?
Solved

I need a GP for moving diabled users to a predefined "Disable User" OU

Posted on 2008-10-01
6
Medium Priority
?
205 Views
Last Modified: 2010-04-18
Windows 2003 AD
We are a service provider - 80% of our user community is in the field
our attrition rate is high -
I need a group policy to migrate disabled users from one OU to a disabled user OU when the user is terminated.
0
Comment
Question by:acreeit
6 Comments
 
LVL 71

Expert Comment

by:Chris Dent
ID: 22619331

It would have to be a script rather than policy, but that's not a big problem.

How do you define / locate terminated users within AD?

Chris
0
 
LVL 31

Expert Comment

by:Henrik Johansson
ID: 22619774
As Chris said, you nead to script it.
One way is to use dsquery and dsmove from adminpak.msi
for /F %a in ('dsquery user OU=old-ou,DC=domain,DC=com -disabled') do @dsmove %a -newparent OU=disabled-users,DC=domain,DC=com
0
 
LVL 22

Expert Comment

by:Paka
ID: 22622904
How about piping the result:
dsquery user -disabled -limit 0 | dsmove user -newparent "ou=disabled, dc=mydomain, dc=com"
(where | is shift-\)  This will move all disabled users in all OUs in your domain to an the disabled OU.  

If you want to preview the accounts that would move:
dsquery user -disabled -limit 0 > disabledusers.txt

If you want to move just 10 accounts (as a test):
dsquery user -disabled -limit 10 | dsmove user -newparent "ou=disabled, dc=mydomain, dc=com"
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:acreeit
ID: 22624859
Can this be automated so that once the Helpdesk disabled the account it is automatically moved to diabled OU?
HOW do I do this?
0
 
LVL 31

Accepted Solution

by:
Henrik Johansson earned 375 total points
ID: 22626682
Place the command line in a script.cmd file and create a schedule task to run the script at a recurring times on the DC.
Keep in mind that %a in for-loop nead to be replaced with %%a when using script files. The single %a is used when executing command directly in command prompt.
0
 

Author Comment

by:acreeit
ID: 22626727
Thank you willl test
0

Featured Post

Learn to develop an Android App

Want to increase your earning potential in 2018? Pad your resume with app building experience. Learn how with this hands-on course.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Transferring FSMO roles is done when an admin wants to split roles between certain Domain Controllers or the Domain Controller holding the Roles has been forcefully demoted using dcpromo / forceremoval
Sometimes it necessary to set special permissions on user objects.  For instance when using a Blackberry server, the SendAs permission needs to be set. I see many admins struggle with the setting that permission only to see it disappear within a few…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question