Difficulty removing user from universal groups in Powershell


hi! have universal group users domains in forest added 1 vendor supported systems query through ldap. resides on 1 of 4 domains in forest , can contain members of other three.

when want remove users using powershell, errors remove-adgroupmember , remove-adprincipalgroupmembership because not in same domain. found following suggestion on msdn's blogs, still cannot find user remove.

ps forestaaa:\> $forestbbbuser = get-aduser swami -server $forestbbb
ps forestaaa:\> add-adgroupmember administrators -members $forestbbbuser
ps forestaaa:\>
ps forestaaa:\> $forestaaagroup = get-adgroup administrators
ps forestaaa:\> add-adprincipalgroupmembership -server $forestbbb swami -memberof $forestaaagroup
ps forestaaa:\> remove-adprincipalgroupmembership -server $forestbbb swami -memberof $forestaaagroup

i however, able make work using

set-adobject-identity$($group.distinguishedname) -remove@{member="$($member.distinguishedname)"} -server$server

i not understand why activedirectory module's cmdlets won't work though. suggestions?

this works:

$g =get-adgroup testgrp2 -server domainb $u = get-aduser jsmith -server -doaminb remove-adprincipalgroupmembership -identity $u -memberof $g


\_(ツ)_/



Windows Server  >  Windows PowerShell



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS