Solved

I need a GP for moving diabled users to a predefined "Disable User" OU

Posted on 2008-10-01
6
200 Views
Last Modified: 2010-04-18
Windows 2003 AD
We are a service provider - 80% of our user community is in the field
our attrition rate is high -
I need a group policy to migrate disabled users from one OU to a disabled user OU when the user is terminated.
0
Comment
Question by:acreeit
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 71

Expert Comment

by:Chris Dent
ID: 22619331

It would have to be a script rather than policy, but that's not a big problem.

How do you define / locate terminated users within AD?

Chris
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 22619774
As Chris said, you nead to script it.
One way is to use dsquery and dsmove from adminpak.msi
for /F %a in ('dsquery user OU=old-ou,DC=domain,DC=com -disabled') do @dsmove %a -newparent OU=disabled-users,DC=domain,DC=com
0
 
LVL 22

Expert Comment

by:Paka
ID: 22622904
How about piping the result:
dsquery user -disabled -limit 0 | dsmove user -newparent "ou=disabled, dc=mydomain, dc=com"
(where | is shift-\)  This will move all disabled users in all OUs in your domain to an the disabled OU.  

If you want to preview the accounts that would move:
dsquery user -disabled -limit 0 > disabledusers.txt

If you want to move just 10 accounts (as a test):
dsquery user -disabled -limit 10 | dsmove user -newparent "ou=disabled, dc=mydomain, dc=com"
0
Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

 

Author Comment

by:acreeit
ID: 22624859
Can this be automated so that once the Helpdesk disabled the account it is automatically moved to diabled OU?
HOW do I do this?
0
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 125 total points
ID: 22626682
Place the command line in a script.cmd file and create a schedule task to run the script at a recurring times on the DC.
Keep in mind that %a in for-loop nead to be replaced with %%a when using script files. The single %a is used when executing command directly in command prompt.
0
 

Author Comment

by:acreeit
ID: 22626727
Thank you willl test
0

Featured Post

What Is Transaction Monitoring and who needs it?

Synthetic Transaction Monitoring that you need for the day to day, which ensures your business website keeps running optimally, and that there is no downtime to impact your customer experience.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
A hard and fast method for reducing Active Directory Administrators members.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question