Why use this template?
Use this free PowerShell script when you need to export nested users from an ad group. It is generated locally and can be reviewed before you run it yourself in your own PowerShell session.
The template uses ActiveDirectory and requires Directory read access. Output: CSV report. Level: Intermediate. Action: Read-only. Risk: Low.
Review before running
The script is generated in your browser. Read it before you run it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.
Generate the script
- Open the template in the PowerShell Builder.
- Enter the requested values and review the module, permissions, output and risk.
- Generate the script, read it carefully, and test it outside production before use.
The script is generated locally in your browser. Nothing needs to be uploaded to Opselith.
Generate Export AD group members →How to use this result
Use this report when you need a CSV of user members from one Active Directory group. It expands nested membership and lets you keep the normal columns or choose only the identity and account fields you need.
When this helps
- Export group membership to CSV for an access review, audit, migration check or owner review.
- Include useful user fields such as account name, UPN, email address, enabled state and last logon date.
- Create a repeatable membership snapshot that you can review locally or compare with an earlier export.
How to read the result
- This template expands nested group membership and exports user objects. Nested groups themselves are not exported as user rows.
- LastLogonDate is based on the replicated lastLogonTimestamp value exposed by Active Directory, so it is useful for review but is not a real-time sign-in timestamp.
Things to check
- Only user objects are included. If the group contains computers, contacts or other object types, those objects are outside this user-focused CSV.
- Large or deeply nested groups can take longer because the script resolves membership and then reads the selected user properties.
What to do next: Open the CSV in Group Membership Review to check identifiers and duplicates. If you specifically need only immediate members without expanding nested groups, use the direct-members export instead.
Related tasks
Official references