Destroy then Redeploy with same AD machine name

%3CLINGO-SUB%20id%3D%22lingo-sub-1285482%22%20slang%3D%22en-US%22%3EDestroy%20then%20Redeploy%20with%20same%20AD%20machine%20name%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1285482%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20bit%20of%20context...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20deploying%20servers%20into%20AWS%20with%20terraform.%20We%20want%20to%20be%20able%20to%20quickly%20destroy%20and%20deploy%20machines%20with%20the%20same%20name.%20The%20primary%20reason%20is%20we%20want%20the%20machine%20to%20maintain%20any%20permissions%2C%20groups%20etc%20it's%20a%20member%20of.%20Particularly%20DNS.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20do%20this%2C%20we're%20trying%20to%20reset%20the%20computer%20object%20account%20so%20that%20the%20newly%20deployed%20machine%20can%20assume%20it.%20So%20far%2C%20I've%20tried%20the%20following%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EReset%20Account%20from%20ADUC%20GUI%3C%2FP%3E%3CP%3ESet-AdAccountPassword%20-identity%20%24Computer%20-NewPassword%20(convertto-securestring%20%22computername%24%22%20-asplaintext%20-force)%3C%2FP%3E%3CP%3EChecked%20for%20a%20method%20on%20the%20computer%20object%2C%20but%20none%20available.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENeither%20option%20works.%20I'm%20aware%20there's%20also%20the%20function%20reset-computermachinepassword%2C%20but%20that%20needs%20to%20be%20run%20from%20the%20computer%20itself%20and%20we're%20taking%20the%20assumption%20that%20won't%20be%20possible.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20I%20missed%20anything%2C%20or%20is%20resetting%20the%20computer%20account%20not%20going%20to%20work%20in%20this%20case%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESam%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1285482%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EWindows%20PowerShell%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Visitor

Hi,

 

A bit of context...

 

We are deploying servers into AWS with terraform. We want to be able to quickly destroy and deploy machines with the same name. The primary reason is we want the machine to maintain any permissions, groups etc it's a member of. Particularly DNS.

 

To do this, we're trying to reset the computer object account so that the newly deployed machine can assume it. So far, I've tried the following:

 

Reset Account from ADUC GUI

Set-AdAccountPassword -identity $Computer -NewPassword (convertto-securestring "computername$" -asplaintext -force)

Checked for a method on the computer object, but none available.

 

Neither option works. I'm aware there's also the function reset-computermachinepassword, but that needs to be run from the computer itself and we're taking the assumption that won't be possible.

 

Have I missed anything, or is resetting the computer account not going to work in this case?

 

Thanks,

 

Sam

0 Replies