Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

non expiring and enabled/disabled in ADUC

Posted on 2014-02-11
6
Medium Priority
?
643 Views
Last Modified: 2014-02-20
is there anyway in ad users and computers to run a report of all users who have non-expiring password, and also their account status, i.e. enabled or disabled?
0
Comment
Question by:pma111
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 17

Expert Comment

by:Lior Karasenti
ID: 39849743
This script can help you to find all the none expired passwords:

http://gallery.technet.microsoft.com/scriptcenter/Know-All-User-Accounts-in-721c81f3
0
 
LVL 3

Author Comment

by:pma111
ID: 39849746
i dont want to use a script i want to use aduc, thanks.
0
 
LVL 11

Accepted Solution

by:
Manjunath Sullad earned 2000 total points
ID: 39849795
open ADUC and do the following.

Right-click Saved Queries and click the New-Query option
Type in a name for your saved query, such as Find all Non expiring PW Users
Click the Define Query button
Under the Find drop-down list, select Custom Search
Click the Advanced tab
Type in (objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=65536)
Click the OK button to save the custom entry, then click on the OK button to save the query
Now you should see all users with the flage pw never expires

Click the Export List button from the top of the ADUC windows and save to txt file.



Refer : http://social.technet.microsoft.com/Forums/windowsserver/en-US/e979eb85-8269-4004-bc71-18d9b49d4416/how-to-check-list-users-in-my-ad-configured-with-password-never-expires?forum=winserverDS
0
NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

 
LVL 3

Author Comment

by:pma111
ID: 39849797
will this list account status i.e. enabled/disabled?
0
 
LVL 11

Expert Comment

by:Manjunath Sullad
ID: 39849817
You need to export disabled user list seperately, then compare with password never expiry list.

Refer below link to export disabled user list.

http://social.technet.microsoft.com/Forums/windowsserver/en-US/074e3391-000d-4713-a495-ad743c2f11e3/active-directory-users-and-computers?forum=winservergen


Export these two list to excel and compare these list, You will get Password never expiry with account disabled / enabled user list.
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 39849976
You could use Bulk AD users Freeware tool from Wise soft

There is option called properties to load where you can put whatever attributes you are looking and then export this list to csv file

The search scope can be entire domain, OU or simply users list if you already have

To check account status add userAccountControl attribute and to check if it is having non expiring password add accountExpires

Tool can be run on any server \ client OS from 2003 and do not require PowerShell

http://www.wisesoft.co.uk/software/bulkadusers/default.aspx

Mahesh
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question