<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://www.rabbibob.com/index.php?action=history&amp;feed=atom&amp;title=Powershell%3A_Remove_AD_Group_Memberships_from_OU</id>
	<title>Powershell: Remove AD Group Memberships from OU - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://www.rabbibob.com/index.php?action=history&amp;feed=atom&amp;title=Powershell%3A_Remove_AD_Group_Memberships_from_OU"/>
	<link rel="alternate" type="text/html" href="https://www.rabbibob.com/index.php?title=Powershell:_Remove_AD_Group_Memberships_from_OU&amp;action=history"/>
	<updated>2026-04-29T00:13:51Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.5</generator>
	<entry>
		<id>https://www.rabbibob.com/index.php?title=Powershell:_Remove_AD_Group_Memberships_from_OU&amp;diff=1336&amp;oldid=prev</id>
		<title>Rabbi Bob: /* Code */ Yikes, had Doman Users in the remove, should fail, but oof</title>
		<link rel="alternate" type="text/html" href="https://www.rabbibob.com/index.php?title=Powershell:_Remove_AD_Group_Memberships_from_OU&amp;diff=1336&amp;oldid=prev"/>
		<updated>2019-05-24T14:06:52Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Code: &lt;/span&gt; Yikes, had Doman Users in the remove, should fail, but oof&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 14:06, 24 May 2019&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l50&quot;&gt;Line 50:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 50:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     Get-ADGroup -LDAPFilter &amp;quot;(member=$UserDN)&amp;quot; | foreach-object {&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;     Get-ADGroup -LDAPFilter &amp;quot;(member=$UserDN)&amp;quot; | foreach-object {&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;         #if ($_.name -notin &amp;quot;Domain Users&amp;quot;,&amp;quot;RandomSecGrp&amp;quot;)   #EXCLUSION - slightly more dangerous&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;         #if ($_.name -notin &amp;quot;Domain Users&amp;quot;,&amp;quot;RandomSecGrp&amp;quot;)   #EXCLUSION - slightly more dangerous&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;         if ($_.name -in &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;Domain Users&amp;quot;,&lt;/del&gt;&amp;quot;RandomSecGrp&amp;quot;,&amp;quot;AnotherRandomSecGrp&amp;quot;,&amp;quot;YARSG&amp;quot;,&amp;quot;WeGetIt_AnotherSecGrp&amp;quot;)&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;         if ($_.name -in &amp;quot;RandomSecGrp&amp;quot;,&amp;quot;AnotherRandomSecGrp&amp;quot;,&amp;quot;YARSG&amp;quot;,&amp;quot;WeGetIt_AnotherSecGrp&amp;quot;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;             {&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;             {&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;                 $Group=$_.name&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;                 $Group=$_.name&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key mw_RabbiBob_139-wiki_:diff::1.12:old-1334:rev-1336 --&gt;
&lt;/table&gt;</summary>
		<author><name>Rabbi Bob</name></author>
	</entry>
	<entry>
		<id>https://www.rabbibob.com/index.php?title=Powershell:_Remove_AD_Group_Memberships_from_OU&amp;diff=1334&amp;oldid=prev</id>
		<title>Rabbi Bob: Created page with &quot;=Purpose= This script was an extension of Powershell: AD Group Membership from OU and is quite dangerous.  It will run through the designated OU and remove any security gr...&quot;</title>
		<link rel="alternate" type="text/html" href="https://www.rabbibob.com/index.php?title=Powershell:_Remove_AD_Group_Memberships_from_OU&amp;diff=1334&amp;oldid=prev"/>
		<updated>2019-05-23T20:22:31Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;=Purpose= This script was an extension of &lt;a href=&quot;/index.php/Powershell:_AD_Group_Membership_from_OU&quot; title=&quot;Powershell: AD Group Membership from OU&quot;&gt;Powershell: AD Group Membership from OU&lt;/a&gt; and is quite dangerous.  It will run through the designated OU and remove any security gr...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Purpose=&lt;br /&gt;
