---
title: "Managing Active Directory Groups with PowerShell: The Ultimate Guide"
description: "Learn how to manage Active Directory groups with PowerShell! This hands-on guide shows you how to query, create and modify AD groups using practical real-world examples."
canonical: "https://adamtheautomator.com/powershell-ad-groups-guide/"
---

# Managing Active Directory Groups with PowerShell: The Ultimate Guide

> Learn how to manage Active Directory groups with PowerShell! This hands-on guide shows you how to query, create and modify AD groups using practical real-world examples.

Source: https://adamtheautomator.com/powershell-ad-groups-guide/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![Managing Active Directory Groups with PowerShell: The Ultimate Guide](https://adamtheautomator.com/wp-content/uploads/2024/11/image-23.png)

# Managing Active Directory Groups with PowerShell: The Ultimate Guide

[![](https://secure.gravatar.com/avatar/d0b9d42e21e5622713f8b693aa5c0f9244d5f7dd200ed29b8398f52dee5de337?s=192&d=mm&r=g)Adam Bertram](https://adamtheautomator.com/author/adam-bertram/)4 November 20243 min. read

Categories: [IT Ops](/category/it-ops/)

Tags:[Active Directory](/tag/active-directory/)[PowerShell](/tag/powershell/)

Table of Contents

*   [Prerequisites](#prerequisites)
*   [Querying AD Groups with PowerShell](#querying-ad-groups-with-powershell)
*   [Finding Groups by Name](#finding-groups-by-name)
*   [Filtering by Group Type](#filtering-by-group-type)
*   [Searching in Specific OUs](#searching-in-specific-ous)
*   [Finding Recently Created Groups](#finding-recently-created-groups)
*   [Creating New AD Groups](#creating-new-ad-groups)
*   [Creating a Security Group](#creating-a-security-group)
*   [Creating a Distribution Group](#creating-a-distribution-group)
*   [Creating Multiple Groups at Once](#creating-multiple-groups-at-once)
*   [Modifying Existing Groups](#modifying-existing-groups)
*   [Renaming Groups](#renaming-groups)
*   [Updating Group Descriptions](#updating-group-descriptions)
*   [Changing Group Scope](#changing-group-scope)
*   [Pro Tips](#pro-tips)
*   [Summary](#summary)

As a Windows system administrator, managing Active Directory (AD) groups is probably something you do every day. While you _could_ use the Active Directory Users and Computers (ADUC) MMC snap-in, what happens when you need to manage groups across multiple domains or automate group management tasks? That’s where PowerShell comes in handy. In this hands-on tutorial, you’re going to learn how to use PowerShell to manage AD groups like a pro. You’ll learn how to query groups, create new ones, and modify existing groups using practical real-world examples.

#### Prerequisites

If you’d like to follow along with this tutorial, be sure you have the following prerequisites in place:

*   A Windows computer (Windows 10/11 or Windows Server) joined to an Active Directory domain
    
*   The [PowerShell Active Directory module](https://adamtheautomator.com/install-powershell-active-directory-module/) installed
    
*   A user account with permissions to manage AD groups
    

#### Querying AD Groups with PowerShell

Let’s start with a common scenario – you’re the new IT admin at a company and need to audit the AD group structure. Your manager wants to know what groups exist across different departments. The `Get-ADGroup` cmdlet will be your best friend here.

Active Directory group management gets easier when the PowerShell and directory-service fundamentals are fresh. If you want a structured path before applying this in production, [compare Active Directory and PowerShell courses on Udemy](https://trk.udemy.com/c/1454808/3193860/39854) before you buy.

## Finding Groups by Name

Perhaps the simplest task is finding groups containing specific text in their name. For example, to find all groups with “Sales” in the name:

```
Get-ADGroup -Filter 'Name -like "Sales"'
```

The asterisks (\*) are wildcards, matching any characters before or after “Sales”. This command will return all groups that have “Sales” anywhere in their name.

## Filtering by Group Type

Maybe you only want to see security groups (not distribution groups). You can add additional filter criteria using the `-and` operator:

```
Get-ADGroup -Filter 'Name -like "Sales" -and GroupCategory -eq "Security"'
```

Now you’ll only see security groups that have “Sales” in their name.

## Searching in Specific OUs

Need to find groups in a particular organizational unit (OU)? Use the `SearchBase` parameter:

```
Get-ADGroup -Filter * -SearchBase 'OU=Engineering,DC=company,DC=local'
```

This command finds all groups within the Engineering OU and its child OUs.

