Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- DISCLAIMER - This example code is provided without copyright and AS IS. It is free for you to use and modify.
- Manage and Maintain Active Directory Domain Services in Windows Server 2016 - Pluralsight
- ************************************************
- windows-server-2016-manage-maintain-ad-domain-services-m2
- ************************************************
- ***** -- Create and configure Managed Service Accounts
- Import-Module ActiveDirectory
- New-ADServiceAccount -Name TestAccount -RestrictToSingleComputer -Enabled $True
- Add-ADComputerServiceAccount -Identity mydesktop -ServiceAccount TestAccount
- Install-ADServiceAccount -Identity TestAccount
- ***** -- Create and configure Group Managed Service Accounts
- Add-KDSRootKey –EffectiveTime ((get-date).addhours(-10))
- New-ADServiceAccount -name TestgMSA -DNSHostName testgmsa.company.pri -PrincipalsAllowedToRetrieveManagedPassword "Domain Computers"
- Add-ADComputerServiceAccount -Identity mydesktop -ServiceAccount TestgMSA
- Install-ADServiceAccount -Identity TestgMSA
- Test-ADServiceAccount -Identity TestgMSA
- New-Service -Name "TestService" -BinaryPathName "C:\WINDOWS\System32\svchost.exe -k netsvcs"
- ************************************************
- windows-server-2016-manage-maintain-ad-domain-services-m3
- ************************************************
- ***** -- Perform object- and container-level recovery
- Enable-ADOptionalFeature -Identity 'CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=company,DC=pri' -Scope ForestOrConfigurationSet -Target 'company.pri'
- Get-ADObject -Filter {displayName -eq "Dan Jones"} -IncludeDeletedObjects | Restore-ADObject
- ***** -- Clean up metadata
- ntdsutil
- metadata cleanup
- connections
- connect to server den-dc1
- quit
- select operation target
- list domains
- select domain X
- list sites
- select site Y
- list servers
- select server Z
- quit
- remove selected server
- yes
- quit
- ***** -- Monitor and manage replication
- repadmin /showrepl
- repadmin /showrepl PHX-DC1
- repadmin /showconn PHX-DC1
- repadmin /showobjmeta DEN-DC1 "CN=gshields,CN=users,DC=company,DC=pri"
- repadmin /kcc
- repadmin /kcc PHX-DC1
- repadmin /replsum
- repadmin /replicate DEN-DC1 DEN-DC2 "dc=company,dc=pri"
- repadmin /syncall DEN-DC1 "dc=company,dc=pri" /d /e
- dcdiag /s:den-dc1
- get-adreplicationconnection -server den-dc1
- get-adreplicationfailure -target phx-dc1
- #Query FSMO roles in AD environment
- netdom query fsmo
- #Move FSMO Roles Powershell
- Move-ADDirectoryServerOperationMasterRole -Identity “Target-DC” -OperationMasterRole SchemaMaster,RIDMaster,InfrastructureMaster,DomainNamingMaster,PDCEmulator
- #Enable AD Recycle Bin with PowerShell
- Import-module ActiveDirectory
- Run the following cmdlet to enable the Recycle Bin
- Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target <your forest root domain name>
- Here is an example using the ad.activedirectorypro.com domain.
- Enable-ADOptionalFeature 'Recycle Bin Feature' -Scope ForestOrConfigurationSet -Target ad.activedirectorypro.com
- How to Verify AD Recycle Bin is enabled
- Get-ADOptionalFeature -filter *
- #Get all Enabled Computer accounts
- Get-ADComputer -Filter 'operatingsystem -like "Windows 10*" -and enabled -eq "true"' -Property * | Format-Table Name,OperatingSystem,OperatingSystemServicePack,OperatingSystemVersion -Wrap -Auto
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement