USMT ChangeGroup command to remove users from the Administrators group is not working

I'm running USMT in a task sequence, and using this in my config.xml to remove admin rights:
  <ProfileControl>
    <localGroups>
      <mappings>
        <changeGroup from="Administrators" to="Users" appliesTo="AllUsers">
          <include>
            <pattern>*</pattern>
          </include>
        </changeGroup>
      </mappings>
    </localGroups>
  </ProfileControl>
I see in the scanstate log that this happens: 
[0x000000] ProfileControl: Parsing ChangeGroup Administrators => Users for AllUsers
[0x000000] ProfileControl: Parsing ChangeGroup (Administrators => Users) 1 include nodes
[0x000000] ProfileControl: Parsing ChangeGroup (Administrators => Users) 0 exclude nodes
[0x000000] ProfileControl: Parsing ChangeGroup is done
But, in the loadstate on the other end, this happens:
[0x000000] Local Group Membership Mapping: XYX\User123 Added to Administrators
I've tried USMT 4 and 5, changed appliesTo="AllUsers" to "MigratedUsers", i've made the <include> more specific.  I can see in the C:\_SMSTaskSequence folder that the config.xml does have the correct info in it. 
I thought I had this tested and working previously, and noticed in some recent migrations that the user still had admin rights. I can reproduce the issue on demand now.  I recently upgraded sccm 2012 to r2, but I'm not sure what that would have to do
with the issue. I am not using the USMT 6 package (going from XP still).  It may very well be that my testing was flawed, and I didnt have it working in the first place
Any suggestions are welcome.

you bet, it is a vbs:
Dim network, group, user
Set network = CreateObject("WScript.Network")
Set group = GetObject("WinNT://" & network.ComputerName & "/Administrators,group")
For Each user In group.members
If UCase(user.name) <> "ADMINISTRATOR" And UCase(user.name) <> "DOMAIN ADMINS" And UCase(user.name) <> "SYSTEM WORKSTATION (ADMINISTRATOR)" Then
group.remove user.adspath
End If
Next
Obviously you can modify the list of allowed admin accounts to suit your enviornment.

Similar Messages

  • [svn:fx-trunk] 8417: Remove themes from the package that are not compiling cleanly

    Revision: 8417
    Author:   [email protected]
    Date:     2009-07-07 04:50:21 -0700 (Tue, 07 Jul 2009)
    Log Message:
    Remove themes from the package that are not compiling cleanly
    bug: https://bugs.adobe.com/jira/browse/SDK-21144
    qa: yes
    doc:
    checkintests: pass
    Ticket Links:
        http://bugs.adobe.com/jira/browse/SDK-21144
    Modified Paths:
        flex/sdk/trunk/build.xml

  • How to remove user from custom DLU Group

    Hi,
    I have created a DLU policy that creates a local user, and places this user
    in a custom local group (Group is already present on the system). Now I want
    to remove this user from this custom group and place it in another custom
    group. I have created a second DLU policy to place the user in the new
    custom group. The new custom group is added fine, but the old custom group
    assignment also remains. How should I set up the policy so that the user is
    removed from the old custom group, or is this not possible?
    Regards,
    Hen

    Hen,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
    - Check all of the other support tools and options available at
    http://support.novell.com.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://support.novell.com/forums)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://support.novell.com/forums/faq_general.html
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Remove users from all distribution groups in Microsoft 365

    Hello
    I would like to know if there is a way I can remove a user from all distribution groups in Microsoft 365. I have a rather large list of users that this would need to be applied to though.
    Any help would be greatly appreciated.
    John

    I would assume yes since there is a cmdlet called, "Remove-DistributionGroupMember", you usually have to have to post some code of what you have
    tried or working on to get further help from most other people here. 

