Convergence group members for invitations

Dear all,
we use Convergence with latest patch level. For invitations of groups and using check availability the group members are not resolved and therefore the busy/free time of group members is not displayed. Instead the group name is displayed but the group itself have not calendar.
Is there any possibility - maybe in the config of convergence of ldap settings groups - that the individual calendars of the invited group members with showing free/busy time show up and in consequence the auto select time will work, too.
The invitation of the group members itself works fine.
Thanks for any help

How are the group members defined in the LDAP entry for the group?
With the assumption that you are using Calendar 7 with Convergence, the Calendar configuration considers the following attributes for members in an LDAP group:
<tt>
davcore.ldapattr.dngroupmember=uniquemember
davcore.ldapattr.urlgroupmember=memberurl
davcore.ldapattr.mailgroupmember=mgrprfc822mailmember
</tt>
Only <tt>uniqueMember</tt> is considered for ACL checking, along with invitation and free/busy scheduling.
The <tt>mgrprfc822mailmember</tt> attribute is taken into account only when inviting the group.
This is because, when doing the ACL check, we are relying on the LDAP Directory to provide us with the <tt>isMemberOf</tt> attribute directly on the logged in user LDAP entry (as opposed to looking at all the members of the group). The <tt>isMemberOf</tt> operational attribute is itself derived from the <tt>uniqueMember</tt> attribute only.
Doing a group expansion for ACL purposes would be too expensive an operation.
As a side note, we also check for dynamic group membership through the <tt>memberurl</tt> LDAP attribute of the group, both for scheduling and ACL purposes.
Reference KM Doc:
Calendar 7: Allowing Members Of A Migrated LDAP Group To Subscribe To Calendars (Doc ID 1483916.1)
-Deb

Similar Messages

  • Web Conference - Invitations via Group Lists - Only some members see invite

    1) Start a new conference via a browser.
    2) Input invites - enter apac-ondemand-team-sg-grp
    3) Only some members of the APAC-OnDemand-Team workspace can see the conference in the list. Most cannot.
    Why can only some members of the workspace see the conference?
    We checked to ensure that those members that could not see the conference were logged in.

    Hi,
    Do we have any difference between the users ? If you as a user create the conference and can see the other members to invite them then there should not be a difference.
    Can you try inviting the users who cannot see the conference as members of the group as individuals - that way we can distinguish between group and user access issues if they can see it when invited personally but not when done as a group invite the issue may be in the group configuration.
    Phil

  • Grouping functionality for Bid Invitations.

    Is there any way to group external requirements to Bid invitations.

