# global catalog port `-server dc01.contoso.com:3268` # set extension attr `Set-ADUser -replace @{extensionAttribute15='f'}` # pw never expires `Get-AdUser -filter { passwordNeverExpires -eq $true -and enabled -eq $true } | Select Name, DistinguishedName` # get user by SID `get-aduser -Identity "S-1-5-21-" -server dc01.contoso.com:3268` # force pw reset `get-aduser -filter * -SearchBase 'OU=Users,DC=Contoso,DC=com' | set-aduser -ChangePasswordAtLogon $true` # submit CSR to CA `certreq -submit -attrib "CertificateTemplate:Webserver Version3" docs_req.req` # sort users by last logon `get-aduser -filter 'enabled -eq "true"' -properties lastlogontimestamp | Select samaccountname, @{Name="lastLogontimestamp";Expression={[datetime]::FromFileTime($_.'lastLogontimestamp')}} | sort-object -property 'lastLogontimestamp' ` # check CRL `certutil -URL "http://ca.contoso.com/CertEnroll/contoso ca01.crl"`