On my publications page you will find several PowerShell scripts for making your Active Directory life easier. The scripts that use a JSON configuration file leverage this unified schema, allowing you to create a single JSON file that represents critical elements of your AD environment.
Schema
{
"ADComputers":[
{
"ComputerName":"",
"Path":""
}
],
"ADContacts":[
{
"FirstName":"",
"LastName":"",
"EmailAddress":"",
"Path":"",
"TelephoneNumber":""
}
],
"ADDFSNFolderPermissions":[
{
"Description":"",
"DFSNFolders":[""],
"Identities":[""]
}
],
"ADDFSNRootPermissions":[
{
"Description":"",
"DFSNRoots":[""],
"Identities":[""]
}
],
"ADDFSRPermissions":[
{
"Description":"",
"DFSRGroups":[""],
"Identities":[""]
}
],
"ADGPOPermissions":[
{
"Description":"",
"GPONames":[],
"GroupNames":[""],
"Permissions":[""]
}
],
"ADGroups":[
{
"Name":"",
"Path":"",
"Scope":0,
"Members":[]
}
],
"ADOrganizationalUnits":[
{
"Name":"",
"Path":""
}
],
"ADOUDelegations":[
{
"Description":"",
"Identities":[],
"Permissions":[],
"OUs":[]
}
],
"ADUsers":[
{
"Surname":"",
"GivenName":"",
"Division":"",
"Title":"",
"EmployeeID":0,
"SamAccountName":"",
"Password":"",
"Path":""
}
]
}
Definition
Root Node
| Key | Value | Required |
|---|---|---|
ADComputers | A list of computers to create. See ADComputers, below. | FALSE |
ADContacts | A list of contacts to create. See ADContacts, below. | FALSE |
ADDefaultObjectsOUs | A dictionary of object types and their default OUs. | FALSE |
ADDFSNFolderPermissions | A list of DFSN folders to delegate. See ADDFSNFolderPermissions, below. | FALSE |
ADDFSNRootPermissions | A list of DFSN roots to delegate. See ADDFSNRootPermissions, below. | FALSE |
ADDFSRPermissions | A list of DFSR permissions to apply. See ADDFSRPermissions, below. | FALSE |
ADGPOPermissions | A list of GPO permissions to apply. See ADGPOPermissions, below. | FALSE |
ADGroupPolicyObjects | A list of group policy objects to create. See ADGroupPolicyObjects, below. | FALSE |
ADGroups | A list of groups to create. See ADGroups, below. | FALSE |
ADOrganizationalUnits | A list of organizational units to create. See ADOrganizationalUnits, below. | FALSE |
ADOUDelegations | A list of delegations to create. See ADOUDelegations, below. | FALSE |
ADUsers | A list of users to create. See ADUsers, below. | FALSE |
ADComputers
| Key | Value | Required |
|---|---|---|
ComputerName | The name of the computer object. | TRUE |
Path | The organizational unit where the computer should be created. | TRUE |
ADContacts
| key | Value | Required |
|---|---|---|
FirstName | The contact first name. | TRUE |
LastName | The contact last name. | TRUE |
EmailAddress | The contact email address. | TRUE |
Path | The organizational unit where the contact should be created. | TRUE |
TelephoneNumber | The contact telephone number. | TRUE |
ADDefaultObjectsOUs
| KEY | Value | Required |
|---|---|---|
Groups | The OU that should contain AD domain built in groups. | TRUE |
Users | The OU that should contain AD domain built in users. | TRUE |
ADDFSNFolderPermissions
| Key | Value | Required |
|---|---|---|
Description | A brief description of the DFSN permission. | TRUE |
DFSNFolders | A list of the folders where the permissions will be applied. | TRUE |
Identities | A list of AD users and group to whom the permissions will be applied. | TRUE |
ADDFSNRootPermissions
| Key | Value | Required |
|---|---|---|
Description | A brief description of the DFSN permission. | TRUE |
DFSNRoots | A list of the folders where the permissions will be applied. | TRUE |
Identities | A list of AD users and group to whom the permissions will be applied. | TRUE |
ADDFSRPermissions
| Key | Value | Required |
|---|---|---|
Description | A brief description of the DFSR permission. | TRUE |
DFSRGroups | A list of the DFS replication groups where the permissions will be applied. | TRUE |
Identities | A list of AD users and group to whom the permissions will be applied. | TRUE |
ADGPOPermissions
| Key | Value | Required |
|---|---|---|
Description | A brief description of the GPO permission. | TRUE |
GPONames | A list of GPO names where the permissions will be applied. | TRUE |
GroupNames | A list of AD groups to whom the permissions will be applied. | TRUE |
Permissions | A list of the permissions to apply. Valid permissions are GpoRead, GpoApply, GpoEdit, and GpoEditDeleteModifySecurity. | TRUE |
ADGroupPolicyObjects
| Key | Value | Required |
|---|---|---|
Name | The name for the group policy object. | TRUE |
Links | A list of OUs where the policy should be linked. | TRUE |
ADGroups
| Key | Value | Required |
|---|---|---|
Name | The group name. | TRUE |
Path | The OU where the group should be created. | TRUE |
Scope | The group GroupScope. | TRUE |
Groups | Other [parent] groups where this groups should be a member. | TRUE |
ADOrganizationalUnits
| Key | Value | Required |
|---|---|---|
Name | The organizational unit name. | TRUE |
Path | The organizational unit where the new OU should be created. | TRUE |
ADOUDelegations
| Key | Value | Required |
|---|---|---|
Description | A brief description of the delegation. | TRUE |
Identities | A list of users and groups to whom the delegation will be applied. | TRUE |
Permissions | The permissions that will be applied for the user to the OU. See Permissions (below) for valid values. | TRUE |
OUs | A list of OU distinguished names where the delegation will be applied. | TRUE |
ADUsers
| Key | Value | Required |
|---|---|---|
Surname | The user last name. | TRUE |
GivenName | The user first name. | TRUE |
Division | The user division. | TRUE |
Title | The user title. | TRUE |
EmployeeID | The user employee ID. | TRUE |
SamAccountName | The user SamAccountName. | TRUE |
Password | The user password in plain text. | TRUE |
Path | The organizational unit where the user should be created. | TRUE |
Groups | A list of groups where this user should be a member. | TRUE |