    Hi,
    When you press the Submit to Grouping button in the Carry Out Sourcing option ,report BBP_SC_TRANSFER_GROUPED must be executed.
    Read the Documentation given in the report BBP_SC_TRANSFER_GROUPED .
    Short text
    Automatic Grouping of Requirements for POs and Bid Invitations
    Purpose
    This report groups together requirement items to which a valid source of supply has been assigned (for grouping into purchase orders) and whose product category has been enabled for grouping (sourcing option in Customizing).
    In cases where assignment is automatic, the system sets the requirement as Transferred to Grouping.
    In cases where a source of supply is assigned manually, the purchaser has to choose the function Transfer to Grouping in the sourcing application for the requirements.
    You should schedule this report periodically, and make sure that the report is run separately for each document type (purchase order, bid invitation).
    Prerequisites
    You have assigned each relevant product category to a sourcing option for grouping, for example, Automatic Grouping, Sourcing for Item Without Assigned Source of Supply.
    For more information, see the Implementation Guide (IMG) for Supplier Relationship Management: SRM Server -> Sourcing -> Define Sourcing for Product Categories.
    Features
    Report BBP_SC_TRANSFER_GROUPED provides the following functions:
    For automatically grouping requirements into purchase orders:
    It selects all requirements that have a unique valid source of supply, and have been set up for grouping. You can use selection criteria to further restrict the requirements that are selected.
    It groups requirements by vendor. In other words, it groups together all of the requirements that can be sent to the same vendor.
    You can use a Business Add-In (BAdI) to make additional groupings. If the standard system groups together certain requirements, but you want to create them in separate local purchase orders, use the BAdI BBP_GROUP_LOC_PO for this purpose.
    Note that there are some limitations to creating purchase orders this way. For example, it is not possible to group together requirements with different vendors in the same purchase order. This report uses the same differentiation criteria as the sourcing application (for example, business partner, company code, product type).
    It uses function module BBP_PD_PO_CHECK to check the assignment to a source of supply. The report passes on requirements to function module BBP_PD_SC_TRANS_MULTI_LOC_PO, where they are grouped, and converted into a purchase order.
    In a production run (that is, not a test run), the system issues error messages to the Application Monitor. Example: A contract item assigned during sourcing is no longer valid when grouping is about to occur. This error appears in the Application Monitor. The system moves the requirement item to the worklist of the sourcing application.
    The Application Monitor assigns errors to one of the following categories:
    Shopping Cart: Automatic Grouping
    Purchase Order: Automatic Grouping
    If necessary, you can copy this report, and change the selection criteria to suit your needs. You can start the report in test mode.
    Note: In the sourcing application, you can determine which requirements are planned for the next report run by choosing Find -> For Grouping.
    For automatically grouping requirements into bid invitations:
    It selects all requirements that have been set up for grouping. A source of supply is not required. You can use selection criteria to further restrict the requirements that are selected.
    You can use the BAdI BBP_TRANSFER_GROUP to take bid invitations that have been grouped by the system, and then split them up on the basis of your own customer-specific criteria. You can use the BAdI BBP_SAVE_BID_ON_HOLD to determine whether or not a bid invitation should be published automatically.
    The report passes on requirements to function module BBP_PD_SC_TRANSFER_MULTI_RFQ, where they are grouped, and converted into a bid invitation.
    In a production run (that is, not a test run), the system issues error messages to the Application Monitor.
    If necessary, you can copy this report, and change the selection criteria to suit your needs. You can start the report in test mode.
    Note: In the sourcing application, you can determine which requirements are planned for the next report run by choosing Find -> For Grouping.
    Output
    The report displays the purchase orders or bid invitations resulting from the grouping of the requirements. It also shows incorrect requirements that the system was unable to group into a purchase order or bid invitation.
    Related thread:
    SOCO Submit to Grouping functionality?
    Re: Bid invitation
    BR,
    Disha.
    <b>Pls reward points for useful answers.</b>

  • How can I set up an SMS group so that all group members can dial a group number and have a text sent out to all members of the group

    How can I set up an SMS group so that all group members can dial a group number and have a text sent out to all members of the group
    This would be an SMS group similar to an email listserv but running on the SMS network
    I have seen private individuals offering this service
    It seems strange to me that no internet site like Apple, Yahoo or Google offers this as a free service much as the email group services are free services.
    Steve

    I think the app GroupMe might do what you want. You might also try contacting your carrier. My carrier offered some fancy group texting service for a while but they never really advertised it so, unless you asked, you never would have known. But, GroupMe is available in the app store. There are lots of other apps that also do group texting but it seems to be the one that gets recommended the most.

  • How to show logged-in Line Group Members in a Hunt Pilot (CUCM V7.1.3)

    I have configured a Hunt Pilot with a Hunt List which points to a Line Group with some DNs as Line Group Members. Additionally i gave the affected Users the option to log-in or log-out from the Hunt Pilot by configuring the "Hunt Group Logout" Button in the corresponding Phone Button Template.
    Is there a way to find out who is logged-in or logged-out from the Hunt Pilot?

