Difficulty removing user from universal groups in Powershell


hi! have universal group users domains in forest added 1 vendor supported systems query through ldap. resides on 1 of 4 domains in forest , can contain members of other three.

when want remove users using powershell, errors remove-adgroupmember , remove-adprincipalgroupmembership because not in same domain. found following suggestion on msdn's blogs, still cannot find user remove.

ps forestaaa:\> $forestbbbuser = get-aduser swami -server $forestbbb
ps forestaaa:\> add-adgroupmember administrators -members $forestbbbuser
ps forestaaa:\>
ps forestaaa:\> $forestaaagroup = get-adgroup administrators
ps forestaaa:\> add-adprincipalgroupmembership -server $forestbbb swami -memberof $forestaaagroup
ps forestaaa:\> remove-adprincipalgroupmembership -server $forestbbb swami -memberof $forestaaagroup

i however, able make work using

set-adobject-identity$($group.distinguishedname) -remove@{member="$($member.distinguishedname)"} -server$server

i not understand why activedirectory module's cmdlets won't work though. suggestions?

this works:

$g =get-adgroup testgrp2 -server domainb $u = get-aduser jsmith -server -doaminb remove-adprincipalgroupmembership -identity $u -memberof $g


\_(ツ)_/



Windows Server  >  Windows PowerShell



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com