naming conventions, scope, category, and OU before running an approved creation without -WhatIf. Consult the New-ADGroup reference for parameter details.

Review a group’s members

Use Get-ADGroupMember to inspect membership before or after a change. It can help you verify that you have the intended group and that a member was added or removed as expected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Get-ADGroupMember -Identity 'Finance-Readers'

See Microsoft’s Get-ADGroupMember reference for supported parameters.

Add a member to a group

Add-ADGroupMember adds users, groups, service accounts, or computers. Identify the group and member precisely, and preview the change before applying it where that fits your change process:

Add-ADGroupMember -Identity 'Finance-Readers' -Members 'jdoe' -WhatIf

After reviewing the preview and obtaining any required approval, apply the change and confirm membership:

Add-ADGroupMember -Identity 'Finance-Readers' -Members 'jdoe'
Get-ADGroupMember -Identity 'Finance-Readers'

Microsoft’s Add-ADGroupMember reference describes the cmdlet as “Adds one or more members to an Active Directory group.” Supported AD identity forms can be used for members; use the form that unambiguously identifies the intended object.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Remove a member

Use Remove-ADGroupMember to remove a member from a group. Check both the group and member identities before proceeding; the preview helps catch a mistaken target.

Remove-ADGroupMember -Identity 'Finance-Readers' `
  -Members 'jdoe' `
  -WhatIf

Once the proposed removal is reviewed and authorized, run it without -WhatIf, then use Get-ADGroupMember to verify the resulting membership.

The add and remove member cmdlets expose -WhatIf and -Confirm controls. See the Remove-ADGroupMember reference for its parameters and behavior.

Delete a group

Remove-ADGroup deletes the group object, including security and distribution groups. Deletion is distinct from removing a member and has a wider impact, so validate the exact group and follow your organization’s change-control and retention policies.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Remove-ADGroup -Identity 'Finance-Readers' -WhatIf

Review the preview before running an approved deletion without -WhatIf. Microsoft documents the cmdlet in the Remove-ADGroup reference.

On-premises AD DS and Microsoft Entra ID are different workflows

The commands in this guide manage AD DS groups through the ActiveDirectory module. Microsoft Entra ID groups are managed with a separate Microsoft Entra PowerShell workflow, not by substituting cloud objects into these cmdlets. Microsoft’s Entra group management guide covers its own module setup, prerequisites, and tasks such as creating groups, adding users or owners, listing members, and cleaning up resources.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.