A thread · 7 notes · Script Library
Keeping Active Directory tidy.
Tiering, exports, stale computers, service accounts and DNS on the domain controllers.
- 1
Delegating Your Tier 0 OU to a Dedicated Admin Group with PowerShell
Create a Tier 0 admin group, keep it where only Tier 0 can touch it, and give it full control of the Tier 0 OU. Preview the whole thing with -WhatIf first.
- 2
Building a Tier 2 OU Structure and Admin Group with PowerShell
Create the Tier 2 OU, its sub-OUs and the group that manages them, and delegate just enough rights for workstation and user admin work.
- 3
Exporting Active Directory OUs to CSV (With Paths You Can Actually Read)
Dump every OU in the domain to a spreadsheet, with a readable path, depth, GPO link count and, if you want, how many objects live in each one.
- 4
Exporting Active Directory Computer Objects to CSV
A computer inventory straight out of AD, with OS build, last logon, password age and OU in one tidy CSV, ready for audits or a stale-machine cleanup.
- 5
Deleting Stale Computer Accounts from Active Directory, Safely, with a CSV Log
Feed it a list or an OU, and it deletes (or disables) only the computers that are genuinely stale, logs every decision to CSV, and shows you the plan first with -WhatIf.
- 6
Auditing Active Directory Service Accounts with PowerShell (gMSAs Included)
One report for every kind of service account, gMSAs and old-school user accounts alike, showing password age, SPNs, delegation and who can read the gMSA password.
- 7
Setting DNS Client Settings on Domain Controllers with PowerShell (and Why Loopback Goes Last)
Point each domain controller at a partner DC first and itself (127.0.0.1) last, the way Microsoft recommends, across all your DCs in one pass.