Desktop Functions:

   Smart Device Functions:

Show Recent Changes
Subscribe (RSS)
Misc. Pages
Helpful Tools
Suggested Reading
Website TODO List
Support Forum
Download Visual Studio Add-In

Terms of Use
Privacy Policy
dscracknames (ntdsapi)
The DsCrackNames function converts an array of directory service object names from one format to another. Name conversion enables client applications to map between the multiple names used to identify various directory service objects. For example, user objects can be identified by SAM account names (domain\username), user principal name (, or distinguished name.

C# Signature:

[DllImport("ntdsapi.dll", CharSet=CharSet.Auto, SetLastError = false)]
static public extern uint DsCrackNames(
      IntPtr hDS,
      DS_NAME_FLAGS flags,
      DS_NAME_FORMAT formatOffered,
      DS_NAME_FORMAT formatDesired,
      uint cNames,
    [MarshalAs(UnmanagedType.LPArray, ArraySubType = UnmanagedType.LPWStr, SizeParamIndex = 4)]
        string[] rpNames,      
      string[] rpNames,
      out IntPtr ppResult  // PDS_NAME_RESULT

VB Signature:

    <DllImport("ntdsapi.dll")> _
    Public Shared Function DsCrackNames(ByVal hDS As IntPtr, _
        ByVal flags As DS_NAME_FLAGS, _
        ByVal formatOffered As DS_NAME_FORMAT, _
        ByVal formatDesired As DS_NAME_FORMAT, _
        ByVal cNames As UInt32, _
        <MarshalAs(UnmanagedType.LPArray, ArraySubType:=UnmanagedType.LPWStr, SizeParamIndex:=4)> ByVal rpNames As String(), _
        ByRef ppResult As IntPtr) As Object
    End Function

User-Defined Types:



The success of the name conversion request depends on where the client is bound. Clients bind to specific instances of the directory service using some variant of DsBind. If bound to a global catalog, the scope of the name mapping is the entire forest. If not bound to a global catalog, the scope of the name mapping is the domain not covered by a global catalog for that domain controller. If not bound to a global catalog and a name is not found, but the input name unambiguously identifies its domain and this domain is in the forest, then the return data identifies the DNS domain name for the domain of interest. Clients are expected to use this data to bind to the correct domain controller or global catalog and call DsCrackNames again with the new bind handle.

The return value from DsCrackNames indicates errors such as invalid parameters or insufficient memory. However, problems in converting individual names are reported in the status member of the DS_NAME_RESULT_ITEM structure returned for each input name.

Note Do not confuse the values of the format elements of the formatOffered parameter used by the DsCrackNames function with the similarly named format elements as defined in the ADS_NAME_TYPE_ENUM enumeration used by the IADsNameTranslate interface. The two sets of element formats are not equivalent and are not interchangeable.

Tips & Tricks:

Please add some!

Sample Code:

using System;
using System.Runtime.InteropServices;
using System.Text;

namespace test
  class Class1
    const uint NO_ERROR = 0;
    [DllImport("ntdsapi.dll", CharSet=CharSet.Auto)]
    static public extern uint DsCrackNames(
      IntPtr hDS,
      DS_NAME_FLAGS flags,
      DS_NAME_FORMAT formatOffered,
      DS_NAME_FORMAT formatDesired,
      uint cNames,
      string[] rpNames,
      out IntPtr ppResult  // PDS_NAME_RESULT

    [DllImport("ntdsapi.dll", CharSet=CharSet.Auto)]
    static public extern void DsFreeNameResult(IntPtr pResult /* DS_NAME_RESULT* */);

    public enum DS_NAME_ERROR
      DS_NAME_NO_ERROR = 0,

      // Generic processing error.

      // Couldn't find the name at all - or perhaps caller doesn't have
      // rights to see it.

      // Input name mapped to more than one output name.

      // Input name found, but not the associated output format.
      // Can happen if object doesn't have all the required attributes.

      // Unable to resolve entire name, but was able to determine which
      // domain object resides in.  Thus DS_NAME_RESULT_ITEM?.pDomain
      // is valid on return.

      // Unable to perform a purely syntactical mapping at the client
      // without going out on the wire.

      // The name is from an external trusted forest.


      public enum DS_NAME_FLAGS
      DS_NAME_NO_FLAGS = 0x0,

      // Perform a syntactical mapping at the client (if possible) without
      // going out on the wire.  Returns DS_NAME_ERROR_NO_SYNTACTICAL_MAPPING
      // if a purely syntactical mapping is not possible.

