Solved

GPO TO DISABLE  INACTIVE ACCOUNTS IN  AD 2008

Posted on 2014-11-18
12
126 Views
Last Modified: 2014-11-25
I need to remove users and computers account that has not logged in to the network in the past 30 days (AD Cleanup). I want to create new OUs as "Disabled Users" and "Disabled Computers" and move these accounts to its corresponding container using a GPO. Can anyone please tell me how to accomplish this? Your feedback will be greatly appreciated.
0
Comment
Question by:Hunter24
  • 4
  • 4
  • 3
12 Comments
 
LVL 37

Assisted Solution

by:Neil Russell
Neil Russell earned 150 total points
ID: 40450471
In a word, you cant. A GPO wont manage ad in that respect.  Your best bet would be a powershell script run in task manager on a daily/weekly basis.
0
 
LVL 29

Assisted Solution

by:becraig
becraig earned 350 total points
ID: 40450473
Your best solution here would be to run a daily script to do this, there are lots of examples and ways to get there:

http://www.experts-exchange.com/Software/Server_Software/Active_Directory/Q_24890316.html
0
 

Author Comment

by:Hunter24
ID: 40450629
Thank you for your fast response in this issue. However,  I still need you to clarify my doubts,  does that mean that I can create the OUs and the script will move the objects  to it? Can these OUs be created within the Users and computers Containers or should be created somewhere else? Can this script or any other be modified to automatically delete this objects after a certain amount of time assuming that they are in the Disabled container?
0
 
LVL 37

Accepted Solution

by:
Neil Russell earned 150 total points
ID: 40450635
Containers should not be used to hold your USERS and COMPUTER objects!  They can not, for one thing, have group policies applied to them.

We do exactly what you are asking but I am not in the office with access to all of the scripts right now.

We extract users who have not logged in for xx days and disable the accounts, move them to a root/DISABLED/USERS OU.
After a further xxx days, users in that OU are then deleted.

We also remove users from ALL groups as they are disabled, email the line manager and change the password to a random one incase the account is re-enabled.
0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 40450636
I can post an article tomorrow detailing exactly how its all done, with the scripts, if you  dont have a full answer by then.
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 
LVL 29

Assisted Solution

by:becraig
becraig earned 350 total points
ID: 40450637
You can open a question to have a script created to do all you need.

From what you are saying I am guessing it would work as below.

1. Check for the destination OU if not present create it
2. Check for the users who meet the criteria if found move to that OU
3. Check users in the destination OU and if more than x days then delete.

You can create the OU anywhere you need to.
Yes the script will move the objects once found based on the logic above.
Yes the script can be created to delete objects in the disabled OU after x days.
0
 

Author Comment

by:Hunter24
ID: 40452854
Hi Neilsr
 If you have that article please post it here, it should be a very helpful guide in this process. Please note that Users and Computers ARE NOT  in the same OU as you explained. Under the domain tree there is a separate OU for each.

Hi becraig:

You got it! Points 1-3 in your answer is exactly what I need! Should I open a SEPARATE question for this script?Please advise. Thanks.
0
 
LVL 29

Expert Comment

by:becraig
ID: 40452938
I would suggest that, in the powershell zone.

Though I can write it pretty quickly there are a lot of other experts who can contribute and get you the most efficient path.
0
 

Author Comment

by:Hunter24
ID: 40453598
becraig:

I followed your recommendation and have just opened a new question in the powershell zone.
0
 
LVL 29

Expert Comment

by:becraig
ID: 40453738
Great I'll take a look, I'm sure one of the guys might have already provided a solution by now.
0
 

Author Closing Comment

by:Hunter24
ID: 40465518
Thanks to both for your support, I'm using the AD Tidy app, it has helped me a lot.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now