Thursday, December 3, 2015

Powershell modify active directory user account data

Hi mates,
a customer asked me to do a quick operation on his Active Directory.
Practically the needs were :

1. add into a specific group a list of users retrieved from a TXT file
2. retrieve active directory users members from this group
3. for each user modify the description field for future usage maintaning the old value in case it exists

Thursday, November 26, 2015

Sophos destination NAT

Hi mates,
I had, few days ago, a particular request : a customer asked me to NAT RDP connection to a custom/specific/non standard port.
This customer has a very good product named Sophos UTM Firewall (version 9.3XX).
I worked with Sophos when it was Astaro....for several years, and my 20-25 customers were fully satisfied.
Anyway......it's easy as you can imagine but I would like to share the steps....maybe tomorrow you have to replicate this and you are too tired to think....you want only to follow (someday could happen)
In particular the customer's IT Dept. decided to change the default RDP port (and also SSH) from 3389 to 33389.

Tuesday, November 3, 2015

Powershell manage local users and group, nest domain users with domain group and local computer admins

Hi mates,
few months ago one of my customer told me :
"I need to clean a lot of servers in terms of local administrators group. At the sametime I would like to change the method to manage local administrators.....is it possbile to create one group for each single server so I can manage members from AD ?
And what we can do for the current situation ? Is it possible to clean without creating issue ? "
Effectively there were a lot of external partner's account inside these local groups, additionally there were a lot of internal application guys username
Anyway what I needed to do is well explained inside the script.....so enjoy :

Friday, October 23, 2015

Powershell delete files older than......

Hi mates,
how many times you asked to yourself : how can I delete files older than a specified date ? How can I clean a specific directory that preserve, for example, backup files from several sources ?
Quick and easy, skinny and essential.
Here below the script .....you can customize the number of days that you want preserve : older items will be deleted.
Obviously you have to customize the path too.

Wednesday, October 21, 2015

Powershell report user list and their expiring date

Hi mates,
how many times you asked to yourself : how can I generate a report regarding active directory expiring users ?
I had, few months ago, the need to search in a specific OU, which users where active or not and which users have the expiration date configured.
This report was used for several purposes : check the status of interim users, consultant, partners and so on.
This report gives you a good visibility of the status of a specific set of users :

Thursday, October 15, 2015

Powershell quick clean to resigned users

Hi mates,
how many times you asked to yourself : how can I clean active directory from the group membership perspective ?
How can I clean resigned users ? few months ago we were discussing about the importance of group membership.
Sometimes the group membership could determine how many licenses I'm using for a specific product, how many sessions (Citrix for example) I'm potentially delivering to the end users.
Anyway independently of what is your usage and purpose of it, we were also discussing about to maintain "alive" (or zombified) the resigned users in a specific OU.

Powershell compare file contents

Hi mates,
how many times you asked to yourself : how can I compare file contents ?
I had some needs during the previous days....I know you too, maybe :-)
Anyway my last one was related to a complex script that should evaluate the password change  of active directory users : if the user didn't change the password during the last 90 days we send him a first email. The week later another time : if the user of the first week didn't change the password yet we send him a second email, different from the first one, informing him that the week later we will disable his account. The last week another time : if the user is still persisting we lock the account.
The logic behind this script is complex enough, at least for me....I'm not a programmer.
I needed to compare several text files reporting the result of the queries done during the three weeks examined before.
I'll post this script later, during next weeks but in the meantime I would like to share some brief consideration regarding the file comparison.