Tuesday, 30 August 2011

Inactive computer account clean up


                         As workstations get added and removed to AD, computer accounts become needs to be cleaned up so they can be used for new computers. The following Powershell code retrieves all computers that either has not logged into AD for more than 90 days or never logged in and exports into a file.

Get-QADComputer -SizeLimit 0 -IncludedProperties LastLogonTimeStamp -SearchRoot 'ad.umbc.edu/Dept' |
where { ($_.AccountIsDisabled -eq $false) -and (($_.LastLogonTimeStamp -eq $null) -or ((((get-date) - $_.LastLogonTimeStamp).Days) -gt 90)) } |
Select-Object Name, ParentContainer, DN | Sort -Property ParentContainer| Export-Csv <file>

1 comment:

  1. Thanks, it's very useful information related to find all inactive computer accounts in active directory environment. I have already read many article related to this topic and then I tried this automated active directory cleanup tool ( https://blog.netwrix.com/2018/02/15/the-ten-best-free-active-directory-management-tools/ ) that allows to find out inactive or stale computer accounts from active directory and manage inactive computer's accounts and move to another OU.

    ReplyDelete

How can VMware Integrated Containers be useful in real life scenario

What is VIC: VIC - vSphere Integrated Containers enables IT, teams, to seamlessly run traditional workloads and container workloads ...