Setting user object attributes msDS-SupportedEncryptionTypes and userAccountControl using the cmdlets Get-QADUser and Set-QADUser to enable encryption methods work with Kerberos

set-Location c:\
Add-PSSnapin Quest.ActiveRoles.ADManagement
Get-PSsnapin
Set-QADPSSnapinSettings -DefaultSizeLimit 0
Get-Command Get-QAD*

Get-QADUser -sl 0 -IncludeAllProperties -SerializeValues

PS C:\> Get-QADUser spider001 -sl 0 -IncludeAllProperties -SerializeValues > C:\User.txt

PS C:\> Get-QADUser spider001 -sl 0 -IncludedProperties userAccountControl,’msDS-SupportedEncryptionTypes’ | Format-Tabl

e name,userAccountControl,’msDS-SupportedEncryptionTypes’

Name          userAccountControl   msDS-SupportedEncryptionTypes

spider001   2163200                      31

PS C:\> Set-QADUser spider002 -objectAttributes @{‘msDS-SupportedEncryptionTypes’=31}

PS C:\> Set-QADUser spider002 -objectAttributes @{‘userAccountControl’=2163200}

PS C:\> Set-QADUser spider003 -objectAttributes @{‘msDS-SupportedEncryptionTypes’=31}

PS C:\> Set-QADUser spider003 -objectAttributes @{‘userAccountControl’=2163200}

PS C:\> Get-QADUser spider002 -sl 0 -IncludedProperties userAccountControl,’msDS-SupportedEncryptionTypes’ | Format-Tabl

e name,userAccountControl,’msDS-SupportedEncryptionTypes’

Name          userAccountControl    msDS-SupportedEncryptionTypes

spider002   2163200                       31

 

 

WordPress Themes