    Hi Bill,
    thanks for your very interesting hint .
    I run the query you posted and actually got the following output. But the displayed linegroups are only a subset from my configured 79 linegroups . Is there a possibility to display all linegroups with all corresponding DNs and can i display this information for only one linegroup?
    When i know the queery that satisfy my claims, i will write a small web application that uses the AXL-SOAP API.
    Regards, Robert
    admin:run sql select lg.name as LineGroup,n.dnorpattern,dhd.hlog from linegroup as lg inner join linegroupnumplanmap as lgmap on lgmap.fklinegroup=lg.pkid inner join numplan as n on lgmap.fknumplan = n.pkid inner join devicenumplanmap as dmap on dmap.fknumplan = n.pkid inner join device as d on dmap.fkdevice=d.pkid inner join devicehlogdynamic as dhd on dhd.fkdevice=d.pkid order by lg.name
    linegroup                      dnorpattern     hlog
    ============================== =============== ====
    LG_A-Ulr4_Augsburg_9965077_235 \+498215075234  f
    LG_A-Ulr4_Augsburg_9965077_235 \+498215075209  f
    LG_A-Ulr4_Augsburg_9965077_235 \+498215075224  f
    LG_A-Ulr4_Augsburg_9965077_235 \+498215075226  f
    LG_A-Ulr4_Augsburg_9965077_235 \+498215075227  f
    LG_A-Ulr4_Augsburg_9965079_300 \+498215075327  f
    LG_A-Ulr4_Augsburg_9965079_300 \+498215075306  f
    LG_AB-Fried17_9965006          \+496021391713  f
    LG_AB-Fried17_9965006          \+496021391714  f
    LG_AB-Fried17_9965006          \+496021391721  f
    LG_AB-Fried17_9965006          \+496021391727  f
    LG_AM-Mar9_9965004             \+499621474921  f
    LG_BT-Sch9_9965010             \+4992189423    f
    LG_DD-Fet29_9965014            \+493514459055  t
    LG_HO-Bah1_9965020             \+4992818194122 f
    LG_KE-Moz31_9965024            \+498315215110  f
    LG_LA-Dre11_9965025            \+498714308419  f
    LG_LA-Dre12_9965026            \+498719239113  f
    LG_Mue-Sta41_9965029           \+498631386227  f
    LG_N-KOEN11_9965034            \+4991124039112 f
    LG_N-KOEN11_9965034            \+4991124039142 f
    LG_N-KOEN11_9965034            \+4991124039110 f
    LG_N-Ste6_9965057_400          \+499112428403  f
    LG_N-Ste6_9965058_450          \+499112428455  f
    LG_NES-Sie2_9965008            \+499771610413  f
    LG_NES-Sie2_9965008            \+499771610421  f
    LG_NM-Bah12_9965030            \+499181293312  f
    LG_PA-Kle13_9965035            \+498519594109  f
    LG_PA-Kle13_9965035            \+498519594113  f
    LG_PAN-Drb12_9965036           \+498561961225  t
    LG_PAN-Drb12_9965036           \+498561961224  f
    LG_R-Her2_9965068_400          \+499413783414  f
    LG_TS-Bah26_9965040            \+498619887312  f
    LG_Voicemail                   997005          t
    LG_Voicemail                   997006          t
    LG_Voicemail                   997007          t
    LG_Voicemail                   997008          t
    LG_Voicemail                   997009          t
    LG_Voicemail                   997010          t
    LG_Voicemail                   997011          t
    LG_Voicemail                   997012          t
    LG_Voicemail                   997013          t
    LG_Voicemail                   997014          t
    LG_Voicemail                   997015          t
    LG_Voicemail                   997016          t
    LG_Voicemail                   997017          t
    LG_Voicemail                   997018          t
    LG_Voicemail                   997019          t
    LG_Voicemail                   997020          t
    LG_Voicemail                   997021          t
    LG_Voicemail                   997022          t
    LG_Voicemail                   997023          t
    LG_Voicemail                   997024          t
    LG_Voicemail                   997025          t
    LG_Voicemail                   997026          t
    LG_Voicemail                   997027          t
    LG_Voicemail                   997028          t
    LG_WEN-Buer16_9965041          \+499614820413  t
    LG_WEN-Buer16_9965041          \+499614820415  f
    LG_WM-Puet35_9965042           \+49881922927   f
    admin:

