?
Solved

Remove user from Domain Guest group

Posted on 2005-02-24
3
Medium Priority
?
628 Views
Last Modified: 2008-02-01
I am not happy at this point. I have a user that I added to the Domain Admins group. He is the president of the company so I did what he asked.
 I knew it was a mistake. He added the Domain Admins to the Domain Guests group. He neglected to tell me this. He just said hmm the CRM just stopped working. Well that was the first symptom of what was going on. I log in I get Access denied errors when I access active directory. I can't even look at any of the accounts. I used the trusty showgrps.exe and low and behold administrator is a member of the Domain admin. Right now I am looking at having to rebuild this server or remove AD from the domain and rebuild it from scratch since I didn't have a back up since I am just getting this server up and running.
My question is this. Is there a script or command that will remove an account from a certain group? Maybe in safe mode or AD restore mode?

The worse case senario is rebuild this server, exchange, SQL, and the CRM. I can say goodbye to my weekend. Can I punch the president in the face? Maybe I should let him do this work. Leave some nice words on the white board for him. :-/
0
Comment
Question by:Templar_m
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 18

Accepted Solution

by:
luv2smile earned 2000 total points
ID: 13395753
First off, I want to say I feel your pain because I'm in a similar situation. Luckily..*cross my fingers* I haven't had anything bad happen yet, but I just hate the idea of people who are not system administrators having domain admin rights....

I wonder if you could remove the group membership thru this command:

http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/schmmgmt_remove_member_schemaadmin_group.asp
0
 
LVL 7

Expert Comment

by:ScrptMasta
ID: 13395830
You can use this script to remove a User in AD from an AD group. Just place the code into a notepad file and save with a .VBS extension. You will need to change the info in the script to match your users and domain of course. Then run from the command prompt like this,

C:\>CSCRIPT myfile.vbs

Removes user MyerKen from the group Sea-Users.
***********************************************************************
Const ADS_PROPERTY_DELETE = 4
 
Set objGroup = GetObject _
   ("LDAP://cn=Sea-Users,cn=Users,dc=NA,dc=fabrikam,dc=com")
 
objGroup.PutEx ADS_PROPERTY_DELETE, _
    "member",Array("cn=MyerKen,ou=Management,dc=NA,dc=fabrikam,dc=com")
objGroup.SetInfo
***********************************************************************

      
0
 
LVL 3

Author Comment

by:Templar_m
ID: 13398449
I tried the vbs thing already figured there might have been another way.

Thanks ScrptMasta. That seemed to take the user out of that group but the error still remained. I think he did more damage than I can see.
0

Featured Post

Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question