ldapsearch -x -h <DC IP Address> -b "<Base DN>" -D "<user@fqdn>" -W -s sub "(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=8192))" | grep distinguishedname -i
ldapsearch -x -h <DC IP Address> -b "<Base DN>" -D "<user@fqdn>" -W -s sub '(&(objectCategory=person)(objectClass=user))' | grep "cn:\|description:"
ldapsearch -x -h <DC IP Address> -b "<Base DN>" -D "<user@fqdn>" -W -s sub '(&(objectCategory=user)(memberOf=cn=Domain Admins,cn=Users,dc=ad,dc=test,dc=local))' | grep "distinguishedName:"
ldapsearch -x -h <DC IP Address> -b "<Base DN>" -D "<user@fqdn>" -W -s sub "(objectCategory=computer)" | grep -E "distinguishedname.*server" -i
There are two ways this default functionality can be disabled. First, it can be disabled by changing the default ms-DS-MachineAccountQuota value at the domain to 0 from 10.
ldapsearch -x -h <DC IP Address> -b <Base DN>" -D "<user@fqdn>" -W -s sub "(objectclass=domain)" | grep "ms-ds-machineaccountquota" -i
ldapsearch -x -h <DC IP Address> -b <Base DN>" -D "<user@fqdn>" -W -s sub "(servicePrincipalName=*)"