Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Script to install program based on AD group


Recommended Posts

Posted (edited)

Hi,

 

I would like a script that will install an application based on the AD group. I have the app and the switches.

 

I would like it so it checks if the computer is in a group and if it is then check if a file exists on the local machine if it doesn't then run the installer. If not run to the next command for the next bit of software and so on..

 

I would like it in .bat but i suspect it might need to be .vbs

 

Does anyone have anything please?

 

Thanks

Edited by FN-GM
Posted

If you use a GPO to apply it as a startup script to a spceific OU then only machines in that OU will run it.

 

You can then do it in a batch file and use the if not exist or if exist statements in your batch file to control what is run.

 

Ben

Posted
If you use a GPO to apply it as a startup script to a spceific OU then only machines in that OU will run it.

I know that but i dont wish to go down that route. We will have lots of different apps on different machines and doing that will make things messy.

 

thanks anyway

Posted

Ok then use groups to control who the gpo is applied to instead then saves needing to read ad groups from within your script and makes that simpler as well.

 

Ben

Posted
Ok then use groups to control who the gpo is applied to instead then saves needing to read ad groups from within your script and makes that simpler as well.

 

Ben

 

I dont want to do that either. I know how to do this but as i originally asked for i would like a script to do this.

Posted
I would like it so it checks if the computer is in a group and if it is then check if a file exists on the local machine if it doesn't then run the installer.

 

We have a .vbs login script to assign printers by OU of the user or machine, if that's any use to get you started:

 

Option Explicit
on error resume next

Dim objNetwork, objSysInfo, strUserDN
Dim objGroupList, objUser, objFSO
Dim strComputerDN, objComputer, user

Set objNetwork = CreateObject("Wscript.Network")
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objSysInfo = CreateObject("ADSystemInfo")
strUserDN = objSysInfo.userName
strComputerDN = objSysInfo.computerName

' Bind to the user and computer objects with the LDAP provider.
Set objUser = GetObject("LDAP://" & strUserDN)
Set objComputer = GetObject("LDAP://" & strComputerDN)

' Not quite sure why this is in a loop - maybe you just have to wait for Windows to get back to you?
Do While User = ""
User = lcase(objNetwork.UserName)
Loop

if InStr(strComputerDN, "OU=Staff Room") then
   Run command goes here.
end if

  • 2 weeks later...
Posted
We have a .vbs login script to assign printers by OU of the user or machine, if that's any use to get you started:

 

Option Explicit
on error resume next

Dim objNetwork, objSysInfo, strUserDN
Dim objGroupList, objUser, objFSO
Dim strComputerDN, objComputer, user

Set objNetwork = CreateObject("Wscript.Network")
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objSysInfo = CreateObject("ADSystemInfo")
strUserDN = objSysInfo.userName
strComputerDN = objSysInfo.computerName

' Bind to the user and computer objects with the LDAP provider.
Set objUser = GetObject("LDAP://" & strUserDN)
Set objComputer = GetObject("LDAP://" & strComputerDN)

' Not quite sure why this is in a loop - maybe you just have to wait for Windows to get back to you?
Do While User = ""
User = lcase(objNetwork.UserName)
Loop

if InStr(strComputerDN, "OU=Staff Room") then
   Run command goes here.
end if

 

Thanks, but i am not good enough to pull that apart.

 

Does anyone have anything please?

 

Thanks

Posted
Thanks, but i am not good enough to pull that apart.

 

You can just cut-and-paste most of that code - it simply sets up a couple of objects to then use to query active directory. You just need to edit the last 3 lines:

 

if InStr(strComputerDN, "OU=Staff Room") then

Run command goes here.

end if

 

In this case, replace "Staff Room" with the name of the organisational unit (OU) your computers are in, then add any commands you want to run in the "Run command goes here" - you can simply run an external command:

 

Set objShell = WScript.CreateObject("WScript.Shell")

objShell.Run "\\server\path\myfile.bat", 1, True

 

A quick Google for "vbs if file exists" seems to bring up a bunch of code to check if a file exists or not.

