• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2494
  • Last Modified:

Automatically Join Computers in an OU to a security group

Hello, in our domain we have multiple offices across the country. Each of these offices has it own OU, eg London, Manchester, Liverpool etc.

Each Citys OU contains child OUs for objects eg Users, Laptops, Desktops, Security Groups, Distribution Groups etc

I have a security group that is for the whole of the domain, what I want to do is automatically make any laptop in every city City a member of the security group.

Is there a way to do this? I would mind a powershell script running every so often. ut it would be nice to be able to put in some sort of policy that forces a member of an OU into a group.
0
infradatel
Asked:
infradatel
  • 4
  • 3
  • 2
2 Solutions
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Try this:

Get-QADComputer -SearchRoot "OU=NAMEOF OU,OU=NAMEOFCITYOU,DC=Test,DC=local" | Add-QADGroupMember "TEST\GROUPNAME"

You will need to specify the search root to each laptop OU. You will also need the Quest AD CMDLets.

http://www.quest.com/powershell/activeroles-server.aspx
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Set it up as a scheduled task and you are good to go!
0
 
infradatelAuthor Commented:
Is there a way to do this without installing the Quest Modules?
0
Free Backup Tool for VMware and Hyper-V

Restore full virtual machine or individual guest files from 19 common file systems directly from the backup file. Schedule VM backups with PowerShell scripts. Set desired time, lean back and let the script to notify you via email upon completion.  

 
Joseph MoodyBlogger and wearer of all hats.Commented:
Yes - if you have a 2008 R2 web services, you can use the AD builtin powershell cmdlets.

Just replace qad- with ad-

The Quest Modules are very nice though and super simple! You just need them on a workstation.
0
 
infradatelAuthor Commented:
Ok thanks will go e it a try now I have a server with web services on
0
 
McKnifeCommented:
Hi.

Have a look at the concept of shadow groups. http://www.youtube.com/watch?v=HMixa01i78g In the descriptive text, a script is linked.
0
 
infradatelAuthor Commented:
With the help of both of you I have managed to get this working as required, using shadow groups I have even managed to get it to automate deletion of computers removed from the OU. THanks Guys.
0
 
Joseph MoodyBlogger and wearer of all hats.Commented:
Awesome!

If you can, post your script. Others may find it useful!
0
 
McKnifeCommented:
Could you do all you wanted using shadow groups?
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

  • 4
  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now