Active directory Remove user from Specific groups


hi guys,

in powershell can add ldap search parameters filter this:

$groupfilter = "(&(objectcategory=group)(cn=wholeadgroup))"

but want search on specific part of group name.

like this, cmdlet instead of object:

$groupfilter = get-adgroup -filter {name -like "sccm.*"}

in last case cannot use in adsi command remove.

so has got straight forward solution delete computer object queried group (a group matches word in query)?

kind regards,

andré

hi andré,

give shot, remove computer objects groups filter picks up:

$groups = get-adgroup -filter 'name -like "test group *"'  foreach ($group in $groups) {     $groupmembers = get-adgroupmember $group | { $_.objectclass -eq 'computer' }     remove-adgroupmember -identity $group -members $groupmembers -confirm:$false }

this remove computer objects without prompting. if want prompt before removing object, remove -confirm:$false switch remove-adgroupmember


don't retire technet! - (maybe there's still chance hope, on 11,925+ strong , growing)



Windows Server  >  Windows PowerShell



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client