  • Missing group members in ADSI & LDAP

    Hi there. I have an AD problem here (obviously :))
    It started by wanting to list all members of a group (recursivly, but that does not matter for now, the problem occurs on a single group).
    I tried this in Powershell, but our AD is still  on 2003, so no AD web services, so no powershell.
    In PHP & Java I got the same results: It only shows 3 members, where there should be 23.
    In Active Directory Computers & Users, these 23 (including a group) are listed on the member tab.
    In ADSI I see only the 3 entries mentioned above in the attribute "member", and the other users don't have the membersOf attribute backlink.
    dsget group -members (-expand) works properly.
    Where do Active Directory Computers & Users and dsget get their information regarding group members from, and how can I access that programmatically via LDAP access from php or Java?

    Sorry, forgot about the Domain Users or the Domain Admins group over the link/image upload issue.
    No, it wasn't these groups.
    But: you were on the right path. The term primary group is what I was missing.
    The group is for one of our roadwarrior subsidiaries, and they are not Domain users as primary group, but the one shown here.
    Do you happen to know which LDAP attributes represent the primary group association?
    The primaryGroupID attriute store the RID of the group that is assigned as the primary group. This was to work around the limitation in Windows 2000 before LVR (Linked-Value Replication) so that more than 5000 users could be member of the same group. (It also
    plays a role for POSIX - Services for Mac clients)
    Enfo Zipper
    Christoffer Andersson – Principal Advisor
    http://blogs.chrisse.se - Directory Services Blog

  • SharePoint Hosted App to Read members of Site owner group, if "Who can view the membership of the group? " is set to Group members only

    Hi,
    Is there a way to read group members of site owner group via SharePoint hosted app . The "Who can view the membership of the group? " is set to Group members only. As per my research SCA can only view the group members of site owner group
    if this settings is applied.
    Thanks,
    Sudhir
    Sudhir rawat

    See this.
    Avoid changing the MaxPageSize LDAP query policy
    http://jeftek.com/219/avoid-changing-the-maxpagesize-ldap-query-policy/
    Regards~Biswajit
    Disclaimer: This posting is provided & with no warranties or guarantees and confers no rights.
    MCP 2003,MCSA 2003, MCSA:M 2003, CCNA, MCTS, Enterprise Admin
    MY BLOG
    Domain Controllers inventory-Quest Powershell
    Generate Report for Bulk Servers-LastBootUpTime,SerialNumber,InstallDate
    Generate a Report for installed Hotfix for Bulk Servers

  • How to restrict Permission to the group members in Forum??

    Hi All,
    I have created discussion forum for a group in that group some members are Expert person who will answer thread posted by the group members
    Noe the issue that i am faceing is that:
    <b>1)when any user posts thread he and some other group member other than expert is able to see Reply and delete link,with that link any other person can reply or delete thread that i want to restrict.
    delete and reply link should be visible only to Expert person
    2)Edit Subscription tab is also visible to every group people but that should be only visible to Expert that also i want to restrict.</b>
    I think that this thing can be achived by assigning proper permission to the users
    Any help achiveing me this will be highly appretiated and rewarded.
    thanks in advance.
    Vinit

