Planehazza Posted February 14, 2022 Posted February 14, 2022 (edited) Having a massive house clean of AD, and the current phase is dist. list groups. We have a LOT at one school and many are no longer needed. I don't want to just delete them in case we get the inevitable complaint (we're auditing them and are giving staff notice so they should know to mark them as 'keep'). What's the best way to remove them? Simply move them to non synced OU so that we can move them back to quickly restore them? The risk of deleting them and having a request for its recreation in a year's time is all but 0%. All email lists are currently 'xxxxEngDept' (xxxx being DFE number) etc., but all remaining groups are being renamed to a more neat and professional name, so once a an email list is deleted, there is 0% chance a group will ever have that name again. Having said that, never say never... Edited February 14, 2022 by Planehazza
Mako Posted February 14, 2022 Posted February 14, 2022 I generally move them to a non-sync'd OU. Should do what you want while retaining them in on-premises AD.
chaplic Posted February 14, 2022 Posted February 14, 2022 In the AdminDescription field in AD, put Group_ This will stop the group from syncing to AAD, reversing it will see if reappear. Then set a calendar reminder to nuke them completely :-) 1
Planehazza Posted February 14, 2022 Author Posted February 14, 2022 (edited) In the AdminDescription field in AD, put Group_ This will stop the group from syncing to AAD, reversing it will see if reappear. Then set a calendar reminder to nuke them completely :-) Interesting, never heard of this. EDIT: Handy to know, thanks! Office 365 - The (Previously) Undocumented AAD Connect Filter - Perficient Blogs Edited February 14, 2022 by Planehazza
Planehazza Posted February 21, 2022 Author Posted February 21, 2022 Slight diversion from the original question... I need to rename ~40 AD dist. groups, which involves editing about 6 attributes each. We started with exchange hybrid, but we decommissioned our exchange server about 18 months ago. I would have, otherwise, simply use EMC to change them via PowerShell, but without an exchange server I cannot do this that I'm aware of. Anyone got any ideas how I could do this with powershell without an on prem exchange server?
chaplic Posted February 21, 2022 Posted February 21, 2022 All the attributes are in AD just use AD powershell, e.g. ProxyAddresses holds the email addresses. Owners of groups is trickier but doable.
Planehazza Posted February 21, 2022 Author Posted February 21, 2022 All the attributes are in AD just use AD powershell, e.g. ProxyAddresses holds the email addresses. Owners of groups is trickier but doable. That's what I thought too. I've obviously not tried hard enough with the cmdlets.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now