Skip to main content

How do you provide alternate credentials to a script?

Providing alternate credentials allows scripts to run while a non administrator is logged into the client. I found script samples for this on

The following code was taken from WindowsITPro.comL

LISTING 1: ADSI Script That Uses Alternate Credentials Const

ADS_SECURE_AUTHENTICATION = 1 strUserDN = "cn=Administrator,cn=Users,dc=acme,dc=com"strPassword = "bXk23s8w" ' BEGIN CALLOUT ASet objRoot = GetObject("LDAP:")Set objDomain = _ objRoot.OpenDSObject("LDAP://dc=acme,dc=com", _ strUserDN, strPassword, ADS_SECURE_AUTHENTICATION)' END CALLOUT A Set objOU = objDomain.Create("organizationalUnit", "ou=Students")objOU.Put "Description", "Student OU"objOU.SetInfo Set objGroup = objOU.Create("Group", "cn=Seniors")objGroup.Put "sAMAccountName", "Seniors"objGroup.Put "Description", "Seniors"objGroup.SetInfo Set objUser = objOU.Create("User", "cn=Student1")objUser.Put "sAMAccountName", "Student1"objUser.Put "Description", "Student1"objUser.SetInfo objGroup.Add objUser.ADSPath

LISTING 2: WMI Script That Uses Alternate Credentials Const

wbemImpersonationLevelImpersonate = 3 strComputer = "foo"strUser = "Administrator"strPassword = "bXk23s8w" ' BEGIN CALLOUT ASet objSWbemLocator = _ CreateObject("WbemScripting.SWbemLocator")objSWbemLocator.Security_.ImpersonationLevel = _ wbemImpersonationLevelImpersonateSet objSWbemServices = _ objSWbemLocator.ConnectServer(strComputer, _ "root\cimv2", strUser, strPassword)' END CALLOUT A Set colSWbemObjectSet = _ objSWbemServices.ExecQuery("SELECT * FROM “ _ & “Win32_OperatingSystem") For Each objSWbemObject In colSWbemObjectSet WScript.Echo "Name: " & objSWbemObject.Name WScript.Echo "Caption: " & objSWbemObject.CaptionBEGIN COMMENT ' Insert additional Win32_OperatingSystem properties here.END COMMENTNext


Popular posts from this blog

Adding a Comment to a GPO with PowerShell

As I'm writing this article, I'm also writing a customization for a PowerShell course I'm teaching next week in Phoenix.  This customization deals with Group Policy and PowerShell.  For those of you who attend my classes may already know this, but I sit their and try to ask the questions to myself that others may ask as I present the material.  I finished up my customization a few hours ago and then I realized that I did not add in how to put a comment on a GPO.  This is a feature that many Group Policy Administrators may not be aware of. This past summer I attended a presentation at TechEd on Group Policy.  One organization in the crowd had over 5,000 Group Policies.  In an environment like that, the comment section can be priceless.  I always like to write in the comment section why I created the policy so I know its purpose next week after I've completed 50 other tasks and can't remember what I did 5 minutes ago. In the Group Policy module for PowerShell V3, th

Return duplicate values from a collection with PowerShell

If you have a collection of objects and you want to remove any duplicate items, it is fairly simple. # Create a collection with duplicate values $Set1 = 1 , 1 , 2 , 2 , 3 , 4 , 5 , 6 , 7 , 1 , 2   # Remove the duplicate values. $Set1 | Select-Object -Unique 1 2 3 4 5 6 7 What if you want only the duplicate values and nothing else? # Create a collection with duplicate values $Set1 = 1 , 1 , 2 , 2 , 3 , 4 , 5 , 6 , 7 , 1 , 2   #Create a second collection with duplicate values removed. $Set2 = $Set1 | Select-Object -Unique   # Return only the duplicate values. ( Compare-Object -ReferenceObject $Set2 -DifferenceObject $Set1 ) . InputObject | Select-Object – Unique 1 2 This works with objects as well as numbers.  The first command creates a collection with 2 duplicates of both 1 and 2.   The second command creates another collection with the duplicates filtered out.  The Compare-Object cmdlet will first find items that are diffe

How to list all the AD LDS instances on a server

AD LDS allows you to provide directory services to applications that are free of the confines of Active Directory.  To list all the AD LDS instances on a server, follow this procedure: Log into the server in question Open a command prompt. Type dsdbutil and press Enter Type List Instances and press Enter . You will receive a list of the instance name, both the LDAP and SSL port numbers, the location of the database, and its status.