Bit of fun with extracting SMTP secondary addresses from user account.
$user=get-aduser testuser -prop,proxyAddresses
$user|select samaccountname,@{Name=”AdditionalAddresses”;Expression={($_.proxyAddresses| Foreach-object {$_.split([environment]::NewLine)} | Where-Object {$_ -match “smtp”} | ForEach-Object {$_.substring(5)}) -join "|"}}
so..
#
#Export Detailed AD Membership info
#dump a full member list text file only once per day
#
$outputfile = $savepath + "\" + $dayofweek + "_theuserlist.xlsx"
del $outputfile
$allpandas = get-aduser -filter {extensionattribute5 -eq "Pandas"} -Properties displayname,title,company,department,lastlogondate,physicalDeliveryOfficeName,proxyAddresses,EmailAddress
$allpandas = $allpandas|select samaccountname,givenname,surname,displayname,title,company,department,UserPrincipalName,physicalDeliveryOfficeName,lastlogondate,EmailAddress,@{Name=”AdditionalAddresses”;Expression={($_.proxyAddresses| Foreach-object {$_.split([environment]::NewLine)} | Where-Object {$_ -match “smtp”} | ForEach-Object {$_.substring(5)}) -join "|"}}
$allpandas | C:\scripts\Export-XLSX.ps1 -Path $outputfile -WorkSheetName 'pandas'
Showing posts with label active directory. Show all posts
Showing posts with label active directory. Show all posts
Thursday, April 16, 2015
Monday, March 23, 2015
force a machine password change
nltest.exe /sc_change_pwd:mydomain.corp.mycompany.com
now with more info...
http://blogs.msdn.com/b/sudhakan/archive/2010/01/07/experimenting-with-windows-machine-account-passwords-and-vm-snapshots.aspx
Labels:
active directory,
machine,
machine password reset,
password
Saturday, January 25, 2014
Comparing AD object security
$tango=(Get-Acl "AD:$((Get-ADUser tango).distinguishedname)").access | select identityreference, accesscontroltype $cash=(Get-Acl "AD:$((Get-ADUser cash).distinguishedname)").access | select identityreference, accesscontroltype compare $tango $cashstill couldn't get to root cause of the issue.(automated system cant update account)
Tuesday, October 8, 2013
Quick Audit of Active Directory OUs Users
$splat=$null
$Splat = @()
$95days = (get-date).adddays(-95)
$AlltheOus=Get-ADOrganizationalUnit -filter * -SearchBase "OU=Humans,DC=coolkids,DC=local" -Properties CanonicalName
foreach($OU in $AlltheOus) {
$objectCount=(Get-adobject -Filter * -SearchBase $ou.distinguishedname -searchscope Onelevel|Measure-Object).count
$u=Get-ADUser -filter * -searchbase $ou.distinguishedname -Properties passwordneverexpires,passwordlastset -searchscope Onelevel
$total=($u | measure-object).count
$Enabled=($u | where {$_.Enabled} | Measure-Object).count
$Disabled=$total-$Enabled
$nonExpirePassword=($u | where {$_.passwordneverexpires} | Measure-Object).count
$passwordolder90=($u | where {$_.passwordlastset -lt $95days} | Measure-Object).Count
$Splat += New-Object psobject -Property @{
Name=$ou.CanonicalName;
TotalObjects=$objectCount;
TotalUsers=$Total;
Enabled=$Enabled;
Disabled=$Disabled;
PasswordNonExpire=$nonExpirePassword;
Password90days=$passwordolder90;
OU=$OU.Distinguishedname
}
}
$splat | Select-Object Name,TotalObjects,TotalUsers,Enabled,Disabled,PasswordNonExpire,Password90days,OU | Sort-Object name| export-csv C:\temp\QuickOUAudit.csv -NoTypeInformation -force
Wednesday, August 28, 2013
Powershell Add Users CSV to AD Group
Hi,
Need import a list of users into a group.
Add-groupmember normally has a break down if the user already exists.
so added some checks and balances before adding them.
user account that are written to screen dont exist in AD
Need import a list of users into a group.
