How to determine what groups a user belongs to?
There are several commands that can be done. Here are a few:
/opt/quest/bin/vastool list group <groupname>
/opt/quest/bin/vastool -u <user> auth groups
/opt/quest/bin/vastool -u host/ attrs <user> memberOf
Here is an example of a useful command for scripting:
root@v403h-rh6 etc]# vastool -u host/ attrs gboudreau memberOf
memberOf: CN=lgaccess,CN=Users,DC=i,DC=ts,DC=hal,DC=ca,DC=qsft
memberOf: CN=MCUADMIN,CN=Users,DC=i,DC=ts,DC=hal,DC=ca,DC=qsft
memberOf: CN=Domain Admins,CN=Users,DC=i,DC=ts,DC=hal,DC=ca,DC=qsft
You could then user awk,sed or cut commands to just get the shortname of the group instead of the full distinguished name.
For Example:
[root@v403h-rh6 etc]# vastool -u host/ attrs gboudreau memberOf | cut -d: -f2 | cut -d, -f1
CN=lgaccess
CN=MCUADMIN
CN=Domain Admins
For more information see the vastool man page
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center