Hacks #25-35
A large part of day-to-day administration of an Active Directory
environment is managing users and their accounts. The usual way of
doing this is with the Active Directory Users and Computers (ADUC)
console, but when it comes to
organizations with thousands of users, this tool can be frustrating
to use.
This chapter is about alternatives to ADUCways of doing things
faster using scripts. You'll find scripts to display
information about users, find specific users on your network, change
user passwords, unlock user accounts, get a list of disabled
accounts, display which groups a user belongs to, and more. If
you're familiar with VBScript, you can also
customize these scripts further to meet the specific needs of your
own networking environment.
For all these scripts, make sure you have the latest scripting
engines on the workstation from which you run the script. You can
download the latest scripting engines from the Microsoft Scripting
home page (http://msdn.microsoft.com/scripting/). Also,
when working with the Active Directory Services Interface (ADSI), you
must have the same applicable rights you need to use the built-in
administrative tools. For more information, see
Microsoft's ADSI web page (http://www.microsoft.com/windows2000/techinfo/howitworks/activedirectory/adsilinks.asp).