{"id":2063,"date":"2015-03-11T23:10:17","date_gmt":"2015-03-11T21:10:17","guid":{"rendered":"http:\/\/www.windows-infrastructure.de\/?p=2063"},"modified":"2021-03-06T18:09:00","modified_gmt":"2021-03-06T16:09:00","slug":"change-users-primary-group-powershell","status":"publish","type":"post","link":"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/","title":{"rendered":"Change a Users primary group with Powershell"},"content":{"rendered":"

beim Versuch\u00a0die Primary Group eines Users zu l\u00f6schen, l\u00e4uft der Befehl zwangsl\u00e4ufig in einen Fehler. „The user cannot be removed from a group because the group is currently the user’s primary group“<\/em> . Jeder User muss by Design im Besitz einer Primary Group sein, weshalb nur die M\u00f6glichkeit bleibt, eine andere Gruppe als prim\u00e4re zu setzen.
\nNils Kaczenski hat hierzu einen sehr guten\u00a0Artikel verfasst;\u00a0Die Primary Group in Active Directory<\/a><\/p>\n<\/span>\n

Der User wird aus der standard Gruppe „Domain Users“\u00a0entfernt. Dazu wird er\u00a0Mitglied einer zweiten Gruppe, die zu seiner primary group ge\u00e4ndert\u00a0wird.<\/p>\n

<\/span><\/span><\/p>\n

1. Gruppe „FGPP_802.1x_MAB_Users“ wird dem User „ABCDEF123456789“\u00a0hinzugef\u00fcgt<\/p>\n

Add-ADGroupMember -Identity FGPP_802.1x_MAB_Users -Members ABCDEF123456789 -ErrorAction SilentlyContinue<\/pre>\n

<\/span>\"member<\/p>\n

 <\/p>\n

 <\/p>\n

<\/span><\/span><\/p>\n

2. Auslesen der PrimaryGroupID des Users (Domain Users entspricht immer 513)<\/p>\n

get-aduser ABCDEF123456789 -Properties PrimaryGroupID<\/pre>\n

<\/span><\/span><\/p>\n

3.\u00a0Bei der Gruppe heist das Attribut PrimaryGroupToken<\/em>, und entspricht dem RID (relative identifier) der SID<\/p>\n

Get-ADGroup \"domain users\" -Properties PrimaryGroupToken\r\n\r\nPrimaryGroupToken : 513<\/pre>\n

<\/span><\/span><\/p>\n

4. Das selbe wird bei der Gruppe ausgelesen, die als primary group gesetzt werden soll<\/p>\n

PS C:\\Windows\\system32> Get-ADGroup FGPP_802.1x_MAB_Users -Properties PrimaryGroupToken\r\n\r\nPrimaryGroupToken : 1728<\/pre>\n

<\/span><\/span><\/p>\n

5. mit set-aduser wird dem user die PrimaryGroupID 1728 zugewiesen<\/p>\n

Set-aduser -identity ABCDEF123456789 -Replace @{PrimaryGroupID=\"1728\"}\r\n\r\nGet-aduser ABCDEF123456789 -Properties PrimaryGroupID<\/pre>\n

 <\/p>\n

 <\/p>\n

\"member<\/p>\n

<\/span><\/span><\/p>\n

6. die Gruppe „domain users“ wird entfernt<\/p>\n

remove-adgroupmember -identity \"domain users\" -members ABCDEF123456789 -confirm:$false<\/pre>\n

