Modifies attributes of one or more existing computers in the directory.

Dsmod is a command-line tool that is built into Windows Server 2008. It is available if you have the Active Directory Domain Services (AD DS) server role installed. To use dsmod, you must run the dsmod command from an elevated command prompt. To open an elevated command prompt, click Start, right-click Command Prompt, and then click Run as administrator.

For examples of how to use this command, see Examples.

Syntax

dsmod computer <ComputerDN> ... [-desc <Description>] [-loc <Location>] [-disabled {yes | no}] [-reset] [{-s Server> | -d Domain>}] [-u <UserName>] [-p {<Password> | *}] [-c] [-q] [{-uc | -uco | -uci}]

Parameters

Parameter Description

<ComputerDN>

Required. Specifies the distinguished names of one or more computers that you want to modify. If values are omitted, they are obtained through standard input (stdin) to support piping of output from another command to input of this command.

-desc <Description>

Specifies the description of the computer object that you want to modify.

-loc <Location>

Specifies the location of the computer object you want to modify.

-disabled {yes | no}

Specifies if the computer account is disabled for logon (yes) or not (no).

-reset

Resets computer accounts.

{-s <Server> | -d <Domain>}

Connects a computer to a remote server or domain that you specify. By default, dsmod connects the computer to the domain controller in the logon domain.

-u <UserName>

Specifies the user name with which the user logs on to a remote server. By default, -u uses the user name with which the user logged on. You can use any of the following formats to specify a user name:

  • user name (for example, Linda)

  • domain\user name (for example, widgets\Linda)

  • user principal name (UPN) (for example, Linda@widgets.contoso.com)

-p {<Password> | *}

Specifies to use either a password or an asterisk (*) to log on to a remote server. If you type *, dsmod prompts you for a password.

-c

Reports errors, but continues with the next object in the argument list when you specify multiple target objects (continuous operation mode). If you do not supply this parameter, dsmod exits when the first error occurs.

-q

Suppresses all output to standard output (quiet mode).

{-uc | -uco | -uci}

Specifies that dsmod formats output or input data in Unicode. The following table shows each format.

Value Description

-uc

Specifies a Unicode format for input from or output to a pipe (|).

-uco

Specifies a Unicode format for output to a pipe (|) or a file.

-uci

Specifies a Unicode format for input from a pipe (|) or a file.

/?

Displays help at the command prompt.

Remarks

  • This command supports only a subset of commonly used object class attributes.

  • If a value that you supply contains spaces, use quotation marks around the text, for example, "CN=DC2,OU=Domain Controllers,DC=Contoso,DC=Com".

  • If you supply multiple values for a parameter, use spaces to separate the values, for example, a list of distinguished names.

  • Dsmod does not support the addition of security principals in one forest to groups that are located in another forest when a forest trust exists between both forests. You can use Active Directory Users and Computers to add security principals across a forest trust.

Examples

To disable multiple computer accounts, type:

dsmod computer CN=MemberServer1,CN=Computers,DC=Microsoft,DC=Com  CN=MemberServer2,CN=Computers,DC=Microsoft,DC=Com -disabled yes 

To reset multiple computer accounts, type:

dsmod computer CN=MemberServer1,CN=Computers,DC=Microsoft,DC=Com  CN=MemberServer2,CN=Computers,DC=Microsoft,DC=Com -reset