Script to Move New User to the Identical OU of Existing User

Posted on 2011-05-02
Medium Priority
Last Modified: 2012-06-21
We have several hundred devices that are setup to Auto-login using the same AD account. Because of a software requirement we now need each device to Auto-login with a unique account. We have created the new accounts and I am writing a batch file script to do the move. I have most of the steps I want to automate completed, but I'm having difficulty coming up with a way to move the new accounts to the respective OU of existing accounts.

I can run "dsquery user -samid %ExistingUser%" to get a distiguished name of the existing account but I can't just pipe that over to "dsmove %NewUserDN% -newparent %ExistingUser% since the CN in the existing user's distinguished name is still there.

I guess I'm looking for a way to take the CN= section off of the %ExistingUser% variable to just get the distinguished name of the OU it's in. Unless of course there is an easy way to do this with the ds commands that I'm just overlooking.

Thanks for any suggestions!

Question by:Cacophony777
LVL 85

Accepted Solution

oBdA earned 2000 total points
ID: 35510632
Try this:
@echo off
set ExistingUser=SomeUserID
for /f "tokens=1* delims=," %%a in ('dsquery user -samid %ExistingUser%') do set ExistingUserOU="%%b
echo ExistingUserOU: %ExistingUserOU%

Open in new window


Author Closing Comment

ID: 35514248
Perfect. I'm not sure I entirely get what that FOR statement is doing, but I do know that it works. Thanks, much!

Featured Post

Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question