Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-40656: Unable to run “RemoveAllOrphans.ps1” powershell script when ZPA is enabled

Authentication Service ,  

10 September,20 at 07:38 PM

Problem: To remove orphan objects run the following PowerShell script“.\RemoveAllOrphans.ps1”, but the following error is encountered “Cannot remove users from zone because auto provisioning is enabled” if ZPA is currently running.

Cause: To run script “.\RemoveAllOrphans.ps1” with ZPA enabled / running you have to include “-OverrideZPA” otherwise it will throw the error “Cannot remove users from zone because auto provisioning is enabled

Workaround: Run script specifying “-OverrideZPA” to get around error, but this doesn't seem to work  "Ex. PS C:\Program Files\Centrify\PowerShell\Centrify.DirectControl.PowerShell\Samples>.\RemoveAllOrphans.ps1 -OverrideZPA"

User-added image


Solution: Add to the “end” of the following lines below “-OverrideZPA” in the RemoveAllOrphans.ps1 script and save changes. (See screenshot example below)

# Delete all the orphan use profile in computer zone
  • Get-CdmUserProfile -Computer $managedComputer | Where-Object {$_.IsOrphan} | remove-CdmUserProfile -OverrideZPA

# Delete all the orphan group profile in computer zone
  • Get-CdmGroupProfile -Computer $managedComputer | Where-Object {$_.IsOrphan} | remove-CdmGroupProfile  -OverrideZPA

# Delete all the orphan use profile in zone
  • Get-CdmUserProfile -Zone $zone | Where-Object {$_.IsOrphan} | remove-CdmUserProfile -OverrideZPA

# Delete all the orphan group profile in zone
  • Get-CdmGroupProfile -Zone $zone | Where-Object {$_.IsOrphan} | remove-CdmGroupProfile -OverrideZPA
User-added image

Run script with parameter "-OverrideZPA" (See example below)

PS 
C:\Program Files\Centrify\PowerShell\Centrify.DirectControl.PowerShell\Samples>.\RemoveAllOrphans.ps1 -OverrideZPA

User-added image

 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.