Modifies attributes of one or more existing computers in the directory.
Dsmod is a command-line tool that is built into Windows Server 2008. It is available if you have the Active Directory Domain Services (AD DS) server role installed. To use dsmod, you must run the dsmod command from an elevated command prompt. To open an elevated command prompt, click Start, right-click Command Prompt, and then click Run as administrator.
For examples of how to use this command, see Examples.
Syntax
dsmod computer <ComputerDN> ... [-desc <Description>] [-loc <Location>] [-disabled {yes | no}] [-reset] [{-s Server> | -d Domain>}] [-u <UserName>] [-p {<Password> | *}] [-c] [-q] [{-uc | -uco | -uci}]
Parameters
Parameter | Description | ||||||||
---|---|---|---|---|---|---|---|---|---|
<ComputerDN> |
Required. Specifies the distinguished names of one or more computers that you want to modify. If values are omitted, they are obtained through standard input (stdin) to support piping of output from another command to input of this command. |
||||||||
-desc <Description> |
Specifies the description of the computer object that you want to modify. |
||||||||
-loc <Location> |
Specifies the location of the computer object you want to modify. |
||||||||
-disabled {yes | no} |
Specifies if the computer account is disabled for logon (yes) or not (no). |
||||||||
-reset |
Resets computer accounts. |
||||||||
{-s <Server> | -d <Domain>} |
Connects a computer to a remote server or domain that you specify. By default, dsmod connects the computer to the domain controller in the logon domain. |
||||||||
-u <UserName> |
Specifies the user name with which the user logs on to a remote server. By default, -u uses the user name with which the user logged on. You can use any of the following formats to specify a user name:
|
||||||||
-p {<Password> | *} |
Specifies to use either a password or an asterisk (*) to log on to a remote server. If you type *, dsmod prompts you for a password. |
||||||||
-c |
Reports errors, but continues with the next object in the argument list when you specify multiple target objects (continuous operation mode). If you do not supply this parameter, dsmod exits when the first error occurs. |
||||||||
-q |
Suppresses all output to standard output (quiet mode). |
||||||||
{-uc | -uco | -uci} |
Specifies that dsmod formats output or input data in Unicode. The following table shows each format.
|
||||||||
/? |
Displays help at the command prompt. |
Remarks
- This command supports only a subset of commonly used object
class attributes.
- If a value that you supply contains spaces, use quotation marks
around the text, for example,
"CN=DC2,OU=Domain Controllers,DC=Contoso,DC=Com".
- If you supply multiple values for a parameter, use spaces to
separate the values, for example, a list of distinguished
names.
- Dsmod does not support the addition of security
principals in one forest to groups that are located in another
forest when a forest trust exists between both forests. You can use
Active Directory Users and Computers to add security
principals across a forest trust.
Examples
To disable multiple computer accounts, type:
dsmod computer CN=MemberServer1,CN=Computers,DC=Microsoft,DC=Com CN=MemberServer2,CN=Computers,DC=Microsoft,DC=Com -disabled yes
To reset multiple computer accounts, type:
dsmod computer CN=MemberServer1,CN=Computers,DC=Microsoft,DC=Com CN=MemberServer2,CN=Computers,DC=Microsoft,DC=Com -reset