diff --git a/Healthcheck/HealthcheckAnalyzer.cs b/Healthcheck/HealthcheckAnalyzer.cs index f71168e..966ac5c 100644 --- a/Healthcheck/HealthcheckAnalyzer.cs +++ b/Healthcheck/HealthcheckAnalyzer.cs @@ -1159,7 +1159,7 @@ private void GeneratePrivilegedGroupData(ADDomainInfo domainInfo, ADWebService a dnsAdminFound = true; }; // we do a one level search just case the group is in the default position - adws.Enumerate(domainInfo.DefaultNamingContext, "(&(objectClass=group)(description=DNS Administrators Group))", properties, callback, "OneLevel"); + adws.Enumerate("CN=Users," + domainInfo.DefaultNamingContext, "(&(objectClass=group)(description=DNS Administrators Group))", properties, callback, "OneLevel"); if (!dnsAdminFound) { // then full tree. This is an optimization for LDAP request