Active Directory

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Change the default UPN for a domain

    With companies changing UPN's on user accounts due to things like O365 migrations, make it possible to change and set the default UPN used for new user creation in a domain.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  2. Get-ADUser PasswordExpirationDate

    The Get-ADUser cmdlet should optionally return a "PasswordExpirationDate" attribute that is derived from "msDS-UserPasswordExpiryTimeComputed" and shown in a friendly format.

    This is already done for PasswordLastSet from pwdLastSet and perhaps other attributes.

    Without this enhancement, we must parse and convert the time such as:
    $user = Get-ADUser -Properties msDS-UserPasswordExpiryTimeComputed sAMAccountName
    ([datetime]::fromfiletime([int64]::parse(($user)."msDS-UserPasswordExpiryTimeComputed"))).tostring()

    Or we resort to non-PowerShell tools:
    net user sAMAccountName /domain

    9 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  3. Port Active Directory Module to PowerShell Core and Make Cross Platform

    Active Directory is used for more than just Windows Environments. Traditionally, scripting languages, such as python, have been used in the Linux space to perform automation against Active Directory. Now that PowerShell Core 6.0.X is GA, it would be great if the Active Directory module could be ported to be compatible with PowerShell Core and made cross-platform compatible. This would enable PowerShell based Active Directory management and automation possibilities from Linux, Mac, and IoT in addition to Windows.

    Currently, PSSnapin dependencies in the AD module make it impossible to use in PowerShell Core. This leaves AD as one of the…

    169 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  4. Set-GpPermission - Add a "Force" parameter

    The Set-GpPermission PowerShell cmdlet generates a prompt when attempting to remove the "Authenticated Users" permission from a GPO. There is no way to avoid this, which makes programmatic GPO creation very difficult. Please add a "-Force" parameter to avoid this prompt, or make the "-Confirm:$False" parameter also apply to this prompt.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  5. 000

    000

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  6. 000

    000

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  7. Replace gpresult with a PowerShell cmdlet

    GPResult served us well when support was done manually on each client from the keyboard. What we need now is a cmdlet that we can use when remoting into a PC and get results that are applied to the PC, including polices that are not applied.

    8 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  8. Active Directory Dark Theme

    When set the Windows 10 to Dark Theme, change the color of Active Directory from the Server and from the Administrative Tools from Windows 10 to a Dark Theme also!

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  9. GPO search and list all policies with a specific setting pending on the OU you have selected.

    Add a feature to search and list all policies with a specific setting pending on the OU you have selected. pending on the OU you have selected.

    1 vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  10. AGPM and Powershell scripting

    AGPM is a great tool to delegate and keep control on our GPO infrastructure. But the scripting possibilities are very poor.
    I suggest you to extend the powershell module for AGPM, and adding, at least, an Import-AGPMFromProduction Cmd-let that will allow us to automate updates into AGPM.

    My use case is that people can still make some changes outside AGPM system (especially the link change, which cannot be controled directly by AGPM). This change are important to keep track, in my opinion. So I regularly manually import the GPO from production into AGPM.

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  11. Remove 'This will clear your current search result' in Find ...

    When we type in a computer in the search field, in ‘Active Directory Users and Computers’ Find ..., and forget to change to 'computer'. Then when we change it to computer it will clear the name box. with the message 'This will clear your current search result' Why? this have been bugging me for many, many years... so this is my user-voice :-)

    I would like this behavior to change. Maybe just not to clear the box, and say nothing, and just change to computer.

    Or there could be an option, to have the search filed be custom and remember…

    31 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    4 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  12. Publish activedirectory module to PSGallery

    The active directory module is really useful, but a pain to install on a server/computer.
    Current install instructions are these: https://blogs.technet.microsoft.com/ashleymcglone/2016/02/26/install-the-active-directory-powershell-module-on-windows-10/

    I would love the possibility to just do:
    Install-Module "ActiveDirectory" and have everything good to go.

    16 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  13. BUG: Active Directory Users and Computers - using the search will not open the full properties

    Active Directory Users and Computers - using the search will not open the full properties.

    How to reproduce:
    if you search for an object in ADUC and select properties of the object (e.g User account) some tabs will be missing, e.g. the tab where you see all AD properties. This can only be reached by using navigating to the object in the OU and right click > properties.

    It's an unneccessary shortcoming for long imho. I am aware that MS would like to dump ADUC for the sake of the new PS based console but still in some cases both…

    21 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  14. Provide a method for merging/spitting Group Policy Objects including GPP

    Provide a tool/method for merging/spitting Group Policy Objects including GPP. Integrate AGPM into group policy management console fully and use same backup and restore format for GPOs.
    Integrate Microsoft Security Compliance Manager/ the new Policy Analyzer functionality into group policy management console.

    I want to be able to apply the latest security baselines and split and merge GPOs all in one console.

    Provide PowerShell cmdlets for merging and splitting of GPOs including GPP.

    3 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  15. Active Directory Administrative Center (ADAC) search feature is incomplete

    well, WTH?! ADUC lets you find users, computers, group, printers, shares, etc.

    why on earth the new ADAC is lacking this feature? why don't you have the option to choose primitive object types in ADAC search as you can in ADUC? I know you have LDAP query builder and all that (which is awesome by the way); but shouldn't simple stuff be available and intuitive stuff be as easy as they have always been with newer tools?

    2 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  16. Improve Members and Member Of view in Active Directory Administrative Center

    When opening a user or group and looking at “Member of” or “Members” in ADAC only three items is visible in the view. I would like the ability to resize the view to include more than three items.

    28 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  17. Managed Service Accounts in Active Directory Administrative Center

    I would like to create, view and edit Managed Service Accounts from Active Directory Administrative Center.

    27 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  18. AGPM status icons and requester feedback

    AGPM is a great tool for GPO management but I think it's missing some functionality.
    When working in the controlled GPO section you have icon showing if a GPO it's checked out. Would be good to see more status icons showing these states: deployed, checked out, modified after deployment.
    Also it would be nice if the requester of a GPO action can get mail notification back when it's done or rejected.

    7 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  19. Set-ADAccountPassword Raises Error if DN of Account has "*" Character

    The Set-ADAccountPassword cmdlet raises an error if the distinguished name of the account includes the asterick character, "*". The error is raised even if you identify the user by sAMAccountName (astericks are not allowed in sAMAccountName values). It does not help to identify the user by distinguished name, even if you escape the "*" character, whether you escape with the backtick "`", the backslash "\", or using the 2 character ASCII hexadecimal equilvalent "\2A". The only workaround found is to bind to the account using the [ADSI] accelerator and invoke the SetPassword method.

    Assuming the user "cn=Will * Johnson" exists,…

    6 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
  20. version control for Group Policy

    It would be nice if there was a supported way to use version control tools (i.e. GIT, SVN, etc.) to manage various versions of Active Directory Group Policies.

    15 votes
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)

    We’ll send you updates on this idea

    2 comments  ·  Management Tools  ·  Flag idea as inappropriate…  ·  Admin →
← Previous 1 3
  • Don't see your idea?

Feedback and Knowledge Base