Add-groupmember normally has a break down if the user already exists.
so added some checks and balances before adding them.
user account that are written to screen dont exist in AD
#Grab the Users
$lolz = Import-Csv .\users0813.csv
#locate the Group
$group = get-adgroup remoteaccess
#get existing members
$groupmembers = Get-ADGroupMember $group
#go Silent so that can peform the get-aduser without erros
$ErrorActionPreference="SilentlyContinue"
foreach ($user in $lolz) {
#check if user exist in AD
$target=get-aduser $user.'default login'
if (!$target){
# display missing ppls
Write-Host $user.'default login'
} Else {
# check if already a member of the group
If(!($groupmembers.samaccountname -contains $user.'default login')){
#add to group
Add-ADGroupMember $group -Members $user.'default login'
}
}
#set back to null for next persome
$target=$null
}
$ErrorActionPreference="Continue"
Tuesday, April 23, 2013
How to Create Custom Active Directory LDAP Searches
Cool stuff from
http://blogs.msdn.com/b/muaddib/archive/2011/10/24/active-directory-ldap-searches.aspx
Also see the post below on creating queries for individual UserAccountControl flags.
How to use the UserAccountControl flags to manipulate user account properties
http://support.microsoft.com/kb/305144
http://support.microsoft.com/kb/305144
Now on to the queries.
All XP ComputersAlthough this can be done easy enough with the GUI, I wanted to show the syntax so it can be used as a building block for more complex theories. One thing to notice is the query parameter "objectCategory=computer". By including this as part of our query we reduce the number of objects that have to be searched making for a faster query and less performance impact on the DC performing the query.
(&(objectCategory=computer)(operatingSystem=Windows XP*))
(&(objectCategory=computer)(operatingSystem=Windows XP*))
Windows XP Computers with Service Pack 2 Installed(&(objectCategory=computer)(operatingSystem=Windows XP Professional)(operatingSystemServicePack=Service Pack 2))
Windows XP Computers with Service Pack 1 Installed
(&(operatingSystem=Windows XP*l)(operatingSystemServicePack=Service Pack 1)))
(&(operatingSystem=Windows XP*l)(operatingSystemServicePack=Service Pack 1)))
Windows XP Computers with No Service Pack Installed
This one is structured a Little different. Notice the "!" before operating SystemServicePack and the "*". The "!" means NOT so the statement reads "NOT equal to anything" instead of NULL or empty quotes ("") like some other languages.
(&(operatingSystem=Windows XP Professional)(!operatingSystemServicePack=*)))
This one is structured a Little different. Notice the "!" before operating SystemServicePack and the "*". The "!" means NOT so the statement reads "NOT equal to anything" instead of NULL or empty quotes ("") like some other languages.
(&(operatingSystem=Windows XP Professional)(!operatingSystemServicePack=*)))
Windows Server 2003 No Service Pack 1(&((objectCategory=computer))(operatingSystem=Windows Server 2003)(!operatingSystemServicePack=*)))
Windows Server 2003 Service Pack 1 Installed (&(objectCategory=computer)(operatingSystem=Windows Server 2003)(operatingSystemServicePack=Service Pack 1))
Windows 2000 Professional (&(objectCategory=computer)(operatingSystem=Windows 2000 Professional))
Windows 2000 Server (&(objectCategory=computer)(operatingSystem=Windows 2000 Server))
All Windows Server 2003 Servers
(&((objectCategory=computer))(operatingSystem=Windows Server 2003))
(&((objectCategory=computer))(operatingSystem=Windows Server 2003))
SQL Servers (running on Windows 2003) (please verify in your environment)
(&(objectCategory=computer)(servicePrincipalName=MSSQLSvc*)(operatingSystem=Windows Server 2003))
(&(objectCategory=computer)(servicePrincipalName=MSSQLSvc*)(operatingSystem=Windows Server 2003))
SQL Servers any Windows Server OS(&(objectCategory=computer)(servicePrincipalName=MSSQLSvc*)(operatingSystem=Windows Server*))
Windows Vista SP1(&(objectCategory=computer)(operatingSystem=Windows Vista*)(operatingSystemServicePack=Service Pack 1))
Windows Server 2008 Enterprise(&(objectCategory=computer)(operatingSystem=Windows Server® 2008 Enterprise)(operatingSystemServicePack=Service Pack 1))
Windows Server 2008 (all versions)
(&(objectCategory=computer)(operatingSystem=Windows Server® 2008*))
(&(objectCategory=computer)(operatingSystem=Windows Server® 2008*))
Windows Server 2008 R2 Enterprise
(&(objectCategory=computer)(operatingSystem=Windows Server 2008 R2 Enterprise))
(&(objectCategory=computer)(operatingSystem=Windows Server 2008 R2 Enterprise))
Sample User Attribute Query (ExtensionAtrribute5)
(&(objectCategory=user)(&(extensionAttribute5>=20080101)(extensionAttribute5<=20080520)))
(&(objectCategory=user)(&(extensionAttribute5>=20080101)(extensionAttribute5<=20080520)))
WIndows Server 2008 ALL
(&(objectCategory=computer)(operatingSystem=Windows Server 2008*))
(&(objectCategory=computer)(operatingSystem=Windows Server 2008*))
Windows Server 2008 RTM
(&(objectCategory=computer)(operatingSystem=Windows Server 2008 *)(!operatingSystemServicePack=*))
(&(objectCategory=computer)(operatingSystem=Windows Server 2008 *)(!operatingSystemServicePack=*))
Windows Server 2008 SP1
(&(objectCategory=computer)(operatingSystem=Windows Server 2008*)(operatingSystemServicePack=Service Pack 1))
(&(objectCategory=computer)(operatingSystem=Windows Server 2008*)(operatingSystemServicePack=Service Pack 1))
Windows 7 RTM(&(objectCategory=computer)(operatingSystem=Windows 7*)(!operatingSystemServicePack=Service Pack 1))
Windows 7 SP1(&(objectCategory=computer)(operatingSystem=Windows 7*)(operatingSystemServicePack=Service Pack 1))
Monday, March 18, 2013
Build Import of DHCP Reservations - Powershell
Just followed ‘example 2’ - in the powershell command
example http://technet.microsoft.com/en-us/library/jj590686.aspx
Eg
Scopeid,IPAddress,Name,Clientid,Description
10.192.66.0,10.192.66.101,xx_L1_AP01,50-57-AC-9e-b1-26,SW - Gi1/0/47
10.192.66.1,10.192.66.102,xx_L1_AP02,d8-67-AC-95-5a-35,SW - Gi2/0/47
10.192.66.2,10.192.66.115,xx_L3_AP01,d4-8c-AC-04-72-e9,SW - Gi7/39
10.192.66.3,10.192.66.116,xx_L3_AP02,d4-8c-AC-2f-2b-ea,SW - Gi7/40
PS
C:\> Import-Csv
Path Reservations.csv | Add-DhcpServerv4Reservation
-ComputerName koolkids.lc.local
pretty cool.
J
Thursday, August 23, 2012
Powershell - remove user from list of groups
#
# remove user from list of groups
#
#
get-content "C:\app\lols.txt" | % {get-adgroup $_ | remove-adgroupmember -Member dgoodlif -Credential $myadmin -confirm y}
Tuesday, July 10, 2012
Trusted Domain Authentication issues
Intermittently we had servers that were unable to authenticate to the secondary domain - noobs
It seem that when the PDC2 was restarted the problem was fixed. I believe the servers switched to back to using PDC1 or another DC and were happy.
The trust was verified, etc but I think this was done on PDC1, started to annoy me... so had a look around.
On PDC1 there is a noobs.domainname secondary zone
On PDC2 Primary DNS is itself Secondary DNS being PDC1
On pdc2 was unable to resolve noobs.domainname
ping noobs.domainname
Ping request could not find host noobs.domainname
nltest /SC_Verify:noobs.domainname
Flags: 80Trusted DC NameTrusted DC Connection Status Status = 1311 0x51f ERROR_NO_LOGON_SERVERS
Trust Verification Status = 1311 0x51f
ERROR_NO_LOGON_SERVERS
[FIX] On Pdc2 Added a conditional forwarder for noobs.domainname to pdc1
nltest /SC_Verify:noobs.domainname
Flags: b0 HAS_IP HAS_TIMESERV
Trusted DC Name \\ExternalPDC.noobs.domainname
Trusted DC Connection Status Status = 0 0x0 NERR_
SuccessTrust Verification Status = 0 0x0 NERR_Success
It seem that when the PDC2 was restarted the problem was fixed. I believe the servers switched to back to using PDC1 or another DC and were happy.
