Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

ldifde import script needed for users and OU

Posted on 2014-12-10
7
Medium Priority
?
309 Views
Last Modified: 2014-12-27
Hello,
I am looking for ldifde script to import the ldf files.

I already exported the OUs and Objects using the commands below, but now I need a script to import them into the target.local domain.

THank you very much!

ldifde -f sourceOu.ldf -s QMM-SRCEXCH -d "dc=source,dc=local" -p subtree -r "(objectClass=organizationalUnit)" -l "cn,objectclass,ou"

ldifde -f sourceuser.ldf -s QMM-SRCEXCH -d "dc=source,dc=local" -p subtree -r "(&(objectCategory=person)(objectClass=User)(givenname=*))" -o "badPasswordTime,badPwdCount,lastLogoff,lastLogon,logonCount, memberOf,objectGUID,objectSid,primaryGroupID,pwdLastSet,sAMAccountType"
0
Comment
Question by:claudiamcse
  • 5
6 Comments
 
LVL 19

Expert Comment

by:Raheman M. Abdul
ID: 40493991
Refer: http://support.microsoft.com/kb/237677

To import OU:

ldifde -i -f sourceOu.ldf -s QMM-SRCEXCH -d "dc=target,dc=local" -p subtree -r "(objectClass=organizationalUnit)" -l "cn,objectclass,ou"

To Import users:
 ldifde -i -f sourceuser.ldf -s QMM-SRCEXCH -d "dc=target,dc=local" -p subtree -r "(&(objectCategory=person)(objectClass=User)(givenname=*))" -o "badPasswordTime,badPwdCount,lastLogoff,lastLogon,logonCount, memberOf,objectGUID,objectSid,primaryGroupID,pwdLastSet,sAMAccountType"

NOTE: Because LDIFDE does not export passwords, when the users are imported into the directory, the account is disabled and the password is set to null. This is done for security reasons. Also, the account option "User must change password at next logon" is selected.
0
 

Author Comment

by:claudiamcse
ID: 40499676
Outstanding! Thank you
0
 

Author Comment

by:claudiamcse
ID: 40499722
I am sorry. This actually doesn't work....It throws error
0
New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

 

Author Comment

by:claudiamcse
ID: 40499726
C:\LDIFDE-exports>ldifde -i -f corpQAUser.ldf -d "dc=corp,dc=testlab,dc=com" -p
subtree -r "(&(objectCategory=person)(objectClass=User)(givenname=*))" -o "badP
asswordTime,badPwdCount,lastLogoff,lastLogon,logonCount, memberOf,objectGUID,obj
ectSid,primaryGroupID,pwdLastSet,sAMAccountType"
Invalid Parameter: RootDn not required for import
Invalid Parameter: Filter not required for import
Invalid Parameter: Scope not required for import
Invalid Parameter: Omit List not required for import

I also tried this command but it gives another error since our environment has custom schema.....Is there a way to import users that have attributes exported from custom schema?

Please help.

I tried this command and it also gives an error:
ldifde -i -f Exportuser.ldf -s Server2

this error :

dd error on line 2: No Such Attribute

The server side error is "The parameter is incorrect."

0 entries modified successfully.

An error has occurred in the program
0
 

Accepted Solution

by:
claudiamcse earned 0 total points
ID: 40513344
This issue was resolved by only exporting the attributes that can be imported into the Target schema. Once I determined the attributes that I have in the target and exported only the needed attributes, the import worked.
0
 

Author Closing Comment

by:claudiamcse
ID: 40519479
This was the resolution. The other resolution didn't work
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The following article is intended as a guide to using PowerShell as a more versatile and reliable form of application detection in SCCM.
Windows 10 came with  a lot of built in applications, Some organisations leave them there, some will control them using GPO's. This Article is useful for those who do not want to have any applications in their image (example:me).
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Loops Section Overview

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question