How to find out disabled/inactive users in active directory

Log in into your DC then execute PowerShell and run the following the following commands

Load the AD powershell

Once loaded run the following command

Following domain has been used in this example

PS S:\> Search-ADAccount -AccountDisabled -SearchBase “DC=yourdomain,DC=int” | FT Name,LastLogonDate,ObjectClass –A

It will display a list of disabled accounts in Active Directory.

This will display all disabled users in active directory which might be absolute and removed. Obviously always check before any removal process that these can be removed!

Once all the disabled users are removed you can search for inactive users.

Change the date so it’s 1 year difference from the current date.

Search-ADAccount -AccountInactive -Datetime 01/04/2015 -SearchBase “DC=yourdomain,DC=int” | FT Name,LastLogonDate,ObjectClass –A

Once you got a list revise the user and disable them first before any removal.

Hope this helps someone.

Many thanks for reading and comments always welcome.






Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s