 <\/p>\n

 <\/p>\n","protected":false},"excerpt":{"rendered":"

beim Versuch\u00a0die Primary Group eines Users zu l\u00f6schen, l\u00e4uft der Befehl zwangsl\u00e4ufig in einen Fehler. „The user cannot be removed from a group because the group is currently the user’s primary group“ . Jeder User muss by Design im Besitz… Weiterlesen →<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":2078,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[10],"tags":[143,142],"yoast_head":"\nChange a Users primary group with Powershell - windows-infrastructure.de<\/title>\n<meta name=\"description\" content=\"Bevor die primary group ge\u00e4ndert werden kann, wird dem User eine zus\u00e4tzliche Gruppe zugewiesen, die anschliessend primary group wird. Die Standard Gruppe "Domain Users" wird danach gel\u00f6scht\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Change a Users primary group with Powershell - windows-infrastructure.de\" \/>\n<meta property=\"og:description\" content=\"Bevor die primary group ge\u00e4ndert werden kann, wird dem User eine zus\u00e4tzliche Gruppe zugewiesen, die anschliessend primary group wird. Die Standard Gruppe "Domain Users" wird danach gel\u00f6scht\" \/>\n<meta property=\"og:url\" content=\"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/\" \/>\n<meta property=\"og:site_name\" content=\"windows-infrastructure.de\" \/>\n<meta property=\"article:published_time\" content=\"2015-03-11T21:10:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-03-06T16:09:00+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/www.windows-infrastructure.de\/wp-content\/uploads\/hc_0125.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"422\" \/>\n\t<meta property=\"og:image:height\" content=\"463\" \/>\n<meta name=\"twitter:label1\" content=\"Gesch\u00e4tzte Lesezeit\">\n\t<meta name=\"twitter:data1\" content=\"1 Minute\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"http:\/\/www.windows-infrastructure.de\/#website\",\"url\":\"http:\/\/www.windows-infrastructure.de\/\",\"name\":\"windows-infrastructure.de\",\"description\":\"Windows Server Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"http:\/\/www.windows-infrastructure.de\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"de-DE\"},{\"@type\":\"ImageObject\",\"@id\":\"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/#primaryimage\",\"inLanguage\":\"de-DE\",\"url\":\"http:\/\/www.windows-infrastructure.de\/wp-content\/uploads\/hc_0125.jpg\",\"width\":422,\"height\":463,\"caption\":\"member of active directory primary group domain users\"},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/#webpage\",\"url\":\"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/\",\"name\":\"Change a Users primary group with Powershell - windows-infrastructure.de\",\"isPartOf\":{\"@id\":\"http:\/\/www.windows-infrastructure.de\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/#primaryimage\"},\"datePublished\":\"2015-03-11T21:10:17+00:00\",\"dateModified\":\"2021-03-06T16:09:00+00:00\",\"author\":{\"@id\":\"http:\/\/www.windows-infrastructure.de\/#\/schema\/person\/60ba29b74ac5d95d2d152448d563e4a8\"},\"description\":\"Bevor die primary group ge\\u00e4ndert werden kann, wird dem User eine zus\\u00e4tzliche Gruppe zugewiesen, die anschliessend primary group wird. Die Standard Gruppe \\\"Domain Users\\\" wird danach gel\\u00f6scht\",\"inLanguage\":\"de-DE\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/www.windows-infrastructure.de\/change-users-primary-group-powershell\/\"]}]},{\"@type\":\"Person\",\"@id\":\"http:\/\/www.windows-infrastructure.de\/#\/schema\/person\/60ba29b74ac5d95d2d152448d563e4a8\",\"name\":\"Holger Wache\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"http:\/\/www.windows-infrastructure.de\/#personlogo\",\"inLanguage\":\"de-DE\",\"url\":\"http:\/\/www.windows-infrastructure.de\/wp-content\/uploads\/Holger1.png\",\"caption\":\"Holger Wache\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/posts\/2063"}],"collection":[{"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/comments?post=2063"}],"version-history":[{"count":12,"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/posts\/2063\/revisions"}],"predecessor-version":[{"id":2346,"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/posts\/2063\/revisions\/2346"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/media\/2078"}],"wp:attachment":[{"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/media?parent=2063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/categories?post=2063"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.windows-infrastructure.de\/wp-json\/wp\/v2\/tags?post=2063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}