Tagged · 16 notes
#Active Directory.
Everything tagged Active Directory, wherever it's filed, newest first.
How this site borrows the warmth of early-'90s Apple ads (editorial type, cream paper, slate ink) and why the fake menu bars and little beige Mac didn't make the cut.
Thread: The design notebook ↗
One script that locks a departing user out, cleans up their groups and licenses, and keeps their mail, with a CSV record of every step.
Thread: The Microsoft Graph toolbox ↗
Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.
Thread: Local admin, done right ↗
A computer inventory straight out of AD, with OS build, last logon, password age and OU in one tidy CSV, ready for audits or a stale-machine cleanup.
Thread: Keeping Active Directory tidy ↗
Clean old user profiles off shared PCs and servers through Win32_UserProfile, so the folder and the registry entry go together and nobody gets a TEMP profile.
Thread: Spring cleaning for Windows PCs ↗
Load mobile numbers into Entra ID as an authentication method before users ever sign in, without stomping on numbers they've already registered.
Thread: The Microsoft Graph toolbox ↗
A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Thread: Getting devices into Intune ↗
Point each domain controller at a partner DC first and itself (127.0.0.1) last, the way Microsoft recommends, across all your DCs in one pass.
Thread: Keeping Active Directory tidy ↗
Create the Tier 2 OU, its sub-OUs and the group that manages them, and delegate just enough rights for workstation and user admin work.
Thread: Keeping Active Directory tidy ↗
Dump every OU in the domain to a spreadsheet, with a readable path, depth, GPO link count and, if you want, how many objects live in each one.
Thread: Keeping Active Directory tidy ↗
One report for every kind of service account, gMSAs and old-school user accounts alike, showing password age, SPNs, delegation and who can read the gMSA password.
Thread: Keeping Active Directory tidy ↗
Create a Tier 0 admin group, keep it where only Tier 0 can touch it, and give it full control of the Tier 0 OU. Preview the whole thing with -WhatIf first.
Thread: Keeping Active Directory tidy ↗
Write extensionAttribute1-15 on cloud-only Entra ID users from a CSV, with a clear note for every synced account it can't touch.
Thread: The Microsoft Graph toolbox ↗
Force an immediate local admin password rotation on every machine in a collection, with Windows LAPS doing the password part so no script ever sees one.
Thread: Local admin, done right ↗
A gpupdate wrapper that checks the domain trust first, never bounces anyone's session, and reports a real success or failure back to ConfigMgr.
Thread: Packaging with ConfigMgr ↗
Feed it a list or an OU, and it deletes (or disables) only the computers that are genuinely stale, logs every decision to CSV, and shows you the plan first with -WhatIf.
Thread: Keeping Active Directory tidy ↗