Finding Stale Accounts in Active Directory

7 03 2010

 I have been having a Twitter conversation with Martin Byford-Rew the IT Manager at Thomas Deacon Academy in Peterborough and others about finding stale accounts in active directory, now I do not have that concern as I use an AD tools which runs overnight and creates or archives accounts as pupils, staff and parents arrive at or leave Twynham, but more of that in a later post.

 Before we used the current AD tools I also had the same problem with keeping Active Directory tidy and up to date the only way I found before reaching for scripting tools was to use the query tools available in Active Directory so I hope this post helps Martin.

  1. Open Active Directory users and computers at the top you will see “saved queries”
  2. Right click Saved Queries and choose new query
  3. Put a name in the name field I chose “Not Logged On For 30 Days”
  4. You can choose to query the whole of your directory or just one OU
  5. Click Define Query
  6. If you are only interested in finding accounts that have not logged on for a while you get the choice between 30,60,90,120 or 180 days since last logon

We only use these queries now to check out parental accounts for inactivity but a tool that is built in but rarely used. Below you can see the results of the query that we created.








Follow

Get every new post delivered to your Inbox.