Common PowerShell Commands for AD

A list of common PowerShell commands for AD. Retrieve AD user(s) # get AD user – basic attributes Get-ADUser “JohnDo” # get AD user – all attributes Get-ADUser “JohnDo” -Properties * # get AD user – additional attribute(s) Get-ADUser “JohnDo” -Properties PasswordLastSet Get-ADUser “JohnDo” -Properties whenChanged,whenCreated # get AD user – output specific attribute Get-ADUser …

Common PowerShell Commands for AD Read More »

Enable AD Object Inheritance using Powershell

An easy way to enable AD object inheritance using Powershell. This can be used for enabling (or disabling) inheritance on multiple AD objects. #$users = Get-ADUser -ldapfilter “(objectclass=user)” -searchbase “DC=domain,DC=local” $users = get-aduser JohnDo #test with a single user first ForEach($user in $users) { $dn= [ADSI](“LDAP://” + $user) $acl= $dn.psbase.objectSecurity if ($acl.get_AreAccessRulesProtected()) { $isProtected = …

Enable AD Object Inheritance using Powershell Read More »