Active Directory Management

Hi there,

I am trying to configure automatic user account expiration in Windows 2008 R2 Active Directory.  I would like i tot use the DSQuery and DSMod commands.  I have piped a DSMod in a DSQuery but syntax is wrong.  I need it to automatic disable user accounts after 90 days of inactivity.  Can someone help?

Thanks in advance.
Who is Participating?
dave121Connect With a Mentor Commented:

You can refer to the link mentioned below for the powershell code-
Will SzymkowskiConnect With a Mentor Senior Solution ArchitectCommented:
This is very easy to accomplish using Powershell. I have added code below to accomplish what you are looking for...

Import-module activedirectory
$expires = get-date
$UserName = read-host "Enter Username Here"
Set-ADUser $Username -AccountExpirationDate $expires.adddays(90)

This script will do accounts 1 by 1 if you want me to modify it based on a CSV or txt file, please advise.

jasonhdzAuthor Commented:
Thanks everyone.

I basically need the script to be able to check:
1.  The last time users in active directory logged in
2.  If this is more than 60 days, then disable the account.

I dont have a X number of static users, it may increase or decrease significantly. that is why i need it to be able to check all users...maybe on a daily basis.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.