Scenario: Add Active Directory users to Distribution Lists
Suppose you want to add a user in Active Directory to one or more Distribution Lists, based on user logon name and group membership. However, you are not sure that the user actually exists in Active Directory. Also, you want make any Task generic, so it can also be used for different users. To handle this situation, do the following:
- At Library > Modules, create two Modules, a Module Query User Properties and a Module Add User to DL_Group.
- The Module Query User Properties contains two Tasks Query Active Directory User and a Task Message Box.
- In the first Task Query Active Directory User, click the Settings tab and select Filter by OU and Include child organizational units.
- On the User Properties tab, add the following AD user properties: Folder, Name, Department, Member of and User logon name (pre-Windows 2000).
- On the Module Parameters tab, click AutoCreate > All.
- In addition to the automatically-created parameters, also create the parameters $[Department], $[UserLogonName] and $[MemberOf]:
- Configure an evaluator that defines that the Task should fail if the specified user does not exist in Active Directory. If the user exists, the parameter $[Department] should get the same value as the Active Directory user property Department:
- In the second Task Query Active Directory User, click the Settings tab and select Filter by OU and Include child organizational units.
- In the Domain field, specify the parameter $[Domain].
- In the Security context field, specify the parameter $[SecurityContext].
- In the Domain controller field, specify the parameter $[DomainController].
- In the Filter by OU field, specify the parameter $[FilterOU].
- On the User Properties tab, add the following AD user properties: Folder, Name, Department, Member of and User logon name (pre-Windows 2000).
- Configure an evaluator that defines that the Task should fail if the specified user does not exist in Active Directory. If the user exists, the parameter $[MemberOf] should get the same value as the Active Directory user property Member Of:
- In the Task Message Box, create a message with caption Query Active Directory Directory User (UserLogonName): $[UserLogonName] and message Department: $[Department], Member Of: $[MemberOf].
- In the Module Add User to DL_Group, add a Task Manage Active Directory User.
- On the Settings tab, specify the parameter $[Domain].
- In the Security context field, specify the parameter $[SecurityContext].
- In the Domain controller field, specify the parameter $[DomainController].
- Select Single User and specify the parameter $[UserLogonName] in the User logon name field.
- On the Member of tab, add the group DL_$[Department] with as action Add to group:
- At Library > Run Books, create a Run Book with three Run Book Jobs.
- In the first <RB Job, on the Properties tab, select the Module Query User Properties in the What field.
- Select Use Run Book Parameter and select the parameter $[RunBookWho].
- In the second <RB Job, on the Properties tab, select the Module Add User to DL_Group in the What field.
- Select Use Run Book Parameter and select the parameter $[RunBookWho].
- In the third <RB Job, on the Properties tab, select the Module Query User Properties in the What field.
- Select Use Run Book Parameter and select the parameter $[RunBookWho].
- On the Run Book Parameters tab of the Run Book, click AutoCreate and specify values that apply to your Ivanti Automation environment for the parameters $[FilterOU], $[Domain], $[DomainController] and $[SecurityContext]. For example:
- On the Links tab, AutoLink the Module parameters to the Run Book parameters with their default action Set initial value.
- Change the parameter link action for the parameter $[Department] for the first link to Get initial value:
- After configuring the <RB, schedule a Job with it. On the Job Parameters tab, specify the user logon name of the user whose settings you want to change and specify which Agent should execute the Task.
When the Run Book is executed, a message box shows the logon name of the user, which department the user belongs to, and to which Distribution Lists the user has been added: