Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

Using adedit to change UNIX Data on a Centrify Zone

11 April,19 at 11:50 AM

Centrify ADEdit is a command-line interface (CLI) utility that enables UNIX administrators to manage Centrify objects—such as zones, rights, and roles—in Microsoft Active Directory.


Here's a custom script that will help you change the shell on all the zone users at the same time:


#!/bin/env adedit
package require ade_lib
        foreach USER [get_zone_users] {
                select_zone_user $USER
                set_zone_user_field shell "%{shell}"


Before you run it make sure to:

1. Specify the AD domain (in DNS format), Zone admin user and its password at line 5;

2. Specify the zone DN at line 7, see below how to retrieve this info:


3. Change the shell value at line 11 (for example set_zone_user_field shell "/bin/false");

4. Make sure to change the file permissions to allow execution (chmod +x