Solved

Command or Script to delete a list of Domain User accounts

Posted on 2012-04-09
6
577 Views
Last Modified: 2012-05-17
I have a list of domain user accounts. I need a script or a command to delete those domain user accounts from AD. Thanks
0
Comment
Question by:jmohan0302
  • 3
  • 2
6 Comments
 
LVL 11

Accepted Solution

by:
Venugopal N earned 333 total points
ID: 37826443
You can use the lDIF untility to delete the bulk users.Before that you need to put the list of users in the below format in an notepad and save with extension .ldf

dn: CN=user1,OU=Marketing,DC=reskit,DC=com
dn: CN=user2,OU=Marketing,DC=reskit,DC=com
dn: CN=user3,OU=Marketing,DC=reskit,DC=com
.
.
.
.
changetype: delete.

Once you have done the creation of the file then run the comamnd

ldifde –i -f filename.ldf -s DC
Where:
 -i import
-s DC name
-f filename.
0
 
LVL 4

Assisted Solution

by:julian_brunt
julian_brunt earned 167 total points
ID: 37826486
using VBS this is the snippet to delete the user account
' Delete a User Account from Active Directory


Set objOU = GetObject("LDAP://ou=hr,dc=fabrikam,dc=com")

objOU.Delete "user", "cn=MyerKen"

Such scripts are available here:
http://gallery.technet.microsoft.com/scriptcenter

** HOWEVER **
I would be tempted to create a separate OU and disable the user accounts and move them there instead of deleting them
0
 

Author Comment

by:jmohan0302
ID: 37831136
Hi Venurajav:

Thanks a lot. Could you please give me the link from where I can download the LDIFDE.exe and also gimme the exact syntax for LDIFDE for deleting the file. Thanks
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 11

Assisted Solution

by:Venugopal N
Venugopal N earned 333 total points
ID: 37831169
By default it will be avaiable on windows server os in %systemroot%\system32 .If not you can get the tool from the support tool folder on the  OS CD.

http://www.petri.co.il/list_all_users_and_groups_in_domain.htm

For syntax

http://technet.microsoft.com/en-us/library/bb727091.aspx
0
 

Author Comment

by:jmohan0302
ID: 37831927
Hi Venurajav,

I tried to execute but getting the following error:

Connecting to "FRMA705"

Logging in as current user using SSPI

Importing directory from file "del1.ldf"

Loading entries
1: CN=BALOGH Diana,OU=Users,OU=FR,DC=fr,DC=euro,DC=biomerieux,DC=net
Entry DN: CN=BALOGH Diana,OU=Users,OU=FR,DC=fr,DC=euro,DC=biomerieux,DC=net
changetype: delete
Add error on line 1: Not allowed on Non-leaf

The server side error is "The directory service can perform the requested operation only on a leaf object."

0 entries modified successfully.

An error has occurred in the program


Kindly help me
0
 
LVL 11

Expert Comment

by:Venugopal N
ID: 37836684
I think the DN specified is not correct.

Run the below command and Which will give you the right DN for the user.Use this DN and try to delete the user by using ldifde,

Dsquery OU –name "BALOGH Diana"
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Suggested Solutions

The saying goes a bad carpenter blames his tools. In the Directory Services world a bad system administrator, well, even with the best tools they’re probably not going to become an all star.  However for the system admin who is willing to spend a li…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now