one-liner getting accounts that are flagged "password never expires"

I'm trying to use Powershell to give me the user accounts of those accounts that have password set to not expire.
I have written this:
Search-ADAccount -PasswordNeverExpires -usersonly |get-aduser -Filter 'name -like "*wildcard*"'  | FT Name, ObjectClass

Open in new window

When run, this first supplies everything that has my *wildcard* in the name, I thought the first part of the script would only send the user accounts that are  set to not expire, clearly it does not.

Second, after the list of users is complete it throws an error over and over for 10-15 seconds:
Search-ADAccount : The server has returned the following error: invalid enumeration context.
At line:1 char:1
+ Search-ADAccount -PasswordNeverExpires -usersonly |get-aduser -Filter 'name -lik ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [Search-ADAccount], ADException
    + FullyQualifiedErrorId : The server has returned the following error: invalid enumeration context.,Microsoft.ActiveDirectory.Management.Commands.SearchADAccount
Who is Participating?
oBdAConnect With a Mentor Commented:
$WildCards = @('priv-*', 'adm-*')
Search-ADAccount -PasswordNeverExpires | ? {$Name = $_.Name; $WildCards | ? {$Name -like $_}} | FT Name, ObjectClass

Open in new window

FOXActive Directory/Exchange EngineerCommented:
Get-Aduser  -properties * -filter "PasswordNeverExpires -eq 'True'" | ft Samaccountname, DisplayName,PasswordNeverExpires
The first part will indeed only return accounts where the password is set to not expire.
The issue is that in the next pipeline step, you're querying again for all users matching the wildcard. What you need instead of Get-ADUser is a simple Where-Clause.
The other error might be caused by the first, because you're pretty much spamming AD with queries.
How many user accounts are we talking about?
Search-ADAccount -PasswordNeverExpires -UsersOnly  -ResultSetSize $Null | ? {$_.Name -like "*wildcard*"}  | FT Name, ObjectClass 

Open in new window

Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

SquigglyMonkeyAuthor Commented:
That won't work, it just gives me  all the accounts that are set to not expire. I am looking for a subset of those accounts that contain a specific set of characters.
I see, get-aduser doesn't care what is piped to it, it just looks at AD. I'll try what you sent and see what happens.
There are north of 50k users. thousands of which are legitimately non-expiring. But I ran into a few specific user names that were set to not expire, and should not be. They all contain something that I can filter on.
Thank you.
FOXActive Directory/Exchange EngineerCommented:
Give me what you can filter on and I will attempt to send you the correct command.  Are all the users in the same OU?  We can target the OU if they are
SquigglyMonkeyAuthor Commented:
Foxluv, thanks, "priv-" or ADM- is what the accounts start with. Unfortunately, the way AD was setup in the first place, the accounts are in multiple OU's (from  geographical dispersement of sites).

odba, Thanks that is super close, It's usable, just giving me a few extra names. I tried to change -like to -contains, but that does not work at all. I tried to add or to is since the accounts start with a couple of different things.

Thanks again.
Dustin SaundersDirector of OperationsCommented:
Maybe I'm not understanding by why not add your wildcard to the filter?

Get-ADUser -Properties * -Filter {PasswordNeverExpires -eq "True" -and name -like "*wildcard*"}

Open in new window

FOXConnect With a Mentor Active Directory/Exchange EngineerCommented:
Get-Aduser  -properties * -filter "Samaccountname -like 'priv*'" | sort PasswordNeverExpires | ft Samaccountname, DisplayName,PasswordNeverExpires

The other one would be
Get-Aduser  -properties * -filter "Samaccountname -like 'ADM*'"| sort PasswordNeverExpires |ft Samaccountname, DisplayName,PasswordNeverExpires
SquigglyMonkeyAuthor Commented:
Thank you both for helping out with this.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.