Re: Query disabled users and delete their memberof associations

Tech-Archive recommends: Speed Up your PC by fixing your registry



As discussed in other forums, group stuff is a bit trickier than the average. To truly comply to the intent, get the user out of all groups, there really is no way to do a single command line and actually to it unless there is a tool built specifically to hide all of the logic. Personally I would tackle this with a perl script and it would chase group nesting, DLs, cross domain memberships, etc.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Joe Kaplan wrote:
Basically, you can only modify the group's member attribute, so you need to get the DN of each group from memberOf and then go back and modify each of those to remove the user. I'm not sure if you can easily script this with command lines tools. It might be more straightforward to write an ADSI script that does it.

Joe R. might know a slick way to get ADFind/ADModify to do it as a one liner though. :)

Joe K.

.



Relevant Pages

  • Re: Email Password Expire Notifications
    ... I haven't looked at Joe's tool suggestion but most command ... Co-author of "The .NET Developer's Guide to Directory Services ... Joe Richards Microsoft MVP Windows Server Directory Services ... write a script, it will probably be easier for you to use a tool like ...
    (microsoft.public.windows.server.active_directory)
  • Re: jms in toronto
    ... Shortish version of The Famous B5 Joke Script Story: ... Peter and Andreas were on stage and Joe was up next. ...
    (rec.arts.sf.tv.babylon5.moderated)
  • Re: jms in toronto
    ... > Shortish version of The Famous B5 Joke Script Story: ... Peter and Andreas were on stage and Joe was up next. ...
    (rec.arts.sf.tv.babylon5.moderated)
  • Re: Email Password Expire Notifications
    ... Co-author of "The .NET Developer's Guide to Directory Services ... Joe Richards Microsoft MVP Windows Server Directory Services ... write a script, it will probably be easier for you to use a tool like ...
    (microsoft.public.windows.server.active_directory)
  • Re: Email Password Expire Notifications
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... freebie download chapter from the publisher. ... write a script, it will probably be easier for you to use a tool like Joe ... Richard's oldcmp tool than to try to execute the ...
    (microsoft.public.windows.server.active_directory)