The etautil command to add an inclusion would have the format of:
etautil -u USER -p PWD -DYN add 'eTGlobalUserContainerName=Global Users,eTNamespaceName=CommonObjects' eTGlobalUser eTGlobalUserName='MY_GU_1' in 'eTADSOrgUnitName=MY_AD_OU,eTADSDirectoryName=MY_AD_ENDPOINT,eTNamespaceName=ActiveDirectory' eTADSAccount eTADSAccountName='MY_AD_ACCOUNT_1' relationship=USERACCOUNT;
The etautil command to remove an inclusion would have the format of:
etautil -u USER -p PWD -DYN delete 'eTGlobalUserContainerName=Global Users,eTNamespaceName=CommonObjects' eTGlobalUser eTGlobalUserName='MY_GU_1' in 'eTADSOrgUnitName=MY_AD_OU,eTADSDirectoryName=MY_AD_ENDPOINT,eTNamespaceName=ActiveDirectory' eTADSAccount eTADSAccountName='MY_AD_ACCOUNT_1' relationship=USERACCOUNT;
Things to note:
1) Running the add inclusion command against an account that is already associated would associate the account to the new user which would automatically remove the old association so no need to do a delete and an add in this case
2) You can feed etautil with an input file so that there is a single bind to the Provisioning Server followed by the commands
So you would run the command:
etautil.exe -u USER -p PWD -f input.txt
where input.txt could have one command per line such as:
delete 'eTGlobalUserContainerName=Global Users,eTNamespaceName=CommonObjects' eTGlobalUser eTGlobalUserName='[default User]' in 'eTADSOrgUnitName=MY_AD_OU,eTADSDirectoryName=MY_AD_ENDPOINT,eTNamespaceName=ActiveDirectory' eTADSAccount eTADSAccountName='MY_AD_ACCOUNT_1' relationship=USERACCOUNT;
delete 'eTGlobalUserContainerName=Global Users,eTNamespaceName=CommonObjects' eTGlobalUser eTGlobalUserName='[default User]' in 'eTADSOrgUnitName=MY_AD_OU,eTADSDirectoryName=MY_AD_ENDPOINT,eTNamespaceName=ActiveDirectory' eTADSAccount eTADSAccountName='MY_AD_ACCOUNT_2' relationship=USERACCOUNT;
delete 'eTGlobalUserContainerName=Global Users,eTNamespaceName=CommonObjects' eTGlobalUser eTGlobalUserName='[default User]' in 'eTADSOrgUnitName=MY_AD_OU,eTADSDirectoryName=MY_AD_ENDPOINT,eTNamespaceName=ActiveDirectory' eTADSAccount eTADSAccountName='MY_AD_ACCOUNT_3' relationship=USERACCOUNT;