  • Jst got a iphone 4s and my itunes is not picking it up at all i have tried many things from the internet but still not working

    Please help ... Stressed new iphone user!!!!!!!!!! lol.
    i got a new iphone 4s on friday, people told me i needed to connect this to the itunes asap.
    i have had a ipod for 4 years and had no problem connecting to itunes before.
    at first my computer would not find the iphone so i looked up tips from apple and other internet sources ... after deleting temp files my computer picked up my iphone but itunes didnt... i kept getting a pop up when going on to itunes saying "this iphone cannot be used because the required software is not installed. Run the itunes installer to remove itunes, then install itunes again.
    So i did i did this serveral times and the pop still keeps coming up and everytime i reinstall itunes i have to delete temp files for my computer to pick my iphone up. i contacted apple and an adviser sent me a link to follow to delete itunes and other in a order which i did several times and still not worked.
    i tried my iphone on my mums computer and it has picked it up but in my mums itunes i want my itunes as i have purchased many songs. now my ipod wont even register to itunes. i also get a pop up from windows saying Host process for windows services stopped working and was closed ... i ahve followed all the advice for that even a clear up on my computer and still nothing. you can even find apple mobile device anywhere on the computer tho my mobile is charging when plugged in. i have tried everything that apple reccomends anyone able to help
    Thank you

    Try this article if you haven't already
    This is the only possibility that came to my mind when reading about your issue:
    "If an iPhone, iPad, or iPod touch is not recognized in iTunes on Windows, the Apple Mobile Device Service (AMDS) may need to be restarted"

  • Cannot remove tvshow from itunes, control delete does not work

    Cannot delete movies or tvshows from itunes, control delete does nothing, please help.

    Hi pcshow,
    These instructions from the iTunes Help menu, should answer your question:
    Delete an item from your library
    Click the item to select it, and press the Delete key.
    Click Delete Item.
    Do one of the following:
    Remove the item only from your iTunes library: Click Keep File.
    Delete the item from your computer: Click Move to Trash. The item is removed the next time you empty the Trash.
    I believe you meant to Control click which is the same as a right click on your mouse, to get a list of commands.  That also works.
    Cheers,
    - Judy

  • The Help Link from the Application Pages Does not Work for Peoplesoft Campus Solutions 9.0

    Hi everyone.
    I have a problem, I have been trying to set up the Help Link from the Application Pages for Peoplesoft Campus Solutions 9.0 according to the instructions given in the Document: http://docs.oracle.com/cd/E17566_01/epm91pbr0/eng/psbooks/EnablingtheHelpLinkfromApplicationPages.pdf ,  (referenced in the Doc ID 1289101.1, E-PB: How to Set Up the Context Sensitive Help with Hosted PeopleBooks using Universal Linking).
    I follow the instructions of that document carefully:
    I go to: PeopleTools -> Web Profile -> Web Profile Configuration
        2. Then I choose the Web Profile: "Development".
        3. Then Change the value for the Help URL field by entering the following URL format: http://www.oracle.com/pls/topic/lookup?id=%CONTEXT_ID%&ctx=hrcs90r5 , the ctx parameter selected is the one that correspond to  the Campus Solutions (hrcs90r5) according to the Product Line Code Table (ULinkID) especified in the mentioned document.
        4. Stop the Web Domain and Clear cache.
        5. Start the Web Domain again.
    After setting up the Web Profile Configuration I test the help links, thas is why I click in the Help link in any Peoplesoft CS 9.0 Application Page (modify a person), but the next error message appears: "We're sorry, the topic you requested was not found.".
    I tried many combinations with the ctx parameters URL but it does not work yet. 
    I did the same test, but this time using the Help URL field with a HRMS ctx parameter by entering the following URL format: http://www.oracle.com/pls/topic/lookup?id=%CONTEXT_ID%&ctx=hcm92pbr5 , and It works fine !!!
    According to the previous test you realize that It works with HRMS ctx parameter but not with Campus Solutions 9.0 ctx parameter,  Does anybody know what else can I do ? Am I doing anything wrong or missing? or maybe the Oracle's ctx parameter for Campus Solutions URL It is broken simply.
    Thanks for you help and feedback.

