Tuesday, October 17, 2017

Forcing password resets for a group of users

Management is always good for coming up with requests that are . . .unique.

In today's case, my management was planning to bring extra staff in to "help" with a push to force all staff members to change their network passwords. The initial plan on this was that these 'extras' would help by personally clicking through user accounts and flagging them to 'change password on next login'.

"Why can't we just script it?" I asked.

"Well we can't just set everyone to change their password we need to be able to exclude specific staff, and only force specific accounts to be forced to change. ". I was told in response.

"No problem..." I say.

There are plenty of samples out there for using command line and powershell commands to flag all members of an OU, or all users in a domain to have their passwords set to change on next logon, but I was unable to find what I needed to allow us to be more selective.

What I needed was a way to set "change password on next logon" for select staff quickly and with reporting. I decided to base my process on a windows group. Here's the script result and what it does.

- Checks the members of a group in AD, dumps that member list to a text file.
- Runs through the resulting list of names and sets them to change password on next login. 

*****Begin Script*****

# Output Variables
$GM = "c:\scripts\groupmembers.txt"
$results = "c:\scripts\changerequests.txt"

# Add AD module for queries
import-module ActiveDirectory

# Dump group members
get-adgroupmember -identity ForcePwdChange | select Name | Sort Name >$GM

# Prep results file
echo " ">$results

# Clean up group members data dump
(gc $GM | select -Skip 3) | sc $GM
$Lines = (gc $GM)
$Lines | ForEach-Object { $_.TrimEnd(); } | Out-File $GM -Encoding Ascii
(gc $GM) | ? {$_.trim() -ne "" } | sc $GM

# Process the list of names
$List = (gc $GM)
Foreach ($U in $List)
{
get-aduser -filter 'Name -like $U' | set-aduser -changepasswordatlogon:$true
echo "$U set to change password on next login" >>$results
echo "$U PWD set to change on next Logon"
echo " "
}
read-host "press any key to exit"

*****End Script*****

I need to do a bit of clean up with adding some error catching to this, but I'm posting it now to get it out there. ;) 

I've worked before with parsing the user lists from AD groups, and the sub-section included here for 'clean up group members data dump' is essential, because otherwise the user names won't get clearly read by powershell for the other actions we need. 

This solution is entirely situational . .but that's what scripting is meant to help with, situational issues. Hopefully this helps someone else out there.