Adding Domain Groups to Local Administrators on Remote PCs with PowerShell
Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.
Across the notebook
Entries sharing this tag, wherever they're filed.
Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.
A computer inventory straight out of AD, with OS build, last logon, password age and OU in one tidy CSV, ready for audits or a stale-machine cleanup.
A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Thread: Getting devices into Intune ↗Point each domain controller at a partner DC first and itself (127.0.0.1) last, the way Microsoft recommends, across all your DCs in one pass.
Create the Tier 2 OU, its sub-OUs and the group that manages them, and delegate just enough rights for workstation and user admin work.
Dump every OU in the domain to a spreadsheet, with a readable path, depth, GPO link count and, if you want, how many objects live in each one.
One report for every kind of service account, gMSAs and old-school user accounts alike, showing password age, SPNs, delegation and who can read the gMSA password.
Create a Tier 0 admin group, keep it where only Tier 0 can touch it, and give it full control of the Tier 0 OU. Preview the whole thing with -WhatIf first.
A gpupdate wrapper that checks the domain trust first, never bounces anyone's session, and reports a real success or failure back to ConfigMgr.
Feed it a list or an OU, and it deletes (or disables) only the computers that are genuinely stale, logs every decision to CSV, and shows you the plan first with -WhatIf.