  • 3 weeks later...
Posted

HI

 

What you could do is create a group and put all the computers that you want to install install the program into the group.

 

Now create the script to install the program and set the ntfs permissions so that one the group can read it and link the script up to the domain as a group policy low down. I think this is a very strange way of wanting to do this but it would work,

 

The other way you could do this is with environmental variables. On each machine set an environmental variables. We used to do this with printers say a room number. Then get the script to look for this. I am sorry I dont have the scripts we used here as I am at home.

 

Richard

Posted
HI

 

What you could do is create a group and put all the computers that you want to install install the program into the group.

 

Now create the script to install the program and set the ntfs permissions so that one the group can read it and link the script up to the domain as a group policy low down. I think this is a very strange way of wanting to do this but it would work,

 

The other way you could do this is with environmental variables. On each machine set an environmental variables. We used to do this with printers say a room number. Then get the script to look for this. I am sorry I dont have the scripts we used here as I am at home.

 

Richard

 

I did think of that but it's abit of a messy way to be honest.

Posted
Can you not setup in gpo so that it only applies if machines are in a group like you can with users?

 

As said before i am well aware of that but i do not wish to do that

 

@mac_shinobi seen them but they are for checking users, not computers.

Posted

Dim objNetwork
Set objNetwork = CreateObject("WScript.Network")

Dim objWinntComp
Set objWinntComp = GetObject("WinNT://" & objNetwork.UserDomain & "/" & objNetwork.ComputerName & ",computer")
MsgBox "WinNT://" & objNetwork.UserDomain & "/" & objNetwork.ComputerName & ",computer"

Dim strGroupToCheck
strGroupToCheck = "Jack_grp"

If IsMemberOfGroup(objNetwork.UserDomain, objWinntComp, strGroupToCheck) = True Then
     MsgBox "You are a member of " & strGroupToCheck
ElseIf IsMemberOfGroup(objNetwork.UserDomain, objWinntComp, strGroupToCheck) = False Then
     MsgBox "You are NOT a member of " & strGroupToCheck
     WScript.Quit
ElseIf IsMemberOfGroup(objNetwork.UserDomain, objWinntComp, strGroupToCheck) = "Error" Then
     MsgBox "There was no group found called " & strGroupToCheck
     WScript.Quit
End If      

Function IsMemberOfGroup(strUserDomain, objComp, strGroup) 'the user is a member of a specified group
     IsMemberOfGroup = False
     Dim objGroup
     On Error Resume Next
     Set objGroup = GetObject("WinNT://" & strUserDomain & "/" & strGroup & ",group")
     If Err.Number Then
           IsMemberOfGroup = "Error"
     Else
           IsMemberOfGroup = objGroup.IsMember(objComp.ADsPath & "$")
     End If
End Function

 

Determine computer group membership in VBScript : group, computer, vbscript, membership, determine

 

Also

 

Checking Group Membership in VBScript - CyrusBuilt dot Net

Posted

Could you do something like this in PowerShell, but instead of running "dir" on each computer remotely, you use the Test-Path cmdlet to check if a file/folder/registry key exists and then Start-Process to execute your installer with the relevant parameters?

 

if(!(Get-Module | Where { $_.name -eq "ActiveDirectory" })) {
   Import-Module ActiveDirectory -ErrorAction 0 | Out-Null
}

Invoke-Command -Command { [color="#FF0000"]dir[/color] } -ComputerName ( Get-ADGroupMember "[color="#000080"]Example App v1.0[/color]" -recursive | Select-Object -expand Name ) -ThrottleLimit 32 -ErrorAction SilentlyContinue

Posted
Thanks i will have a play about. I dont think i will be good enough to master this on my own though. I will give it a shot and see what happens.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...