Skip to content

Tools4everBV/HelloID-Conn-SA-Full-AD-AccountEnableDisable

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

27 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Description

This HelloID Service Automation Delegated Form provides AD account enable / disable functionality. The following options are available:

  1. Search and select the target AD user account
  2. Show basic AD user account attributes of selected target user
  3. Select AD user account attributes for filtering common groupmemberships
  4. Modify the enabled state of selected target AD user account

Versioning

Version Description Date
1.1.1 Updated with audit logging 2022/06/08
1.1.0 Updated with code for SA agent 2022/03/14
1.0.1 Added version number and updated all-in-one script 2021/11/03
1.0.0 Initial release 2020/09/01

Table of Contents

All-in-one PowerShell setup script

The PowerShell script "createform.ps1" contains a complete PowerShell script using the HelloID API to create the complete Form including user defined variables, tasks and data sources.

Please note that this script asumes none of the required resources do exists within HelloID. The script does not contain versioning or source control

Getting started

Please follow the documentation steps on HelloID Docs in order to setup and run the All-in one Powershell Script in your own environment.

Post-setup configuration

After the all-in-one PowerShell script has run and created all the required resources. The following items need to be configured according to your own environment

  1. Update the following user defined variables
Variable nameExample valueDescription
ADusersSearchOU[{ "OU": "OU=Disabled Users,OU=HelloID Training,DC=veeken,DC=local"},{ "OU": "OU=Users,OU=HelloID Training,DC=veeken,DC=local"},{"OU": "OU=External,OU=HelloID Training,DC=veeken,DC=local"}]Array of Active Directory OUs for scoping AD user accounts in the search result of this form

Manual resources

This Delegated Form uses the following resources in order to run

Powershell data source 'AD-user-generate-table-wildcard-deactivate'

This Powershell data source runs an Active Directory query to search for matching AD user accounts. It uses an array of Active Directory OU's specified as HelloID user defined variable named "ADusersSearchOU" to specify the search scope.

Powershell data source 'AD-user-generate-table-attributes-basic-deactivate'

This Powershell data source runs an Active Directory query to select a list of basic user attributes of the selected AD user account.

Powershell data source 'AD-user-get-attribute-enabled-deactivate'

This Powershell data source runs an Active Directory query to receive the current enable state of the selected target AD user account.

Delegated form task 'AD-user-set-enabled'

This delegated form task will update the enabled state of the selected target AD user account according to the modifications in this form.

Getting help

If you need help, feel free to ask questions on our forum

HelloID Docs

The official HelloID documentation can be found at: https://docs.helloid.com/