Re: Remove Security Groups

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Al Dunbar [MS-MVP] (alan-no-drub-spam_at_hotmail.com)
Date: 11/05/04


Date: Fri, 5 Nov 2004 12:04:49 -0700


"Glenn L" <the.only(delete)@gmail.com> wrote in message
news:eU34CrWwEHA.824@TK2MSFTNGP11.phx.gbl...
> It appears you want 1000+ users to loose their group membership and only
be
> a member of the "domain users" group.
> The easiest way to do this is to write a VBS script.
> There is no way to accomplish this using group policies.
>
> You might consider a less popular method (al-be-it more scary), if you
don't
> know scripting.
> This requires at least two domain controllers.
> Move all the users to an isolated OU, and replicate this change around.
> Perform a system state backup on one of the DCs.
> Delete the users OU (obviously do this off hours)
> Replicate this deletion. This will cause the groups forward links to the
> users to be broken.
> Then perform a system state restore, and mark the deleted OU as
> authoritative.
> This brings the users back, but will not recreate the links on the groups.
> The end result is all the users will have only the domain users as their
> group.

OUCH!! Seems a bit drastic, even more so than the most obvious script, which
would likely be time-consuming.

/Al

> The following two articles describe this phenomenon.
> http://support.microsoft.com/kb/q280079/
> http://support.microsoft.com/kb/840001
>
> "D-a-n_L" <djlajoie@hotmail.com> wrote in message
> news:uo3wLzRwEHA.3528@tk2msftngp13.phx.gbl...
> >I could just delete the user an accomplish the same thing, but seriously,
> > what I want to do is leave all the user accts intact and remove the
groups
> > from the accounts either by putting the accts into an AD container and
> > applying a GPO against it or some other method...
> >
> > "Ken B" <none@microsoft.com> wrote in message
> > news:uc2cCQPwEHA.3088@TK2MSFTNGP12.phx.gbl...
> >> If you delete the 'custom' security groups, they will no longer be
> >> members
> >> of the groups.... but you'll also lose the groups.
> >>
> >> Ken
> >>
> >>
> >> "D-a-n_L" <djlajoie@hotmail.com> wrote in message
> >> news:OP5I24OwEHA.3144@TK2MSFTNGP15.phx.gbl...
> >> > How can I, or what would be an efficient method to remove all but the
> >> > default security groups from a 1000+ user accounts. Can I just move
all
> > of
> >> > the accounts to a specific container and apply a policy that will do
> > this
> >> > or
> >> > is there another method that is recommended?
> >> >
> >> >
> >>
> >>
> >
> >
>
>



Relevant Pages

  • Re: Remove Security Groups
    ... > The easiest way to do this is to write a VBS script. ... > Move all the users to an isolated OU, and replicate this change around. ... > Perform a system state backup on one of the DCs. ... >> what I want to do is leave all the user accts intact and remove the ...
    (microsoft.public.scripting.vbscript)
  • Re: HDR questions
    ... Below is shell script I use to setup a replicate in 10. ... want to take a backup while I am setting up the replicate. ... there is also a copy of the production database ...
    (comp.databases.informix)
  • Re: VB Script - Last Logon
    ... I want to send the result from the script to a txt or csv ... shortend the time it takes to replicate this data to all DC's down to ... The whole point of retrieving the lastLogonTimeStamp attribute is so you ... This command creates the ...
    (microsoft.public.vb.general.discussion)
  • Re: Scripting Windows 2008 System State Backup
    ... And then to not even have any documentation or examples of how to script it. ... part of our load we do a system state backup with Windows Backup. ... was quite easy you can schedule it and away you go. ...
    (microsoft.public.windows.server.general)
  • Re: force replication (lastLogonTimestamp)
    ... On July 2, the script disables account_A. ... Because lastLogonTimestamp replicates every 14 days, ... If I could force lastLogonTimestamp to replicate (rather than waiting for ... run the script until 14 days after any accounts have been enabled. ...
    (microsoft.public.windows.server.active_directory)