10 May 2013

Search for inactive active directory accounts

i found a neat cmdlet that can retrieve inactive, disabled, expired or expiring active directory accounts;

full details about the command can be found on technet;

pay attention to the "-TimeSpan" argument - if you do not use the correct /accepted formatting the search will return wrong objects;



Search-ADAccount -AccountInactive -UsersOnly -SearchBase 'OU=Users,DC=domain,DC=intra' -TimeSpan 90.00:00:00.0 | Select-Object name, lastlogondate

1 comment:

  1. Thanks for sharing the wonderful post related to search inactive accounts from active directory environment. I used the automate tool from http://www.activedirectorycleanup.com/ which provides the automate facilitate to search inactive or old AD accounts and generate the reports for the required period and sorted or filtered for more accurate information.

    ReplyDelete