Adding an user to group in AD

I was helping a colleague that has no programming background with a little tool he needs to create to add users to an AD group. The ‘tricky’ part is that he started using VB (.net) and my VB skills is a bit (or a lot) rusty…

So I set out to help him but I hit a little snag with the step of actually adding a user to the group.  I got an exception ‘The server is unwilling to process the request‘ when trying to use the following type of code:

de = new DirectoryEntry(groupDn);
de.Properties[“member”].Add(userDn); //<!– breaks here
de.CommitChanges();
I suspected a security issue but even running this code under raised privileges (admin) does not help. The solution is to rather call the COM add method directly:
de = new DirectoryEntry(groupDn);
de.Invoke(“Add”, New Object() {userDn})
Note: groupDn and userDn must be the full LDAP path to the group and user objects.

Leave a Comment


NOTE - You can use these HTML tags and attributes:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>