To count user accounts in an organizational unit, run this powershell command: (Get-ADUser -Filter * -SearchBase “ou=Users,ou=A1,dc=contoso,dc=com”).count Where “ou=” is the path for your OU and “dc=” is yorur domain. My query runs against “contoso.com\users” Reference: http://idefixwiki.no/2013/10/23/ad-count-users-in-organizational-units/
Month: February 2015
MS: Metadata cleanup error: The directory service can perform the requested operation only on a leaf object.
I was doing an AD forest restore (blog will follow soon) - and was trying to do some metadata cleanup. The process I was giving me an error: DsRemoveDsDomainW error 0X2015(The directory service can perform the requested operation only on a leaf object.) Please note that the "domain management" command is for Server 2003 and was… Continue reading MS: Metadata cleanup error: The directory service can perform the requested operation only on a leaf object.
MS: Reset DSRM Password with Ntdsutil
Option 1: Reset DSRM Password with Ntdsutil On your machine, select Run from the Start menu, type ntdsutil and click OK. At the Ntdsutil command prompt, type set dsrm password. At the DSRM command prompt, run the Reset Password command, passing the name of the server on which to change the password, or use the… Continue reading MS: Reset DSRM Password with Ntdsutil
MS: Cleanup metadata using ntdsutil
From an administrative console: C:\Windows\system32>ntdsutil ntdsutil: metadata cleanup metadata cleanup: co server connections: connect to server localhost Binding to localhost ... Connected to localhost using credentials of locally logged on user. server connections: q metadata cleanup: se op ta select operation target: li do Found 1 domain(s) 0 - DC=site1,DC=domain,DC=root select operation target: se do 0… Continue reading MS: Cleanup metadata using ntdsutil
MS: error constructing or publishing certificate 0x80092013
After upgrading an issuing ADCS OS to Server2k12 I got this error: error constructing or publishing certificate: the revocation function was unable to check revocation because the revocation server was offline 0x80092013 So here's how I fixed it: Open an administrative cmd prompt from the ADCS server and type: certutil -CRL