    2799444 - The page you are testing with appears to be a Workforce Administration page. Is that correct?
    The CS PeopleBooks would only work for CS pages, e.g.: try navigating to Main Menu > Campus Community > Personal Information > Add/Update a Person
    Also, you can use multiple ctx parameters:
    E.g.: http://www.oracle.com/pls/topic/lookup?id=%CONTEXT_ID%&ctx=hrcs90r5&ctx=hcm92pbr5&ctx=pt852pbh2
    This way the help would work for the HR related pages like Workforce Administration, Campus Solutions pages like Campus Community and also PeopleTools pages like Web Profile Configuration. Hope this clarifies your question. Thanks!

  • Hide Automator actions from the menubar? LSUIELEMENT Not working.

    So does anyone know why the LSUIELEMENT trick doesn't work for the Menu Bar anymore? This is bugging me. Posts online seem to say that this does the trick but it only hides the dock icon for me.
    I'm using it to speed up start ups, but it moves my menubar icons waay down and is unsightly

    I have this solved. Just to share it:
    With 11g PS3:
    Open the human task, in the human task editor, select “assignment”
    Click the edit icon for “Task will go from starting to final participant
    In the “Configure Assignment” dialog box
    Select Assignment tab
    Check “Show approval controls in task details only”
    These steps will work, after you have followed the steps and redploy, did you check with the existing tasks or with new taks. This will be enabled only to the new tasks and not the existing tasks.
    I have followled the same steps, after the redploy the setpp  will be applicable to new tasks.

  • Action link URL calling from another screen from the same web server not work

    Hi there,
    I have an action link URL calling from another screen from the same web server, used the following syntax:
    /analytics/saw.dll?Go&path=.....
    But it is not working, when open the page, it shows error message
              Oops! Google Chrome could not find analytics
    Any help? Thanks!
    Ling

    That's a +1 from me... same issue and yes, isn't inelegant or a shortcoming for some might be the cause of boldness as they rip their hair off their head so thanks in advance for keeping the refinement of the magic potions making the EA secret magic sauce... which may help stop hairloss
    Cheers!
    tfbkny

  • TS1347 I have about 200 contact number in my Sim but however I tried to sim import contact from the setting it is not working what is the solution to import my sim contact so it is so neccessary for me ?

    Dear all please help me ....

    Hi
    Been using my iPad3 with Reliance in Mumbai for nearly 3 months now. It works great other than the problem with the whole "request handset config" mess.
    The ONLY way to resolve is (in my expereince) is to hit cancel as soon as u see it. It will ALWAYS come on when you reboot ipad or "Reset Network Setting". Other than that, it may pop up now or then randomly. If you are luck y enough to spot it when it comes on randomly, hit CANCEL again and things will continue to work fine.
    If you missed it, it will go the Sim failure and invalid sim.
    In which case you go to settings and "Reset Netwrok Settings", once it reboots and requests handset etc, hit cancel and go on using. Its inconveniant, but if you learn to live with it, it works awesome!
    But i rescently got Airtel, they are pretty good too, no such glitches and it supports personal hotspot also on the iPad3 (Reliance does not).
    Hope this helps!

  • Unable to redownload an app from the Purchases tab - button not working

    Hi!
    I've emailed apple support but they weren't much help - a while ago the option to update Acorn 4 appeared under Updates (along with some other apps, which updated fine) - when I tried to update Acorn, I got an error message.
    I talked to Flying Meat software on twitter, and they said I should completely remove the app (which I did, using AppCleaner) - and now it's appearing at the top of the Purchases tab, but the button to install it has no text on it, and doesn't do anything when I click it.
    Any ideas?
    I'm running the latest version of Moutain Lion.
    P

    How do I download an app that failed to download when the App Store says all Unfinished Downloads are downloaded?

