• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 649
  • Last Modified:

how to clean Active Directory DNS

How to clean Stale records/grabage from Active Directory DNS ,
1 Solution
For DNS you can enable scavenging:

For AD it's a manual process i'm affraid.  You can create scripts to let you know what objects are stale, or you can use 3rd party tools.  Quest Reporter is a good tool so is AD Manager Plus.
harispmAuthor Commented:
I have cleaned DSN entries manually
for cleaning up AD you can do a
dsquery user -inactive xx

Open in new window

or a
dsquery computer -inactive xx

Open in new window

xx is the number of weeks since lastlogon. nb, this takes two weeks to replicate, so for safety, add two weeks on to the value you want.

cat them to a text file to check them, then if you want to, pipe the output into dsmod to disable them

dsquery user -inactive x > c:\inactiveusers.txt
notepad c:\inactiveusers.txt
dsquery user -inactive x | dsmod user disabled=yes

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now