Difficulty removing user from universal groups in Powershell
hi! have universal group users domains in forest added 1 vendor supported systems query through ldap. resides on 1 of 4 domains in forest , can contain members of other three.
when want remove users using powershell, errors remove-adgroupmember , remove-adprincipalgroupmembership because not in same domain. found following suggestion on msdn's blogs, still cannot find user remove.
ps forestaaa:\> $forestbbbuser = get-aduser swami -server $forestbbb
ps forestaaa:\> add-adgroupmember administrators -members $forestbbbuser
ps forestaaa:\>
ps forestaaa:\> $forestaaagroup = get-adgroup administrators
ps forestaaa:\> add-adprincipalgroupmembership -server $forestbbb swami -memberof $forestaaagroup
ps forestaaa:\> remove-adprincipalgroupmembership -server $forestbbb swami -memberof $forestaaagroup
i however, able make work using
set-adobject-identity$($group.distinguishedname) -remove@{member="$($member.distinguishedname)"} -server$server
i not understand why activedirectory module's cmdlets won't work though. suggestions?
this works:
$g =get-adgroup testgrp2 -server domainb $u = get-aduser jsmith -server -doaminb remove-adprincipalgroupmembership -identity $u -memberof $g
\_(ツ)_/
Windows Server > Windows PowerShell
Comments
Post a Comment