Tuesday, 22 April 2008

Do I need all the transaction log files Exchange creates?

Excellent posting here about Exchange transaction log files, in particular what to do if your transaction logs disk fills up.

www.exchangerecovery.org

Kind of handy when you come back to work after a week and the log file disk is full. ;-)

The main point I got from it was the fact that you do not necessarily need all of the transaction logs for a storage group. So say if your disk has filled up with transaction logs you can run eseutil to find out which log files you actually need and move the rest to a temporary location. This should then buy you some time to run a backup to flush the rest out properly.

Monday, 7 April 2008

Disabling Outlook Web Access on AD accounts

A request came up asking, "If we need to could we disable Outlook Web Access for a particuar list of users?"

After some digging around and some great help from Shay Levy on the Powergui message board I was able to come up with the following:

Set-QADUser 'springfield\homer.simpson' -ObjectAttributes @{ProtocolSettings='HTTP§0§1§§§§§§'}

If you need to disable more than one of the options it would be

Set-QADUser 'springfield\homer.simpson' -ObjectAttributes @{ProtocolSettings='HTTP§0§1§§§§§§,IMAP40§1§§§§§'}

The options detailed on the 'Exchange Features' tab of an AD account are stored in the ProtocolSettings field. If you look at that field in Adsiedit, you will see which options have been disabled, if any. From there you can grab the HTTP,IMAP etc string that you need.

More info here:
Making bulk protocolSettings changes

Friday, 28 March 2008

Add Users to an AD group from a CSV file

So I had a text file containing data in the following format:

username1.xxx.xxx.xxx.companyname

username2.xxx.xxx.xxx.companyname

username3.xxx.xxx.xxx.companyname

basically Novell usernames.

These accounts have equivalent usernames in Active Directory in the format

username1

username2

username3

ie. everything after the first dot is removed.


The task is to open up the text file, convert the Novell usernames to the AD format and then add each user to a group. With a bit of help from a post of Richard Siddaway's (http://richardsiddaway.spaces.live.com/blog/cns!43CFA46A74CF3E96!822.entry) the below script does the job.

(As usual the Quest AD cmdlets are required)

# Open the text file, split out each username at the first '.' and keep the first part of each split.
$users = Get-Content C:\Scripts\UserList.csv | %{$_.split(".")[0]}

# For each username get the user's AD DN and add the user to the specified group.
foreach ($a in $users)
{
Get-QADUser -Identity $a | Add-QADGroupMember -Identity 'domainname\groupname'
}

Monday, 24 March 2008

ADMT and Windows Server 2008

Need to migrate from 2003 to 2008 using ADMT 3.0? Looks like you might be able to do it before the 3.1 release which supports 2008. Some great info here:

http://blogs.technet.com/ad/archive/2008/03/10/admt-and-server-2008.aspx

Tuesday, 18 March 2008

VMware Powershell Cmdlets

These are going to be seriously useful.......

http://blogs.vmware.com/vipowershell/

I've been trying them out with some basic Get-VM commands and it is so easy to get info out of your VM infrastructure.

Friday, 14 March 2008

Friday, 7 March 2008

Find Last Logon Date

This script will find the last logon date for a supplied user on each DC in your domain and output to a text file. You can then pull the text file say into Excel and sort on the date column to find when the user last logged in.

(You need the Quest AD cmdlets to run this one)

$DomainControllers = Get-QADComputer -computerrole domainController

foreach ($DC in $DomainControllers)

{
$a = Get-QADUser -Service $DC.name 'domain\user'
$dc.name +" " +$a.lastlogon | Out-File -Append C:\Scripts\LastLogon.txt
}