Gerenciar usuários por linha de comando no Windows

 Para criar usuários locais com net user, digite:
1
net user nome_usuario senha /add


Substitua nome_usuario e senha pelos dados desejados. Você também pode ir além e
digitar o nome completo e a descrição do usuário com:

1
net user nome_usuario senha /add /fullname:"Nome Completo" /comment:"Descrição do usuário"


Caso queira alterar a senha de um usuário local, simplesmente digite:

1
net user nome_usuario nova_senha


Ou se quiser editar o nome completo ou a descrição, digite:

1
net user nome_usuario /fullname:"Novo nome Completo" /comment:"Nova descrição do usuário"


Utilizando este método, você vai criar usuários “Padrão”, ou seja, sem privilégios
administrativos. Para dar privilégios de administrador para determinado usuário,
simplesmente digite:

1
net localgroup administradores nome_usuario /add
 

Caso tenha pensado melhor e acha que o usuário não merece ser um administrador,
digite:

1
net localgroup administradores nome_usuario /delete

 

 

Powershell Active Directory Commands

Find Users or Computer which are expired

Use Search-AdAccount cmdlet to find user, computer or service account enable status

Search-ADAccount -AccountExpired


Check If Users password expired

Search-ADAccount -PasswordExpired


Check if Users account disabled

Search-ADAccount -AccountDisabled


Find all locked out account in active directory

Search-ADAccount -LockedOut | FT Name,ObjectClass -A


Find account inactive for last 90 days

Search-ADAccount -AccountInactive -TimeSpan 90.00:00:00 | FT Name,ObjectClass -A


Unlock User account

Unlock-ADaccount -identity "Garyw"


Get Ad User Distinguished Name

Get-AdUser -Identity "toms" | Select DistinguishedName


Get Ad User using userprincipalname

Use Get-AdUser cmdlet in Active directory to get user using provided userprincipalname.

Get-ADGroupmember -identity salesleader | % { get-aduser $_.samaccountname} | Select Name,UserPrincipalName


Get Ad User SID in active directory

Get-AdUser -Identity toms | Select Name, SID, UserPrincipalName


Modify property of Group in active directory

Lets consider an example to modify description property of group, run below command

Set-ADGroup -Server localhost:60000 -Identity "CN=AccessControl,DC=AppNC" -Description "Access Group" -Passthru

Above PowerShell script, uses Set-AdGroup to set description property using Description parameter.


List all active directory groups

PowerShell Get-AdGroup cmdlet get list of all active directory group, run below command

Get-ADGroup -filter * -properties * |select SAMAccountName, Description|


List of all users in AD group

PowerShell Get-AdGroupMember cmdlet gets active directory group members, run below command

Get-ADGroupMember -Identity "Shell_Sales" | Select-Object Name


Get all computers in Active Directory

PowerShell Get-AdComputer cmdlet get list of active directory computers.

Get-ADComputer -Filter *


Source: https://shellgeek.com


Set AdUser Home Directory in PowerShell

 Using the Set-AdUser cmdlet in PowerShell to set the home directory folder path.

Set-ADUser -Identity Arons -HomeDirectory 'D:\Arons'
 
Get-Aduser -Identity Arons -Properties * | Select SamAccountName,HomeDirectory,HomeDrive,ProfilePath

Clean /var/log/journal

 

$ du -hs /var/log/journal/
4.1G    /var/log/journal/

4,1 GB de arquivos de diários, com o mais antigo datando de mais de dois meses.

$ ls -lath /var/log/journal/*/ | tail -n 2
-rw-r-x---+ 1 root systemd-journal 8.0M Dec 24 05:15 user-xxx.journal

Limpe systemd journals de mais de X dias

A primeira é baseada no tempo, limpando todo o suporte de há mais de, digamos, 10 dias.

$ journalctl --vacuum-time=10d

Vacuuming done, freed 2.3G of archived journals on disk.

Alternativamente, você pode limitar seu tamanho total.
Limpe systemd journals se eles excederem X de armazenamento

Este exemplo manterá 2GB de logs, limpando tudo o que excede isso.

$ journalctl --vacuum-size=2G

Vacuuming done, freed 720.0M of archived journals on disk.

 

 

Windows update error 0x8024500c

Stop windows update service

Type %windir%\SoftwareDistribution\DataStore in this new window and click OK.
 

This will open Windows Explorer on the correct location.
 

Delete all contents of this folder. (Hint: Use Ctrl + A to select all files and folders)

In the new windows you have a navigation on the left side. Use it to navigate to

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
 

Once you found it, search for WUServer and WIStatusServer in the right hand pane.


If they are not listet we cannot clean the download path. Othwerwise delete both.
Restart your computer.

 

 

 

Kaspersky Security Center WSUS Files Storage Location

 Kaspersky seems to be storing windows update files on the C Drive:

Here -> C:\ProgramData\KasperskyLab\adminkit\1093\.working

Change folder location with klsrvswch.exe utility. 

You can reach it from the KSC installation folder. Utility named as "Administration Server Account Switch Utility". It seems like just allows you to switch service account, but also allows to change "wsus" folder path. Continue wizard as if you want to switch service account. You don't need to provide a new service account, you can use current. Last step is the place of path change.

 

Limit SSH access by user and network

 Add user filtering with AllowUsers option in sshd_config file:

AllowUsers johndoe@192.168.1.* admin2@192.168.1.* otherid1 otherid2

This allows johndoe and admin2 only from 192.168.1.* addresses and otherid1, otherid2 from anywhere.

 

 

Remove computer from Azure Arc

   To fully remove a computer from Azure Arc-enabled servers, follow the official steps in the Uninstall the Azure Connected Machin...

Mais vistos