Retrieve Active directory disabled account by Date

Posted on 2013-11-17
Medium Priority
Last Modified: 2013-11-26
I need a script that retrieves Active Directory disabled accounts by Date.

for instance  smith account disabled on 02/12/2013

Any help will be very much appreciated.

Thank you
Question by:jskfan
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
LVL 53

Expert Comment

by:Will Szymkowski
ID: 39655310
Use the following command below to accomplish this...

Import-module activedirectory
$date = get-date 02/12/2013
get-aduser -filter * -properties * | ? {$_.enabled -eq $false -and $_.whenChanged -eq $date} | select Name, whenChanged, Enabled

Open in new window


Author Comment

ID: 39657112
it does not display anything
LVL 53

Accepted Solution

Will Szymkowski earned 1000 total points
ID: 39657211
If the account has been modified since it was disabled then the time will change.

Use the following command and you can sort the time and easily see what accounts have been disabled during the time/day you have specificed.

get-aduser -filter * -properties * | ? {$_.enabled -eq $false} | sort -property whenChanged | select name, enabled, whenChanged

Open in new window

You can also export this to a csv as well see below...

get-aduser -filter * -properties * | ? {$_.enabled -eq $false} | sort -property whenChanged | select name, enabled, whenChanged | export-csv "c:\disabledusers.csv"

Open in new window


Assisted Solution

Pankaj_401 earned 1000 total points
ID: 39660737
There is no timestamp for this specifically. Assuming the accounts haven't
been touched since you disabled them, you can look at the whenLastModified also you need to look at  two fields for this:
"userAccountControl" and "whenChanged"
In "userAccountControl" indicates a disabled account"whenChanged"should tell you when the account was disabled.
For more info look at this also: http://blogs.technet.com/b/heyscriptingguy/archive/2005/05/12/how-can-i-get-a-list-of-all-the-disabled-user-accounts-in-active-directory.aspx

Author Closing Comment

ID: 39678529
Thank you Guys

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question