  • The google feeling lucky app from the address bar is not working, a program called vshare performs a search instead and I am unable to restore the original function. please help

    I do not know how but vshare, has been performing a search everytime I type something in the address bar that is not a complete website i.e. facebook instead of facebook.com
    this is very annoying and I am unable to uninstall vshare, I have even tried uninstalling firefox and reinstalling it

    I had this problem too, and just fixed it, and found a great website that helped.
    1. In Firefox type about:config in the address bar and press ENTER.
    2. Locate and double-click the entry for keyword.URL
    3. Set the value based on which search provider you would like to use for your address bar searches. Here are a few search strings you can use.
    Yahoo: http://search.yahoo.com/search?p=
    Ask: http://www.ask.com/web?q=
    Google: http://www.google.com/search?&q=
    ChaCha: http://search.chacha.com/search/query?searchwithguide=0&query=
    source: http://www.technipages.com/firefox-change-address-bar-search-provider.html
    And if you want the I'm Feeling Lucky search, instead of just the Google page search, then put:
    http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
    instead of: http://www.google.com/search?&q=
    I just did that, and it worked for me. I had to go through a bunch of the different options, but I found one that worked.
    Source: http://www.google.com/support/forum/p/Chrome/thread?tid=25cf5ea2bc5a2744&hl=en

  • To remove user from Group

    I created a new user account from SSH connection to our cluster. The user belongs to two groups by default: nobody and wheel. I tried to delete him from the two group by using dscl command, I got the following error:
    /NetInfo/root/Groups > delete wheel GroupMembership ryan
    <main> attribute status: eDSAttributeNotFound
    /NetInfo/root/Groups > read wheel
    AppleMetaNodeLocation: /NetInfo/root
    GeneratedUID: ABCDEFAB-CDEF-......
    GroupMembership: root
    Password: *
    PrimaryGroupID: 0
    RealName: System Group
    RecordName: wheel
    RecordType: dsRecTypeStandard:Groups
    SMBSID: ......
    I would like to know how to remove him from the two groups. Thank you very much.
    Apple Cluster   Mac OS X (10.4.3)  

    I had to update the code to the following because Get-SPUser was not working properly:
    $url = "https://sharepointdev.spfarm.spcorp.com/sites/desitecoll"
    $userName = "spfarm\spprofileimport";
    $site = New-Object Microsoft.SharePoint.SPSite($url)
    $web = $site.OpenWeb()
    $siteGroups = $web.Groups;
    Clear-Host
    $mySiteGroups = @();
    foreach($group in $siteGroups)
    Write-Host $group
    $mySiteGroups += $group;
    }#foreach
    $members = $web.Groups[$mySiteGroups[0]];
    $owners = $web.Groups[$mySiteGroups[1]];
    $visitors = $web.Groups[$mySiteGroups[2]];
    #Convert the user name to an SPUser account
    $spUser = $web.Site.RootWeb.EnsureUser($userName);
    Write-Host $spUser.ID
    Remove-SPUser -Identity $spUser -Web $url -Group $owners
    $web.Update();
    $web.Dispose();
    Write-Host "User " $userName "removed from " $owners
    Was I not using Get-SPUser correctly?

  • Project Server 2013 - Remove user from resource pool via sync

    Hello everyone,
    has anyone managed to configure their Project Server 2013 box with a resource pool sync that will actually remove user from the resource pool (disable "User can be assigned as resource" or deactivate users) when the user is removed from the AD
    group(s)?
    Setup: Single box, SQL 2012 SP1, SharePoint/Project Server 2013 + PU March + CU April. 2 PWA instances, 1 in SharePoint and 1 in Project permission mode. Tried on 2 different machines (different setup, accounts, domains).
    Proceedings:
    Create AD user U, AD group G. Add U to G.
    Go to PWA, setup resource pool sync with G, sync.
    U is now in the resource pool, has no PWA permissions.
    Remove U from G. Resync resoure pool.
    U is still in resource pool, still a resource, still active, can still be assigned as resource.
    Adding U back to G an repeating the whole spiel with a resource pool and a PWA group sync of G will result in U being added and removed from the user list (as expected), and U being added but not removed from the resource pool.
    Having read
    http://technet.microsoft.com/en-us/library/gg982985.aspx and
    http://technet.microsoft.com/en-us/library/gg750243.aspx, there does not seem to be an omission on my part.
    The first article states:
    Note:
    The corresponding Project Server User Account is not deactivated based on this synchronization. If the same Active Directory user is configured to synchronize with a Project Server security group, the Project Server user account will be inactivated when
    that synchronization occurs. For more information, see
    Best practices to configure Active Directory groups for Enterprise Resource Pool synchronization in Project Server 2013.
    Unfortunately, this deactivation either does not seem to occur even with a PWA group sync or I misunderstood the article.
    So, did anyone manage to setup their resource pool sync in a way, that new resource will be added, but also be removed from the resource pool?
    Kind regards,
    Adrian

