compdigit44
asked on
Search for Account Created in AD between a specific time period
Right now I have a windows 2000 AD domain. IS there a way for me to search in AD for all network account created during a specific time period?
ASKER
Very do I need to install this on my DC or can it be run from my workstation?
Hey :)
The command Mike supplied (and the tool) can be run from any member of the domain (including your workstation or the DC if you prefer).
Chris
ASKER
Very cool..
Also in AD is there a way for me to get a list of account that have been deleted in the past 30 days?
Also in AD is there a way for me to get a list of account that have been deleted in the past 30 days?
Sure :)
The date you use is built in the same way as you did above.
ADFind -f "(&(objectClass=user)(obje ctClass=pe rson)(IsDe leted=TRUE )(whenChan ged>=20090 603000000. 0Z))" -showdel
You'll find that deleted objects have a seriously limited set of attributes, not everything makes it onto the tombstone.
And note that the two "objectClass=" statements are intentional. There are quite a few differences between the regular domain objects and those which have been deleted.
Chris
The date you use is built in the same way as you did above.
ADFind -f "(&(objectClass=user)(obje
You'll find that deleted objects have a seriously limited set of attributes, not everything makes it onto the tombstone.
And note that the two "objectClass=" statements are intentional. There are quite a few differences between the regular domain objects and those which have been deleted.
Chris
ASKER
For the synatex to show all user deleted with in a specific time period for example 6/1/09 - 6/30/09 what would i type in?? I tried what you listed above and it keeps showing zero records
try
ADFind -default -f "(&(objectClass=user)(obje ctClass=pe rson)(IsDe leted=TRUE )(whencrea ted>=20090 601000000. 0Z)(whencr eated<=200 9063000000 0.0Z))" -showdel
See if that gives you records
Thanks
Mike
ADFind -default -f "(&(objectClass=user)(obje
See if that gives you records
Thanks
Mike
ASKER
nope same thing
Zero records return and I do know account have been removed
Zero records return and I do know account have been removed
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
http://www.joeware.net/fre
Scott has a good article here on what you are trying to do
http://blog.scottlowe.org/
So let's say you are trying to find all accounts created between Jan 1, 2009 and May 31, 2009
adfind -default -f "&(objectcategory=person)(
That will output the results to a csv drive on your C drive.
Take a look at the screenshot from my lab.
Thanks
Mike
Adfind-WhenCreated.gif