Wes Ellis./ a personal notebook
Technology. Stories. Side projects.
A few things worth writing down.

A thread · 7 notes · Script Library

Keeping Active Directory tidy.

Tiering, exports, stale computers, service accounts and DNS on the domain controllers.

  1. 1
    Script Library2 min read · Script

    Delegating Your Tier 0 OU to a Dedicated Admin Group with PowerShell

    Create a Tier 0 admin group, keep it where only Tier 0 can touch it, and give it full control of the Tier 0 OU. Preview the whole thing with -WhatIf first.

  2. 2
    Script Library2 min read · Script

    Building a Tier 2 OU Structure and Admin Group with PowerShell

    Create the Tier 2 OU, its sub-OUs and the group that manages them, and delegate just enough rights for workstation and user admin work.

  3. 3
    Script Library2 min read · Script

    Exporting Active Directory OUs to CSV (With Paths You Can Actually Read)

    Dump every OU in the domain to a spreadsheet, with a readable path, depth, GPO link count and, if you want, how many objects live in each one.

  4. 4
    Script Library1 min read · Script

    Exporting Active Directory Computer Objects to CSV

    A computer inventory straight out of AD, with OS build, last logon, password age and OU in one tidy CSV, ready for audits or a stale-machine cleanup.

  5. 5
    Script Library2 min read · Script

    Deleting Stale Computer Accounts from Active Directory, Safely, with a CSV Log

    Feed it a list or an OU, and it deletes (or disables) only the computers that are genuinely stale, logs every decision to CSV, and shows you the plan first with -WhatIf.

  6. 6
    Script Library2 min read · Script

    Auditing Active Directory Service Accounts with PowerShell (gMSAs Included)

    One report for every kind of service account, gMSAs and old-school user accounts alike, showing password age, SPNs, delegation and who can read the gMSA password.

  7. 7
    Script Library2 min read · Script

    Setting DNS Client Settings on Domain Controllers with PowerShell (and Why Loopback Goes Last)

    Point each domain controller at a partner DC first and itself (127.0.0.1) last, the way Microsoft recommends, across all your DCs in one pass.