Page 1 of 1 1
Topic Options
#44396 - 2003-08-21 04:40 PM InGroup for Active Directory / Win2K Professional
David H Offline
Lurker

Registered: 2003-08-21
Posts: 3
Hi,

I am attempting to map different drives for different global-security groups in AD. Simple thing right? Well I created my own group called "NY Docket". Whenever I try to logon a user that is within this group, nothing happens. When I rem out my "Domain Admins" from the script, it also does nothing (just to be sure).

But if I change the "NY Docket" group to "Domain Admins" (which is a default created Active Directory group, not user created), it works just fine. What gives? Is there some property to the default AD group "Domain Admins" that my user created "NY Docket" doesn't have? Do I need to read some other aspect out of Active Directory to get this to work? My script is below. Thanks.

----------------------------------------------------

; DRIVE MAPPING SECTION BY GROUP

?color w+/n "Checking Groups..."
use * /delete /persistent:yes

If InGroup ("Domain Admins")
?color w+/n "Welcome Administrator. Mapping your drives..."
use w: "\\ny-san-01\prgm"

If InGroup ("NY Docket")
?color w+/n "Welcome to FCHS Docketing. Mapping Drives and Printers..."
use f: "\\docketing\d$"
use g: "\\docketing\d$"
_________________________
-David H

Top
#44397 - 2003-08-21 04:48 PM Re: InGroup for Active Directory / Win2K Professional
Radimus Moderator Offline
Moderator
*****

Registered: 2000-01-06
Posts: 5187
Loc: Tampa, FL
you cannot get computer OU info from the ingroup function.

you can do:
code:
	$Computers = GetObject($LDAPofOU)
For each $Item in $computers
$cn=$Item.name
$name=right($cn, len($cn)-3)
next

or wrap this in a function...
_________________________
How to ask questions the smart way <-----------> Before you ask

Top
#44398 - 2003-08-21 04:52 PM Re: InGroup for Active Directory / Win2K Professional
David H Offline
Lurker

Registered: 2003-08-21
Posts: 3
If you read my post, you'll se that this has nothing to do with computers at all, but with Active Directory users in a global security group.
_________________________
-David H

Top
#44399 - 2003-08-21 04:55 PM Re: InGroup for Active Directory / Win2K Professional
Radimus Moderator Offline
Moderator
*****

Registered: 2000-01-06
Posts: 5187
Loc: Tampa, FL
yep.. you are right... nothing to do with computers.

ensure the users have permission to read the from the OU in which the group is located.
_________________________
How to ask questions the smart way <-----------> Before you ask

Top
#44400 - 2003-08-21 05:25 PM Re: InGroup for Active Directory / Win2K Professional
David H Offline
Lurker

Registered: 2003-08-21
Posts: 3
The aren't in any separate OU other than the default domain --> users container. This is Active Directory default. We haven't implemented any OUs.
_________________________
-David H

Top
#44401 - 2003-08-21 05:27 PM Re: InGroup for Active Directory / Win2K Professional
Radimus Moderator Offline
Moderator
*****

Registered: 2000-01-06
Posts: 5187
Loc: Tampa, FL
from a cmd prompt, verify that the groups are accessable by:
net group "NY Docket" /domain

then execute kix32 /f to flush the cache
_________________________
How to ask questions the smart way <-----------> Before you ask

Top
#44402 - 2003-08-21 07:26 PM Re: InGroup for Active Directory / Win2K Professional
Howard Bullock Offline
KiX Supporter
*****

Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
Also review: RESOLVED - BUG Help 4.01 INGROUP Failures and RESOLVED - BUG 4.01 ENUMGROUP Failures as I think that these are required reading when working with groups.
_________________________
Home page: http://www.kixhelp.com/hb/

Top
#44403 - 2003-08-21 08:16 PM Re: InGroup for Active Directory / Win2K Professional
Mike C Offline
Fresh Scripter

Registered: 2002-08-20
Posts: 10
Loc: Ontario, Canada
I am experiencing pretty much the same problem with trying call another script based on group membership. We use W2K pro and W2K severs only and are running ver 4.01.

I can add 15 users to a group and all will work but 2 or 3. I have cleared the cache and verified they are group members. I also logged off and on - many times [Frown]

I must also state that I am not real experienced with scripting.

Any help would be much appreciated.

Thanks
Mike

Top
#44404 - 2003-08-21 08:27 PM Re: InGroup for Active Directory / Win2K Professional
Howard Bullock Offline
KiX Supporter
*****

Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
Also try to qualify your group name with like:

InGroup("domain\group1")

Does this make a difference.
_________________________
Home page: http://www.kixhelp.com/hb/

Top
#44405 - 2003-08-21 08:56 PM Re: InGroup for Active Directory / Win2K Professional
Mike C Offline
Fresh Scripter

Registered: 2002-08-20
Posts: 10
Loc: Ontario, Canada
Thanks, I tried that but it made no difference.

Mike

Top
Page 1 of 1 1


Moderator:  Jochen, Allen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Arend_, Mart 
Hop to:
Shout Box

Who's Online
0 registered and 2220 anonymous users online.
Newest Members
Viginette, ManuvdWielNL, Sir_Barrington, batdk82, StuTheCoder
17888 Registered Users

Generated in 0.074 seconds in which 0.039 seconds were spent on a total of 12 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org