Disable Inactive Active Directory Accounts POWERSHELL Script

Posted on 2011-03-21
Last Modified: 2012-05-11
I'm sure this has been done plenty of times but I can't seem to find a script that will disable active directory accounts (OU = Users) after 90 days of inactivity and move them to another OU called 'Users - Disabled'.  Would anyone be able to provide me with a powershell script that would do this?

Server 2008 Standard SP2
Question by:cmb991
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4

Expert Comment

ID: 35185298
Does it have to be Powershell? I started writing a script of my own to do this, then found this one linked below, which did 90% of what I required and I just added a little customisation.

Expert Comment

ID: 35185328
Ah, my mistake... this is for computer accounts, sorry.

It shouldn't be too difficult to change to user accounts, though.

To disable a user's account, set the UserAccountControl attribute to 0x0202 (0x002 + 0x0200)

Accepted Solution

Draxonic earned 500 total points
ID: 35186710

Author Comment

ID: 35220348
What would be the best way to do this, powershell or VB?  I'm starting to rethink of this issue and trying to figure out the best way.

Expert Comment

ID: 35224606
It doesn't really matter which way you do this.

In terms of programming, I understand that PS is more versatile for manipulation of Microsoft systems, but unless you're actually doing the programming, this is a moot point.

So, a choice of VB or PS is like a choice of bourbon or whiskey. Both will get you drunk, but it's simply a matter of which you prefer.

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Active Directory replication delay is the cause to many problems.  Here is a super easy script to force Active Directory replication to all sites with by using an elevated PowerShell command prompt, and a tool to verify your changes.
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question