      // Force a trip to the DC for evaluation, even if this could be
      // locally cracked syntactically.
      DS_NAME_FLAG_EVAL_AT_DC = 0x2,

      // The call fails if the DC is not a GC

      // Enable cross forest trust referral


    public enum DS_NAME_FORMAT
      // unknown name type
      DS_UNKNOWN_NAME = 0,

      // eg: CN=User Name,OU=Users,DC=Example,DC=Microsoft,DC=Com
      DS_FQDN_1779_NAME = 1,

      // eg: Example\UserN
      // Domain-only version includes trailing '\\'.
      DS_NT4_ACCOUNT_NAME = 2,

      // Probably "User Name" but could be something else.  I.e. The
      // display name is not necessarily the defining RDN.
      DS_DISPLAY_NAME = 3,

      // obsolete - see #define later

      // obsolete - see #define later

      // String-ized GUID as returned by IIDFromString().
      // eg: {4fa050f0-f561-11cf-bdd9-00aa003a77b6}
      DS_UNIQUE_ID_NAME = 6,

      // eg: name
      // Domain-only version includes trailing '/'.

      // eg:

      // Same as DS_CANONICAL_NAME except that rightmost '/' is
      // replaced with '\n' - even in domain-only case.
      // eg:\nuser name

      // eg: www/ - generalized service principal
      // names.

      // This is the string representation of a SID.  Invalid for formatDesired.
      // See sddl.h for SID binary <--> text conversion routines.
      // eg: S-1-5-21-397955417-626881126-188441444-501

      // Pseudo-name format so GetUserNameEx can return the DNS domain name to
      // a caller.  This level is not supported by the DS APIs.

    [ StructLayout( LayoutKind.Sequential, CharSet=CharSet.Auto )]
      public struct DS_NAME_RESULT_ITEM
      public DS_NAME_ERROR status;
      public string pDomain;
      public string pName;

    [DllImport("ntdsapi.dll", CharSet=CharSet.Auto)]
    static public extern uint DsBind(
      string DomainControllerName,      // in, optional
      string DnsDomainName,         // in, optional
      out IntPtr phDS);

    [DllImport("ntdsapi.dll", CharSet=CharSet.Auto)]
    static public extern uint DsUnBind(ref IntPtr phDS);

    [ StructLayout( LayoutKind.Sequential, CharSet=CharSet.Auto )]
      public struct DS_NAME_RESULT
      public uint cItems;
      public IntPtr rItems; // PDS_NAME_RESULT_ITEM

    static void Main(string[] args)
      // Bind to default global catalog
      IntPtr hDS;
      uint err = DsBind(null,null,out hDS);
      if (err != NO_ERROR)
    Console.WriteLine("Error on DsBind : {0}",err);
      // Crack the currently logged on name
    string[] names = new string[]{System.Security.Principal.WindowsIdentity.GetCurrent().Name};
    DS_NAME_RESULT_ITEM[] results =
    foreach (DS_NAME_RESULT_ITEM result in results)
      Console.WriteLine("Result : {0}\r\nDomain : {1}\r\nName : {2}",result.status,result.pDomain,result.pName);
    DsUnBind(ref hDS);

    /// <summary>
    /// A wrapper function for the DsCrackNames OS call
    /// </summary>
    /// <param name="hDS">DsBind handle</param>
    /// <param name="flags">Flags controlling the process</param>
    /// <param name="formatOffered">Format of the names</param>
    /// <param name="formatDesired">Desired format for the names</param>
    /// <param name="names">The names to crack</param>
    /// <returns>The crack result</returns>
    public static DS_NAME_RESULT_ITEM[] HandleDsCrackNames(IntPtr hDS,DS_NAME_FLAGS flags,DS_NAME_FORMAT formatOffered,DS_NAME_FORMAT formatDesired,string[] names)
      IntPtr pResult;
      DS_NAME_RESULT_ITEM[] ResultArray;
      uint err = DsCrackNames(
    (uint)((names == null) ? 0 : names.Length),
    out pResult);
      if (err != NO_ERROR)
    throw new System.ComponentModel.Win32Exception((int)err);
    // Next convert the returned structure to managed environment
    Result.cItems = (uint)Marshal.ReadInt32(pResult);
    Result.rItems = Marshal.ReadIntPtr(pResult, Marshal.OffsetOf(typeof(DS_NAME_RESULT), "rItems").ToInt32());
    IntPtr curptr = Result.rItems;
    ResultArray = new DS_NAME_RESULT_ITEM[Result.cItems];
    for (int index = 0; index < (int)Result.cItems; index++)
      ResultArray[index] = (DS_NAME_RESULT_ITEM)Marshal.PtrToStructure(curptr,typeof(DS_NAME_RESULT_ITEM));
      curptr = (IntPtr)((int)curptr + Marshal.SizeOf(ResultArray[index]));
      return ResultArray;

Alternative Managed API:

Do you know one? Please contribute it!


Please edit this page!

Do you have...

  • helpful tips or sample code to share for using this API in managed code?
  • corrections to the existing content?
  • variations of the signature you want to share?
  • additional languages you want to include?

Select "Edit This Page" on the right hand toolbar and edit it! Or add new pages containing supporting types needed for this API (structures, delegates, and more).

Access directly from VS:
Terms of Use
Edit This Page
Find References
Show Printable Version