清理离职用户账户所属组
#查询出相应的OU下面的离职账号
$users = get-aduser -Filter * -SearchBase ""OU=xxxx,DC=test,DC=com"" | foreach {if ($.enabled -eq $false){echo $.samaccountname}}
#获取当前的日期
$data=get-date -Format 'yyyyMMdd'
#使用循环记录日志并删除对应的组
foreach($user in $users)
{
Get-ADUser -Identity $user -Properties * |select name,memberof |fl >>d:\$data.txt
Get-ADPrincipalGroupMembership -Identity $user | where{$.name -notlike ""domain users""} | % { Remove-ADPrincipalGroupMembership -Identity $user -MemberOf $ -Confirm:$false -ErrorAction SilentlyContinue }
}
write-host ""移除完成!!""

浙公网安备 33010602011771号