    "crystalReportViewer1.ReportSource"  i dont find this anywhr in the file.
    pasting a small portion of my code.....
    <%@ Page Language="C#" MasterPageFile="~/MasterPage.master" AutoEventWireup="true" CodeFile="Reports.aspx.cs" Inherits="Reports" Title="Reports Details" %>
                            <CR:CrystalReportViewer ID="CrystalReportViewer1" runat="server" AutoDataBind="True"
            DisplayGroupTree="False" DisplayToolbar="False" Height="1013px"
            Width="773px" />
                        </td>
                    </tr>
                    <tr>
                    </tr>
                    <tr>
                    </tr>
                   <tr>
                    </tr>
                    <tr>
                        <td colspan="9">
        <CR:CrystalReportSource ID="CrystalReportSource1" runat="server">
            <Report FileName="CrystalReport1.rpt">
            </Report>
        </CR:CrystalReportSource>
                        </td>
                    </tr>
                </table>
            </div>
        </div>
         <br />
    </asp:Content>

  • AD group Members list

    I can use GET-ADGroupMemeber AD powershell command to list the groups of what I need. However, I need a way that if someone adds a person to a group that it will trigger an email alert and send me an email with the new person added to that group. For
    example,  if using a power shell script where if someone adds a person to the domain admins group would it be able to trigger an email alert as soon as the person get added and send me an email of who the new user was added to the group.
    Is this possible using a power shell script with schedule task?

    you can do this in different ways
    for example, create 2 files or arrays and compare both and output the differences.
    Keep track of the count of Members in the admin group. When there's a positive difference it means a user was added.
    Below you can find some helpfull things to achieve what you want.
    Compare-Object :
    http://blogs.technet.com/b/heyscriptingguy/archive/2013/11/21/3610554.aspx
    I've used it in the following way:
    Compare-Object (Get-Content $file1) (Get-Content $file2) | where {$_.SideIndicator -eq "<="}
    for the Send-MailMessage see
    -> http://technet.microsoft.com/en-us/library/hh849925.aspx
    I also found this script where they also use the compare option to get this done
    -> http://www.lazywinadmin.com/2012/03/powershell-monitor-membership-change-to.html
    or
    -> http://gallery.technet.microsoft.com/Monitor-Active-Directory-4c4e04c7

  • CustomRealm without listing Group Members

    Hi,
    we are considering to implement a custom security realm. We have a fixed number
    of groups to be used in ACLs. Users are stored in an LDAP server.
    Group membership depends on some information on the individual user which needs
    to be gathered from a separate backend system. Therefore, it is not feasible to
    implement the getMembers() method on the Group class since that means iterating
    over all "user records" in the backend system.
    Here my question:
    1. Is the getMembers() method needed for Authorization and/or Authentication or
    can we simply make it return an empty list? (We do not mind if we do not see group
    members in the administration console.)
    2. Is it a good idea at all to have this kind of group definition?
    3. What about the method "getUsers" for the ListableRealm? Is this one needed
    for Authorization/Authentification. This method poses a similar problem.
    Regards,
    Andreas

    1. Is the getMembers() method needed for Authorization and/orAuthentication or
    can we simply make it return an empty list? (We do not mind if we do notsee group
    members in the administration console.)I think this method is not needed at all for authentication and
    authorization, it's only used to list the users in the WL admin page.
    3. What about the method "getUsers" for the ListableRealm? Is this oneneeded
    for Authorization/Authentification. This method poses a similar problem.Same answer.

  • LDAPRealmV2 using group members as entries

    Hi all,
    we have configured our ldaprealm v2 (wls 6.1) to have group members as entries
    below the group as opposed to the normal setup with group members as attributes
    of one group. This has imposed some strange problems. We have several groups mapped
    to one role in our webapps, but only members of some of the groups get access.
    From the debug output of the realm I see that the groups working have a dn like:
    groupName=GROUPA, ou=Groups, dc=common, dc=company,dc=com
    and the ones that don't have a dn like:
    groupName=GROUPB,ou=Groups,dc=common,dc=company,dc=com
    that is the only differences are the spaces. I don't see how this could make such
    a difference. In the LDAP all the groups look exactly the same.
    Does anyone have any experience with this or have seen similar problems
    Our ldap realm is configured like this:
    server.host=someserver;
    server.principal=cn=Manager,dc=company,dc=com;
    user.filter=(&(uid=%u)(objectclass=person));
    user.dn=ou=People, dc=common, dc=company, dc=com;
    membership.scope=sub;
    membership.scope.depth=1;
    membership.filter=(&(member=%M)(objectclass=groupMember));
    group.filter=(&(groupName=%g)(objectclass=Group));
    group.dn=ou=Groups, dc=common, dc=company,dc=com

    Check your attribute precedence in the metaverse for the group objects "member" attribute. Make sure your ADMA is set to the highest precedence. 
    Also ensure that the attribute flow on your FIM MA is an export and not an import. 

