Solved

how to add a user to active directory from command line, also specifying the password and the email address

Posted on 2008-10-09
8
330 Views
Last Modified: 2012-05-05
i want to add users to active directory from command line, i must be able to

(1) create the user
(2) specify which active directory security group the user should be added to
(3) include the email address of the user

i have admin access to the active directory, not sure what else is needed to create the user.

please help me understand what is  the meaning of "DC" and "OU" and how and where to find this information on the server. i am sure this information is used while creating the user.
0
Comment
Question by:tarcot
  • 5
  • 3
8 Comments
 
LVL 70

Expert Comment

by:KCTS
Comment Utility
You can create users with a variety of tools such as CSDVE, LDIFDE, VBSCRIPT or (with 2003/8 the DSadd commands) see http://www.computerperformance.co.uk/Logon/DSadd_add_user.htm

but why - I would help to know exactly what you are trying to achieve.
0
 

Author Comment

by:tarcot
Comment Utility
i am specifically interested with the dsadd command, we get a nightly feed of users that are needed to be added to the domain, we use sharepoint, so the next day these users automatically get authenticated when they login.

i am not sure i should  add it in the wss_ou, we are talking about 120,000 users that need to be created.
although creation of these users is a one time thing, there will be 100's of users each day that need to be either added or deleted..

we have a dedicated active directory server to handle this volume.

also in the link that you have sent it does not indicate how  to assign the user to a group, is there a seperate command that i could use to assign user to a group..?



0
 
LVL 70

Expert Comment

by:KCTS
Comment Utility
OK, I see where you are coming from. Theres a lot more on the DS commands (DSadd, DSMod and DSrm) at http://www.computerperformance.co.uk/Logon/DSadd_add_user.htm

As you have so many users to manage in this way, it probably worth looking at third party tools
eg http://manageengine.adventnet.com/products/ad-manager/active_directory_bulk_user_management.html
and
http://www.dovestones.com/products/Active_Directory_User_Import_Features.asp
0
 

Author Comment

by:tarcot
Comment Utility
thanks for the resources, i will definetly consider looking more deeply into it

i did see an entry in the third link that you sent

Group memberOf "CN=ManagersGroup,DC=Domain,DC=Com"

can we use the above syntax with the dsadd command in any way. i believe this is the only thing that is missing.
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 70

Accepted Solution

by:
KCTS earned 500 total points
Comment Utility
you can use the -memberOf option
see http://forums.techarena.in/active-directory/704257.htm for an example
0
 

Author Comment

by:tarcot
Comment Utility
please apologize my ignorance, i am not sure i have understood completly what this means

DSadd user "CN=Last\, First,OU=AB,DC=Xyxyxyx,DC=Com" -pwd Password -samid
First.last -fn First -ln Last -empid 12345 -display "Last, First" -loscr
Script.vbs -upn First.Last@Xyxyxyx.com -memberof "CN=.Abc
Def,OU=AB,DC=Xyxyxyx,DC=com"

please explain
(1) what is -loscr Script.vbs
(2) what is -upn (looking at the example above it looks like an email address for the user)
(3) -pwd, -fn, -ln,  -empid,-display  seem to be various attributes that can be specifed while user creation - am i right..?
(4) i assume that abcbef is the name of the AD security group -- is my understanding correct
0
 

Author Comment

by:tarcot
Comment Utility
i tried the example on the server and got the following error

dsadd user "CN=mytest.user,OU=wss_ou,dc
=s265601-ad01,dc=corp" -pwd Dummy123 -upn a@b.com -memberof
 "cn=Broker,ou=wss_ou,dc=s265601-ad01,dc=corp"
dsadd failed:CN=mytest.user,OU=wss_ou,dc=s265601-ad01,dc=corp:Directory objec
t not found.:The object was created successfully but there was an error during p
ost create operations.
type dsadd /? for help.

my ou name is wss_ou which i just created using the following command
dsadd ou "ou=wss_ou, dc=s265601-ad01,dc=corp"

not sure if there is something else i should do...?
0
 

Author Closing Comment

by:tarcot
Comment Utility
it worked
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Companies that have implemented Microsoft’s Active Directory need to ensure that the Active Directory is configured and operating properly. If there are issues found and not resolved, it eventually leads the components to fail or stop working and fi…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now