| File | Description |
|---|---|
| AD_Group_Membership_Comparison_Tool_Report.pdf | Hands-on walkthrough with screenshots |
| Compare-ADGroupMemberships.ps1 | PowerShell automation script — ready to use |
This PowerShell automation was built to eliminate a repetitive IT support task — manually comparing Active Directory group memberships between two users across multiple domains.
In enterprise environments, checking what groups a user belongs to and how that differs from another user is a daily task for IT support and service desk teams. Doing this manually in Active Directory Users and Computers is slow, error prone, and gives no visibility into group descriptions or canonical paths.
This automation replaces that manual process — a WPF GUI takes two usernames, queries AD across configured domains, compares group memberships, and exports the results to a formatted Excel file in one click.
The manual process before automation:
- Open Active Directory Users and Computers
- Search for User 1, open properties, go to Member Of tab, write down groups
- Repeat for User 2
- Manually compare the two lists
- Manually copy results to Excel
After automation:
- Type two usernames → click Compare → click Export to Excel
- Done in seconds
Open the script and update the domain section at the top:
$domainServers = @(
"example1.com", # Replace with your primary domain
"example2.com", # Replace with your secondary domain
"example3.com" # Add or remove domains as needed
)Replace example1.com and example2.com with your organisation's domain names. Add or remove lines as needed.
- PowerShell 5.1+
- WPF — Windows Presentation Foundation (XAML)
- ActiveDirectory PowerShell Module (RSAT)
- ImportExcel PowerShell Module (auto-installed on first run)
- Get-ADUser / Get-ADGroup
- PSCustomObject · Add-Member
- WPF DataGrid · Event-Driven Programming
| Step | What Happens |
|---|---|
| 1 — Input | Enter two AD usernames in the GUI and click Compare |
| 2 — Query | Script queries each configured domain using Get-ADUser with MemberOf property |
| 3 — Details | For each group, retrieves Name, Description, Notes (info field), and CanonicalName via Get-ADGroup |
| 4 — Compare | Uses PowerShell -notin and -in operators to categorise every group |
| 5 — Display | Results appear in a sortable WPF DataGrid |
| 6 — Export | Click Export to Excel — formatted .xlsx saved to Desktop instantly |
| Column | Description |
|---|---|
| GroupName | Common name of the AD security group |
| Description | Group description from AD |
| Notes | Content of the AD info field |
| CanonicalName | Full canonical path showing domain and OU |
| Status | Only in User1 · Only in User2 · Both |
The exported file is automatically named from the two usernames:
ADGroupComparison_john.smith_vs_mary.jones.xlsx
Features:
- AutoSize — all columns sized to fit content
- BoldTopRow — header row is bold
- FreezeTopRow — header stays visible when scrolling
- Saved directly to the Desktop
Prerequisites:
- Windows machine with PowerShell 5.1 or later
- RSAT Active Directory module installed
- Network access to configured domain controllers
- Read access to AD — standard domain user is sufficient
Steps:
- Edit
$domainServersat the top of the script with your domain names - Open PowerShell
- Run
.\\Compare-ADGroupMemberships.ps1 - Enter User 1 and User 2 usernames
- Click Compare
- Click Export to Excel
IT Support & Service Desk:
- User missing access — compare against a colleague who has access to find the missing group
- New starter setup — compare against a reference user to confirm group memberships are complete
- Offboarding — document all group memberships before account deletion
System Administration:
- Identify differences between accounts in the same role
- Audit privileged accounts for unexpected group memberships
- Troubleshoot permission issues between users who should have identical access
Security & Compliance:
- Access review documentation — export to Excel for audit evidence
- Identify privilege creep — find groups a user has that they should not
- Cross-domain access comparison in multi-domain environments
- PowerShell Scripting & Automation
- WPF GUI Development (XAML)
- Active Directory Module (Get-ADUser · Get-ADGroup)
- Multi-Domain AD Querying
- Distinguished Name Parsing
- PSCustomObject & Add-Member
- Excel Export via ImportExcel
- Error Handling (try/catch)
- Event-Driven Programming
- IT Support Automation
- Access Review Documentation
Identified a repetitive manual IT support task and automated it end to end using PowerShell. The WPF GUI makes it accessible to any IT team member without PowerShell knowledge, while the Excel export provides instant audit-ready documentation. Demonstrates practical scripting ability applied to a real workplace problem.
Part of the Bikash Security Lab series:
📄 Thanks for reading! For a full hands-on walkthrough of this automation with screenshots — download the report here
⭐ If you find this useful, feel free to star the repository ⭐