Active Directory

Active Directory Search Limit

How do I modify the number of Active Directory objects to search?

By default, the Windows 2000 Active Directory searches 10,000 objects at a time. This policy affects all browse displays associated with AD, the Microsoft Management Console (MMC) Active Directory Users and Computers snap-in, and the dialog boxes you use to set permissions for user or group objects in AD. As your organization grows, you might need to change the number of objects to search.

Sponsored Content

Passwords Haven’t Disappeared Yet

123456. Qwerty. Iloveyou. No, these are not exercises for people who are brand new to typing. Shockingly, they are among the most common passwords that end users choose in 2021. Research has found that the average business user must manually type out, or copy/paste, the credentials to 154 websites per month. We repeatedly got one question that surprised us: “Why would I ever trust a third party with control of my network?

To set the number for a group policy object:

  1. Start the MMC Active Directory Users and Computers snap-in.
  2. Right-click the container, and select Properties.
  3. Select the Group Policy tab.
  4. Select the Group Policy Object, and select Edit.
  5. Select the User Configuration branch, and expand Administrative Templates > Desktop > Active Directory.
  6. Double-click Maximum size of Active Directory searches.
  7. Select Enabled, and set the number (e.g., 20000).
  8. Click Apply.
  9. Click OK.
  10. Close the Group Policy Editor.

To edit the registry to set the number for a user:

  1. Start regedit.
  2. Go to the
HKEY_CURRENT_USER\Software\Policies\Microsoft

registry entry.

  1. From the Edit menu, select New > Key.
  2. Enter
​Windows
  1. Select the new Windows key, and from the Edit menu, select New, Key.
  2. Enter
​Directory UI
  1. Go to the Directory UI key, and from the Edit menu, select New, DWORD Value.
  2. Enter
​QueryLimit

and press Enter.

  1. Double-click the new value, and set the decimal value (i.e. 20000).
  2. Click OK.
  3. Close the registry editor.

For both methods, the change will take effect when the user logs on the next time.

Note: Original tip can be found HERE

Related Topics:

BECOME A PETRI MEMBER:

Don't have a login but want to join the conversation? Sign up for a Petri Account

Register
Comments (0)

Leave a Reply