    Hi Adrian,
    you tried to sync the same AD group that you used for the resource pool sync also with a Project Server permission group?
    And on removal of the user of the AD group the project user/resource is not deactivated? Only removed from the group
    Regards
    Christoph
    Hi  Christoph,
    even though I might have tried that before, I tried it again in several constellations. It didn't change anything. The the user will be properly added to and removed from the PWA group whenever I remove them from the AD group, the use will also stay active
    (but cannot logon without permissions). However, the user will always remain in the resource pool, i.e. the "User can be assigned as resource." checkbox will remain unless it is cleared manually.
    Having re-read the technet articles, none of the scenarios actually seem to descibe or address the process that I require, or maybe I'm just misunderstanding. Let me just try to outline the core issue:
    Add user to AD group. Sync AD group with resource pool. User is now a PWA resource and PWA user.
    Remove user from AD group, but do not deactivate/delete user from AD.
    (Magic happens!)
    User cannot be assigned as ressource in PWA.
    So, is there anything to make this step 3 happen, or is it just not possible to sync users out of the resource pool anymore unless they are deleted/deactivated in AD?
    Kind regards,
    Adrian

  • CSSImport Utility - Remove Users from Groups

    We have a security group that has a few hundred users assigned to the group. When there is a need to remove a user from the group it is difficult to find the user as I have comb through the list to find the user i am trying to remove. Two questions: is there a way to sort the users in the group in Share Services? The second question is can users be removed using the CSSImport utility by specifying the "delete" option in the importexport.properties? Does the "delete" option remove the user from the secuity group and or does it delete it completely from ShareServices? (we are using Hyperion v9.3.0.1.0 Build 5)

    Hi,
    I am not so sure about the sorting but removing users from groups can be done with the CSSImportExport utility, I see you are on 9.3.0, try and get hold of the 9.3.1 version as it is backward compatible to the 9.3.0 version and more stable.
    When removing users from groups, just set your import operation to update
    import.operation=update
    and in your import csv just put the group children elements and the users you want in the group.
    #group_children
    id,group_id,group_provider,user_id,user_provider
    TestGroup,,,UserToKeepInGroup,Native Directory
    This way it will keep the users in the import file and remove the users from the group that are not in the file, also it does not remove the user from shared services only from the group.
    Ok?
    Cheers
    John
    http://john-goodwin.blogspot.com/

Maybe you are looking for

  • How do I use an audio interface with iMovie?

    I'm trying to shoot a short clip of a musician playing. I want to use an interface with my higher end mics, and use iMovie '09 to shoot video. I have a Presonus Firebox as my interface. iMovie just doesn't seem to want to recognize it, nor record thr

  • BW-BO integration challenge

    Hello Experts, Could someone probably suggest a good approach to my design issue. Scenario: WEBi report on a BW Query Universe + Teradata Universe for Top X customers. The selection for Top X (Where X is a variable) is by default 20 and has the optio

  • Unable to Check In Publishing Page

    I am running into an issue with a custom page layout that I have created.  On this page layout I have a publishing html field, publishing image field, and a publishing summary links field.  The problem is when I check-in the publishing page as a draf

  • Displaying images in JPanel

    Hi, I'm trying to work out the best method to display a set of thumbnail images in a JPanel (similar to a Thumbnail view in windows XP) - at the moment I'm using a Tree, but am wondering whether this is the best way to go about it? I'm using a tree i

  • Incoming/Outgoing Excise Invoice

    What information should be maintained for following fields that appear under Header:- Excise Ref.no., Excise Ref Date & Excise Removal Time. also when I am trying to post an incoming excise invoice it says "no match record found "GL Account" (OACT) O