## Finding Recently Created Groups

Want to see which groups were created after a certain date? Filter on the `whenCreated` attribute:

```
Get-ADGroup -Filter 'whenCreated -ge "2023-01-01"'
```

This returns all groups created on or after January 1st, 2023.

## Creating New AD Groups

Now let’s look at creating new groups. Maybe your company is restructuring and you need to create groups for new departments.

## Creating a Security Group

Here’s how to create a new security group for IT support staff:

```
New-ADGroup -Name "IT_Support" `
            -GroupScope Global `
            -GroupCategory Security `
            -Description "Group for IT support staff" `
            -Path "OU=IT,DC=company,DC=local"
```

This creates a global security group called “IT\_Support” in the IT organizational unit.

## Creating a Distribution Group

Need an email distribution group? Just change a few parameters:

```
New-ADGroup -Name "Marketing_News" `
            -GroupScope DomainLocal `
            -GroupCategory Distribution `
            -Description "Group for receiving marketing updates" `
            -Path "OU=Marketing,DC=company,DC=local"
```

#### Creating Multiple Groups at Once

Got multiple similar groups to create? Use a loop:

```
$regions = "North", "South", "East", "West"
foreach ($region in $regions) {
    New-ADGroup -Name "Sales_$region" `
                -GroupScope Global `
                -GroupCategory Security `
                -Description "Sales team for $region region" `
                -Path "OU=Sales,DC=company,DC=local"
}
```

#### Modifying Existing Groups

Things change in organizations. Groups need to be renamed, descriptions updated, and scopes modified. Let’s see how to handle these tasks.

## Renaming Groups

To rename a group, you’ll need to change both its name and samAccountName:

```
# First rename the group object
Get-ADGroup EngineeringTeam | Rename-ADObject -NewName TechTeam

# Then update the samAccountName
Get-ADGroup EngineeringTeam | Set-ADGroup -SamAccountName TechTeam
```

## Updating Group Descriptions

Need to update a group’s description? One line with `Set-ADGroup`:

```
Get-ADGroup TechTeam | Set-ADGroup -Description 'Technical Team for Engineering Projects'
```

## Changing Group Scope

If you need to change a group’s scope (like from Global to Universal):

```
Get-ADGroup TechTeam | Set-ADGroup -GroupScope Universal
```

## Pro Tips

Here are some tips to make your AD group management even more efficient:

1.  1.  Always use \`-Filter\` instead of \`-Identity\` when querying multiple groups – it’s more efficient
    2.  Remember that group scope can’t be changed if the group has members – remove members first
    3.  Use the \`-WhatIf\` parameter when making changes to preview what would happen
    4.  Always test your group changes in a non-production environment first

## Summary

You should now have a solid foundation for managing AD groups with PowerShell. While the Active Directory Users and Computers snap-in is great for one-off tasks, PowerShell gives you the power to automate and manage groups at scale. Remember – the examples shown here are just the beginning. PowerShell’s AD cmdlets are incredibly powerful and flexible. As you become more comfortable with these basics, you can build more complex solutions to match your organization’s needs. Need to learn more about Active Directory PowerShell? Check out our other tutorials:

*   *   [How to Install the PowerShell Active Directory Module](https://adamtheautomator.com/install-powershell-active-directory-module/)
*   *   [Managing Active Directory Users with PowerShell](https://adamtheautomator.com/new-aduser)
*   *   [PowerShell Active Directory Reporting](https://adamtheautomator.com/powershell-active-directory-reporting/)

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Fpowershell-ad-groups-guide%2F&text=Managing%20Active%20Directory%20Groups%20with%20PowerShell%3A%20The%20Ultimate%20Guide)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Fpowershell-ad-groups-guide%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Fpowershell-ad-groups-guide%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/2019/08/database-152091_1280.png)

### [Active Directory Database: PowerShell Monitoring Made Easy](/active-directory-database/)

Find the ntds.dit location and monitor your Active Directory database using PowerShell.

![](https://adamtheautomator.com/wp-content/uploads/2019/07/panic-1393619_1280.png)

### [How to Find Locked Out Users in Active Directory with PowerShell](/find-locked-out-users-in-active-directory-powershell/)

See what we can do to find locked out users in Active Directory with PowerShell!

![](https://adamtheautomator.com/wp-content/uploads/2019/08/darknet-3588402_1280.jpg)

### [Master your LDAP Filters in PowerShell while Learning AD](/ldap-filter/)

Learning how to use LDAP filter, how to filter with the Active Directory PowerShell cmdlets, and learn the right way to filter AD objects.

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