  • List Local Group members with PowerShell 5

    This script:
    $Server="."
    $LocalGroup = "Administrators"
    $Group= [ADSI]"WinNT://$Server/$LocalGroup,group"
    $Members = @($Group.psbase.Invoke("Members"))
    $Members | ForEach-Object {
        $_.GetType().InvokeMember("Name", 'GetProperty', $null, $_, $null)
    works fine in powershell 2 (windows 7), but fails on powershell 5
    "Error while invoking GetType. Could not find member."
    It returns only domain groups. No local groups or local users or domain users.
    Is there a reason why? And can it be modified for powershell 5?
    Thanks

    Try it like this:
    $group=[ADSI]"WinNT://$env:COMPUTERNAME/Administrators,group"
    $group.Members() |
    ForEach-Object {
    ($_.GetType()).InvokeMember('Name', 'GetProperty', $null, $_, $null)
    ¯\_(ツ)_/¯

  • Giving Permissions to specific Distribution Group management for deparment secrety

    Dear ALL
    In our exchange 2010 environment we have multiple departmental distribution group.
    We plan to give management of these distribution group members to each departmental secretary.
    How can achieve this?
    Kindly help
    Ashraf

    All very valid points! 
    The one thing I'd ask you to think about is whether or not you should change the default role assignment policy.  If this is for a handful of users, create a new Role Assignment policy, tweak that (using the steps below) and then assign your new one
    to these users that need to manage the DGs.
    http://blogs.technet.com/b/rmilne/archive/2013/08/09/allow-users-to-manage-distribution-groups-without-creating-new-ones.aspx
    Cheers,
    Rhoderick
    Microsoft Senior Exchange PFE
    Blog:
    http://blogs.technet.com/rmilne 
    Twitter:   LinkedIn:
      Facebook:
      XING:
    Note: Posts are provided “AS IS” without warranty of any kind, either expressed or implied, including but not limited to the implied warranties of merchantability and/or fitness for a particular purpose.

  • 6.1 SP2 Caching realm not caching group members

    Hello:
    We have caching realm set over LDAP security realm.
    We see caching realm never caching group members.
    Any help is appreciated.
    Thanks
    Gennadiy
    Here is the sequence we see:
    1) Search for user name - OK
    2) Search for group name - OK
    3) - ALWAYS going to LDAP to get group members even though they should be cached
    at this point.
    The question is - why does it go to LDAP at all?
    I am doing the same call a 1-2 seconds apart. The group members should be cached.
    It looks like caching realm does not actually cache the members within a group.
    The realm is configured to cache group membership:
    Enable Group Cache true
    Group Cache Size: 211
    Group Cache TTLPositive: 600
    Group Cache TTLNegative: 600
    Group Membership Cache TTL: 300
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getUser("AppLayerRunAs")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <user: pos HIT AppLayerRunAs>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getAcl("weblogic.jndi.CCSAcctEntityBean",
    '.')>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getAcl("weblogic.jndi.CCSAcctEntityBean")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <acl: neg HIT weblogic.jndi.CCSAcctEntityBean>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getAcl("weblogic.jndi")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <acl: neg HIT weblogic.jndi>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getAcl("weblogic")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <acl: neg HIT weblogic>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getUser("AppLayerRunAs")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <user: pos HIT AppLayerRunAs>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getUser("AcctEntityUsers")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <user: neg HIT AcctEntityUsers>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getGroup("AcctEntityUsers")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <group: pos HIT AcctEntityUsers>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <LDAPRealm> <search("ou=ldap, ou=dev_serv,
    ou=hick, o=ccs", "(&(member=cn=AppLayerRunAs,ou=LDAP
    ICK,o=CCS)(objectclass=groupofuniquenames))", base DN & below)>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <getUser("AppLayerRunAs")>
    <Jul 17, 2002 8:53:49 AM EDT> <Debug> <CachingRealm> <user: pos HIT AppLayerRunAs>

