Sunday, 18 August 2013

ADDS PowerShell Commands to Expedite Your Tasks

1. How to get the DFL?
PS C:\> Get-ADDomain | findstr / 'DomainMode'
{Quoted text is case sensitive)
2. How to get the FFL?
PS C:\> Get-ADForest | findstr / 'ForestMode'
(Quoted text is case sensitive)
3. How to get the ADDefaultDomainPasswordPolicy?
PS C:\> Get-ADDefaultDomainPasswordPolicy
4. How to get the all Trusts information.
PS C:\> Get-ADTrust -f * | ft
5.Find some specific attributes for an OU users.
PS C:\> get-aduser -f * -Searchbase "ou=powershell,dc=contoso,dc=com" -pr SamAccountName,PasswordExpired,whenChanged,UserPrincipalName
6.Generate a report for all AD users samaccountname,LastLogonDate,Enabled
PS C:\> get-aduser -f * -pr lastlogondate | ft samaccountname,LastLogonDate,Enabled -auto

11.Reset the password for all users of an OU

PS C:\> Get-ADUser -Filter * -SearchBase "ou=test,dc=biz,dc=net"| Set-ADAccountPassword -NewPassword (ConvertTo-SecureString -AsPlainText monster@me123 -Force)

12.Finding Global Catalog
Get-ADForest biz.net | FL GlobalCatalogs

13. Finding last 20 events from Directory Service.
get-eventlog 'Directory Service' -newest 20 | Format-List indx, source, message

14. Find event log entries with a specific text.
Get-EventLog System | Where-Object { $_.Message -match "disk" }

15. How to get the FSMO?
>>[System.DirectoryServices.ActiveDirectory.Domain]::GetCurrentDomain() | Select-Object *owner
 
>>[System.DirectoryServices.ActiveDirectory.Forest]::GetCurrentForest() | Select-Object *owner

or
Get-ADDomain | select PDCEmulator,RIDMaster,InfrastructureMaster | fl
Get-ADForest | select DomainNamingMaster, SchemaMaster | fl


PowerShell Function to Determine the Active Directory FSMO Role Holders
http://gallery.technet.microsoft.com/scriptcenter/PowerShell-Function-to-bec6c607 - Written by Mike F Robbins

16. Reboot Report
Get-EventLog -ComputerName System | Where-Object { $_.Source -eq 'user32' } | ConvertTo-HTML | Out-File C:\Reboot.htm

17.How to unlock the AD accounts.
Search-ADAccount –LockedOut | Unlock-ADAccount

18. How to find the commands are available in a particular Module.

Get-Command -Module dnsserver

19. DCs Inventory -> Output in a CSV

Get-ADDomainController -Filter * | select name, operatingsystem,HostName,site,IsGlobalCatalog,IsReadOnly | Export-Csv c:\dcinventory.csv

 

Saturday, 26 March 2011

Query a reg key for bulk computer

On Error Resume Next
Set objShell = CreateObject("Wscript.Shell")
Set oFso = CreateObject("Scripting.FileSystemObject")
sDesktop = objShell.SpecialFolders("Desktop")
spath = sDesktop & "\Dclist.txt"
Set oT = oFso.OpenTextFile(spath,1)
Do Until oT.AtEndofStream
temp= oT.ReadLine()
strComputer = Trim(temp)

Const HKEY_CURRENT_USER = &H80000001
Const HKEY_LOCAL_MACHINE = &H80000002


Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" & _
strComputer & "\root\default:StdRegProv")

strKeyPath = "Hardware\DESCRIPTION\SYSTEM\BIOS\"
strValueName = "SystemManufacturer"
oReg.GetStringValue HKEY_LOCAL_MACHINE,strKeyPath,strValueName,strValue
Wscript.Echo "OS Architecture for" & " " & strComputer & " " & "is: " & strValue
Loop

Monday, 21 February 2011

Quest Powershell Script For Active Directory

How to find group members for n number of groups
$groups=get-content groups.txtForeach($group in $groups){Get-QADGroupMember $groupGet-qadgroup $group}

Find memberof for n number of users with powershell

$users=get-content users.txtForeach($user in $users){get-Qadmemberof $userGet-qaduser $user}
Extract the known attr for "n" number of users
$users= get-content users.txtforeach ($user in $users) {Get-QADuser $user -SerializeValues}

Find the Canonical Name for n number of users

$users= get-content users.txt
foreach ($user in $users) {Get-QADuser $user -sizelimit 0 Format-table canonicalName}

Find the Dispaly Name for n number of users

$users= get-content users.txt
foreach ($user in $users) {Get-QADuser $user -sizelimit 0 Format-table displayname}

Find the Dispaly Name,Caninicalname and Samaccountname for n number of users

$users= get-content users.txt
foreach ($user in $users) {Get-QADuser $user -sizelimit 0 Format-table displayname,canonicalname,samaccountname}

Extract the known attr for "n" number of users

$users= get-content users.txt
foreach ($user in $users) {Get-QADuser $user -SerializeValues}

Sunday, 20 February 2011

Quest Powersheel

Guys,
Believe me or not? If yes and you are a MS-Directory Professional try it.
Benefits:

1. Where WAN connectivity is very slow you can work through command line.
2. Prevent accident deletion until you put exact deletion command.
3. You can automate you’re your AD environment.
4. Commands are easy to remember.
5. You can extract reports at a glance for million users with various parameters.

For more information see the below links and find the admin guide.

Download Quest Powersheel with admin guide.

http://www.quest.com/powershell/activeroles-server.aspx

Download Prerequisites

Microsft Powershell

http://support.microsoft.com/kb/968930

Dotnet framework 3.5 SP1
http://www.microsoft.com/downloads/en/details.aspx?FamilyID=d0e5dea7-ac26-4ad7-b68c-fe5076bba986&displaylang=en

For query purpose its does not require any kind of special permission.
See the below link also.
http://blogs.technet.com/b/manojnair/archive/2010/12/27/adding-users-to-ad-group-using-quest-powershell-command-lets.aspx


Before running any ps script put the below command.

Set-ExecutionPolicy Unrestricted

Wednesday, 16 February 2011

How to create schedule task with system account

schtasks /create /tn "seclog-Backup" /tr c:\file_copy1.vbs /sc monthly /d 1 /ru "System"
schtasks /create /tn "sec-log-Backup" /tr C:\Script\Sec_Log_Copy.vbs /sc HOURLY /ru "System"

Friday, 11 February 2011

DFS Refresh issue in Windows XP SP3

Here I am not going to explain what is DFS, yesterday I have fixed one major issue on DFS. The problem was, File list in the Windows Explorer folder is not refreshed after you create, move, or delete files. AS per Microsoft that issue has been fixed with XP SP2 but I have faced the issue in xp SP3.

Resolution Steps:
Install a Hotfix, I have given the Microsoft Link for that and create the below mentioned registry key.
Reboot the PC once.
http://support.microsoft.com/kb/953323
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer
On the Edit menu, point to New, and then click DWORD Value. Type NoSimpleNetIDList, and then press ENTER. On the Edit menu, click Modify. Type 1, and then click OK.