This script was an extension of [[Powershell: AD Group Membership from OU]] and is quite dangerous.  It will run through the designated OU and remove any security groups designated (or you can give it a list to ignore, which is even more dangerous if you the list is empty).  Has very basic logging to csv so you could rebuild if you had to.&lt;br /&gt;
&lt;br /&gt;
==To Do==&lt;br /&gt;
* build in a failsafe check ala DO YOU REALLY WANT TO DO THIS?&lt;br /&gt;
* build in a check for OUs never to run against (allow a list of OU&amp;#039;s to be programmed that you couldn&amp;#039;t run this against)&lt;br /&gt;
* figure out a variable check for Test vs Nuke vs Confirm (maybe default to Test)&lt;br /&gt;
* learn how to read in from a list into an array for a .ignore list (or .nuke list)&lt;br /&gt;
&lt;br /&gt;
=Code=&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
##################################################&lt;br /&gt;
## Remove Groups from Users found in target $OU ##&lt;br /&gt;
##################################################&lt;br /&gt;
## To Do&lt;br /&gt;
##  - Build Output to Log [Done]&lt;br /&gt;
##  - Add Flag for Test vs Nuke vs Confirm&lt;br /&gt;
##  - Warning and Confirmation&lt;br /&gt;
##################################################&lt;br /&gt;
## Test&lt;br /&gt;
##  - Multiple -ne in If&lt;br /&gt;
##  - Array of Groups to ignore&lt;br /&gt;
##################################################&lt;br /&gt;
# Research: powershell pass variable to parameter&lt;br /&gt;
# https://stackoverflow.com/questions/46121939/passing-a-powershell-variable-as-a-cmdlet-parameter&lt;br /&gt;
##################################################&lt;br /&gt;
###################################################&lt;br /&gt;
## User Variables&lt;br /&gt;
&lt;br /&gt;
#$OU = &amp;quot;OU=,OU=,OU=,OU=,DC=rabbibob,DC=com&amp;quot;&lt;br /&gt;
$OU = &amp;quot;OU=Users,DC=rabbibob,DC=com&amp;quot;&lt;br /&gt;
####################################################&lt;br /&gt;
&lt;br /&gt;
## Logging Setup&lt;br /&gt;
$Logfile = &amp;quot;AD_RemoveGroups_CleanUp_20190523.log&amp;quot;&lt;br /&gt;
Function LogWrite&lt;br /&gt;
{&lt;br /&gt;
   Param ([string]$logstring)&lt;br /&gt;
&lt;br /&gt;
   Add-content $Logfile -value $logstring&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
# Start&lt;br /&gt;
&lt;br /&gt;
$GetOU = Get-ADUser -SearchBase $OU -Filter *&lt;br /&gt;
foreach ($user in $GetOU) &lt;br /&gt;
    {&lt;br /&gt;
    $UserDN = $user.DistinguishedName&lt;br /&gt;
    $Name=$user.SamAccountName &lt;br /&gt;
    Get-ADGroup -LDAPFilter &amp;quot;(member=$UserDN)&amp;quot; | foreach-object {&lt;br /&gt;
        #if ($_.name -notin &amp;quot;Domain Users&amp;quot;,&amp;quot;RandomSecGrp&amp;quot;)   #EXCLUSION - slightly more dangerous&lt;br /&gt;
        if ($_.name -in &amp;quot;Domain Users&amp;quot;,&amp;quot;RandomSecGrp&amp;quot;,&amp;quot;AnotherRandomSecGrp&amp;quot;,&amp;quot;YARSG&amp;quot;,&amp;quot;WeGetIt_AnotherSecGrp&amp;quot;)&lt;br /&gt;
            {&lt;br /&gt;
                $Group=$_.name&lt;br /&gt;
                $LogLine = $Name+&amp;quot;,&amp;quot;+$Group &lt;br /&gt;
                LogWrite $LogLine&lt;br /&gt;
                write-host &amp;quot;$Name - $Group&amp;quot;&lt;br /&gt;
				### RUN WITHOUT CONFIRMATION&lt;br /&gt;
				remove-adgroupmember -identity $Group -member $UserDN &lt;br /&gt;
				### RUN WITH CONFIRMATION&lt;br /&gt;
				#remove-adgroupmember -identity $Group -member $UserDN -Confirm:$False&lt;br /&gt;
            } &lt;br /&gt;
        }&lt;br /&gt;
    }   &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
[[Category:Powershell]]&lt;br /&gt;
[[Category:Weblog-2019-05]]&lt;/div&gt;</summary>
		<author><name>Rabbi Bob</name></author>
	</entry>
</feed>