Active directory Remove user from Specific groups
hi guys,
in powershell can add ldap search parameters filter this:
$groupfilter = "(&(objectcategory=group)(cn=wholeadgroup))"
but want search on specific part of group name.
like this, cmdlet instead of object:
$groupfilter = get-adgroup -filter {name -like "sccm.*"}
in last case cannot use in adsi command remove.
so has got straight forward solution delete computer object queried group (a group matches word in query)?
kind regards,
andré
hi andré,
give shot, remove computer objects groups filter picks up:
$groups = get-adgroup -filter 'name -like "test group *"' foreach ($group in $groups) { $groupmembers = get-adgroupmember $group | { $_.objectclass -eq 'computer' } remove-adgroupmember -identity $group -members $groupmembers -confirm:$false }
this remove computer objects without prompting. if want prompt before removing object, remove -confirm:$false switch remove-adgroupmember
don't retire technet! - (maybe there's still chance hope, on 11,925+ strong , growing)
Windows Server > Windows PowerShell
Comments
Post a Comment