Solved

Script to generate inactive users from Active Directory

Posted on 2015-02-11
5
113 Views
Last Modified: 2015-02-18
Hello, need help to have script to export (csv or excel) details of inactive user in active directory beyond certain days (eg. 90 days).

The report should have below attributes (including last logon date & time):-
displayName
samAccountName
Description
title
mail
department
telephoneNumber
MOBILE
postalCode
Manager
physicalDeliveryOfficeName,
Company
lastlogondate & time
0
Comment
Question by:TJOSY
  • 2
5 Comments
 
LVL 4

Expert Comment

by:Manoj Bojewar
ID: 40605105
use this attached tool, this will give you exact report.
0
 
LVL 4

Expert Comment

by:Manoj Bojewar
ID: 40605113
0
 

Author Comment

by:TJOSY
ID: 40611137
Thank you Manoj. infact I am looking for PowerShell or vbscript
0
 
LVL 70

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 40613674
I assume you want to us the MS AD module?
Import-Module ActiveDirectory
$Properties = "displayName", "sAMAccountName", "description", "title", "mail", "department", "telephoneNumber", "mobile", "postalCode", "manager", "physicalDeliveryOfficeName", "Company", "lastLogonTimeStamp"
$LastLogonLimit = (Get-Date).AddDays(-90)
Get-ADUser -Filter { LastLogonTimeStamp -lt $LastLogonLimit -and Enabled -eq $true } -Properties $Properties |
  Select-Object $Properties |
  Export-Csv "InactiveReport.csv" -NoTypeInformation

Open in new window

You may choose to remove the "Enabled -eq $true" part of the filter. That's only there to drop disabled accounts from the result set.

lastLogonTimeStamp needs a note as well. It's used because lastLogon is not replicated between domain controllers. lastLogonTimeStamp is, but may be up to 14 days out of date so it's more of a guideline than a definite value. Still, for a 90 day period it should suffice.

HTH

Chris
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Set OWA language and time zone in Exchange for individuals, all users or per database.
If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
Windows 8 comes with a dramatically different user interface known as Metro. Notably missing from the new interface is a Start button and Start Menu. Many users do not like it, much preferring the interface of earlier versions — Windows 7, Windows X…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now