Maximum size of Active Directory searches
Jump to overview

Policy overview

Key metadata and intent for this policy.

User
Category
Desktop > Active Directory
Supported on
At least Windows 2000

Supported OS tags: Windows10, Windows10RT, Windows11, Windows2000, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2003, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016, WindowsVista, WindowsXP

Specifies the maximum number of objects the system displays in response to a command to browse or search Active Directory. This setting affects all browse displays associated with Active Directory, such as those in Local Users and Groups, Active Directory Users and Computers, and dialog boxes used to set permissions for user or group objects in Active Directory. If you enable this setting, you can use the "Number of objects returned" box to limit returns from an Active Directory search. If you disable this setting or do not configure it, the system displays up to 10,000 objects. This consumes approximately 2 MB of memory or disk space. This setting is designed to protect the network and the domain controller from the effect of expansive searches.

Internal name
AD_QueryLimit
Policy ID
d7b6a781f715
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
User
Number of objects returned:
ID AD_QueryLimit_Box
decimal
Path
Software\Policies\Microsoft\Windows\Directory UI
Value name
QueryLimit
Type
REG_DWORD
Range: ? to 4000000000
Number of objects returned:
User · Type decimal
Registry mapping
Path
Software\Policies\Microsoft\Windows\Directory UI
Value name
QueryLimit
Type
REG_DWORD
Details
Range: ? to 4000000000