The trust was verified, etc but I think this was done on PDC1, started to annoy me... so had a look around.
On PDC1 there is a noobs.domainname secondary zone
On PDC2 Primary DNS is itself Secondary DNS being PDC1
On pdc2 was unable to resolve noobs.domainname
ping noobs.domainname
Ping request could not find host noobs.domainname
nltest /SC_Verify:noobs.domainname
Flags: 80Trusted DC NameTrusted DC Connection Status Status = 1311 0x51f ERROR_NO_LOGON_SERVERS
Trust Verification Status = 1311 0x51f
ERROR_NO_LOGON_SERVERS
[FIX] On Pdc2 Added a conditional forwarder for noobs.domainname to pdc1
nltest /SC_Verify:noobs.domainname
Flags: b0 HAS_IP HAS_TIMESERV
Trusted DC Name \\ExternalPDC.noobs.domainname
Trusted DC Connection Status Status = 0 0x0 NERR_
SuccessTrust Verification Status = 0 0x0 NERR_Success
Labels:
active directory,
DNS,
domain trust,
sites and services,
solved,
tactical fix
Friday, June 29, 2012
Machine Password
Text file with list of servers - WindowsServers.txt
Grab the data
Grab the data
$CAITInfo = Get-Content .\CAITWindowsServers.txt | Foreach {get-adcomputer
$_ -properties PasswordLastSet}
Filter and display
$CAITInfo | Sort-Object -descending PasswordLastSet | FT -property
DNSHostname,PasswordLastSet
Grab Older than 30 days... which means either problem? or machine password not updating..
$CAITInfo | Sort-Object -descending PasswordLastSet|Where {
$_.PasswordLastSet -lt (Get-Date).AddDays(-30)} |
FT -property DNSHostname,PasswordLastSet
To force a PC\server to reset machine password to AD (where not a DC)
nltest.exe
/sc_change_pwd:lc.local
wonder if I can do that via powershell :)
Tuesday, April 3, 2012
Powershell : Active Directory user update and rename in 1 line
# tested and used on powershell v3
# 1 Grab username\password
# 2 Grab all users without admin in the name
# 3 For each user
# a Modify display name to include (admin)
# b Rename AD object to include (admin)
#
#It’s setup to run in a single line because I can
#
expanded
#get the admin passwords
# 1 Grab username\password
# 2 Grab all users without admin in the name
# 3 For each user
# a Modify display name to include (admin)
# b Rename AD object to include (admin)
#
#It’s setup to run in a single line because I can
#
$ninja=Get-Credential
; get-aduser -filter
'name -notlike "*Admin*"' -searchbase 'OU=Security - Administrator Accounts,DC=Coolkids,DC=local' -Properties DistinguishedName
| %{set-aduser -credential $ninja
$_ -displayname
($_.name
+ "
(Admin)"); rename-ADObject $_.DistinguishedName
-credential
$ninja -NewName
($_.name
+ "
(Admin)")}
expanded
#get the admin passwords
$ninja=Get-Credential
#
get-aduser -filter 'name -notlike "*Admin*"' -searchbase 'OU=Security - Administrator Accounts,DC=Coolkids,DC=local' -Properties DistinguishedName | %{set-aduser -credential $ninja $_ -displayname ($_.name + " (Admin)"); rename-ADObject $_.DistinguishedName -credential $ninja -NewName ($_.name + " (Admin)")}
#
get-aduser -filter 'name -notlike "*Admin*"' -searchbase 'OU=Security - Administrator Accounts,DC=Coolkids,DC=local' -Properties DistinguishedName | %{set-aduser -credential $ninja $_ -displayname ($_.name + " (Admin)"); rename-ADObject $_.DistinguishedName -credential $ninja -NewName ($_.name + " (Admin)")}
Thursday, December 22, 2011
Update teh Active Directory terminal Session Properties
Set objParent = GetObject("ldap://OU=Level/ 02,OU=Security - Administrator Accounts,DC=XenWorld")
objparent.Filter = Array("user")