    This has been fixed in SP3.
    -utpal

  • Copy global group members to local groups

    I have an AD environment with a lot of global groups, all named G-FG-groupname and I would like to move (or copy) the members of these groups to already existing domain local groups with a similar groupname but
    with another prefix which is L-RG-groupname.
    Example, in which Testn can be replaced by any name.
    Members of domain global group G-FG-Test1 have to be moved or copied to domain local group L-RG-Test1
    Members of domain global group G-FG-Test2 have to be moved or copied to domain local group L-RG-Test2
    Members of domain global group G-FG-Test3 have to be moved or copied to domain local group L-RG-Test3
    etc..
    Many thanks!

    Hi Hoffer,
    as Mike already said, use the Searchbase parameter. Here's an example how it could look like in the previous script:
    # Import Module
    Import-Module ActiveDirectory
    # Get old Groups
    $GroupsOld = Get-ADGroup -Filter { name -like "G-FG-*" } -Properties Members -SearchBase "OU=OU TestOU,DC=intra,DC=netzwerker,DC=de"
    # Then for each group do ...
    foreach ($GroupOld in $GroupsOld)
    # Get the name of the new group
    $NewName = "L-RG-" + $GroupOld.Name.SubString(5)
    # Add Group Members
    Add-ADGroupMember -Identity $NewName -Members $GroupOld.Members -ErrorAction 'SilentlyContinue'
    # Remove Members from old group
    Remove-ADGroupMember -Identity $GroupOld -Members $GroupOld.Members -Confirm:$false
    Basically, use the Distinguished name of an Organizational Unit as the searchbase parameter.
    If you want to know the Distinguished Name of a given OU, you can either use the AD Console, or use this command (change the name as necessary):
    Get-ADOrganizationalUnit -filter { name -eq "OU TestOU" } | Select -ExpandProperty DistinguishedName
    Cheers,
    Fred
    There's no place like 127.0.0.1

Maybe you are looking for

  • How to create a new role : Need to send notifications to multiple users.

    Hi All, I have a requirement where in I need to send notifications to multiple users and no. of users in the list is not fixed.i.e. this builds up dynamically. Kindly let me know how do I achieve this. Also wanted to know where form the Workflow role

  • Part of my code won't work in Firefox

    I'm not really good at coding and I have some problems with my code. I create animated menu in Edge Animate using jquery and then imported it in Muse as a edge file. It's working perfect in IE and Chrome, but something caused problems in Firefox - me

  • Missing Identifier Error.Please help.

    I am using the flwg code and am getting the error: 09:53:29 ORA-00931: missing identifier SELECT XMLELEMENT("Items", XMLATTRIBUTES('Value' as "xmlns:tables"),        XMLELEMENT("Item",  XMLATTRIBUTES(x.code as "code",x.desc as "desc"))        FROM (S

  • Including an Expression in SQL Code with Columns from a Table

    The code under MY CODE will not work. Getting error saying 00922-from keyword not found where expected.. In the examples I looked up, the months_between function was written as a select statement like: Select months_between (sysdate,me607.mbr_dob) /

  • Setting NI5641R ADC input level

    Hi, I am using a NI5641R board and I am programming it using the LabVIEW FPGA Module. How can I set the maximum input level of the ADCs? Concerning the DACs, there is a VI to set the maximum output level in the library that comes with the board. Isn'