for each objUser in objParent
Wscript.Echo "Modifying|" & objUser.Get("CN")
'SESSIONS ATTRIBUTES
objUser.MaxDisconnectionTime = 2880 'In Minutes
objUser.MaxIdleTime = 2880 'In Minutes
objUser.MaxConnectionTime= 0 'active connections okay
objUser.BrokenconnectionAction = 0 '0=Disconnect, 1=End
objUser.SetInfo
next
Details on more properties:
http://www.virtualizationadmin.com/articles-tutorials/terminal-services/scripting/scripting-server-based-computing-terminal-services-attributes-active-directory-user-objects.html
objparent.Filter = Array("user")
for each objUser in objParent
Wscript.Echo "Modifying|" & objUser.Get("CN")
'SESSIONS ATTRIBUTES
objUser.MaxDisconnectionTime = 2880 'In Minutes
objUser.MaxIdleTime = 2880 'In Minutes
objUser.MaxConnectionTime= 0 'active connections okay
objUser.BrokenconnectionAction = 0 '0=Disconnect, 1=End
objUser.SetInfo
next
Details on more properties:
http://www.virtualizationadmin.com/articles-tutorials/terminal-services/scripting/scripting-server-based-computing-terminal-services-attributes-active-directory-user-objects.html
Tuesday, December 20, 2011
Extract Details about your Site Links
Import-Module ActiveDirectory
$ConfigPath = (Get-ADRootDSE).configurationNamingContext
Get-ADObject -Filter 'ObjectClass -eq "siteLink"' -SearchBase $ConfigPath -Properties * | Format-Table Name, replInterval, cost, siteList -AutoSize
From:
http://blogs.technet.com/b/ashleymcglone/archive/2010/10/06/powershell-to-automatically-create-all-ad-hub-to-spoke-site-links.aspx
Bonus Link
http://blogs.technet.com/b/ashleymcglone/archive/2011/06/29/report-and-edit-ad-site-links-from-powershell-turbo-your-ad-replication.aspx
$ConfigPath = (Get-ADRootDSE).configurationNamingContext
Get-ADObject -Filter 'ObjectClass -eq "siteLink"' -SearchBase $ConfigPath -Properties * | Format-Table Name, replInterval, cost, siteList -AutoSize
From:
http://blogs.technet.com/b/ashleymcglone/archive/2010/10/06/powershell-to-automatically-create-all-ad-hub-to-spoke-site-links.aspx
Bonus Link
http://blogs.technet.com/b/ashleymcglone/archive/2011/06/29/report-and-edit-ad-site-links-from-powershell-turbo-your-ad-replication.aspx
Labels:
active directory,
sites and services,
techblog
Cool Script to dump Sites and Services
[System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest().Sites | select name, @{n='subnets';e={$_.subnets | select -expand name}}, @{n='servers';e={$_.Servers | select -expand name}}, @{n='sitelink';e={$_.sitelinks | select -expand name}} | export-csv c:\temp\sites.csv
from
http://www.powershellcommunity.org/Forums/tabid/54/aft/6321/Default.aspx
from
http://www.powershellcommunity.org/Forums/tabid/54/aft/6321/Default.aspx
Thursday, June 30, 2011
Splunk AD Filtering
...\splunk\etc\system\local
## props.conf
[WMI:WinEventLog:Security]
TRANSFORMS-evtlog = wmi-null,wmi-filter,wmi-filter28user,wmi-filter28SecGrp,wmi-filter28DlGrp
## transforms.conf
[wmi-null]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[wmi-filter]
REGEX=(?msi)^(CategoryString=Account Management)
DEST_KEY = queue
FORMAT = indexQueue
[wmi-filter28user]
REGEX=(?msi)^(CategoryString=User Account Management)
DEST_KEY = queue
FORMAT = indexQueue
[wmi-filter28SecGrp]
REGEX=(?msi)^(CategoryString=Security Group Management)
DEST_KEY = queue
FORMAT = indexQueue
[wmi-filter28DlGrp]
REGEX=(?msi)^(CategoryString=Distribution Group Management)
DEST_KEY = queue
FORMAT = indexQueue
Subscribe to:
Posts (Atom)