one-liner getting accounts that are flagged "password never expires"

Posted on 2016-08-09
Last Modified: 2016-08-09
I'm trying to use Powershell to give me the user accounts of those accounts that have password set to not expire.
I have written this:
Search-ADAccount -PasswordNeverExpires -usersonly |get-aduser -Filter 'name -like "*wildcard*"'  | FT Name, ObjectClass

Open in new window

When run, this first supplies everything that has my *wildcard* in the name, I thought the first part of the script would only send the user accounts that are  set to not expire, clearly it does not.

Second, after the list of users is complete it throws an error over and over for 10-15 seconds:
Search-ADAccount : The server has returned the following error: invalid enumeration context.
At line:1 char:1
+ Search-ADAccount -PasswordNeverExpires -usersonly |get-aduser -Filter 'name -lik ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : NotSpecified: (:) [Search-ADAccount], ADException
    + FullyQualifiedErrorId : The server has returned the following error: invalid enumeration context.,Microsoft.ActiveDirectory.Management.Commands.SearchADAccount
Question by:SquigglyMonkey
  • 3
  • 3
  • 2
  • +1
LVL 16

Expert Comment

ID: 41748772
Get-Aduser  -properties * -filter "PasswordNeverExpires -eq 'True'" | ft Samaccountname, DisplayName,PasswordNeverExpires
LVL 83

Expert Comment

ID: 41748779
The first part will indeed only return accounts where the password is set to not expire.
The issue is that in the next pipeline step, you're querying again for all users matching the wildcard. What you need instead of Get-ADUser is a simple Where-Clause.
The other error might be caused by the first, because you're pretty much spamming AD with queries.
How many user accounts are we talking about?
Search-ADAccount -PasswordNeverExpires -UsersOnly  -ResultSetSize $Null | ? {$_.Name -like "*wildcard*"}  | FT Name, ObjectClass 

Open in new window


Author Comment

ID: 41748808
That won't work, it just gives me  all the accounts that are set to not expire. I am looking for a subset of those accounts that contain a specific set of characters.
I see, get-aduser doesn't care what is piped to it, it just looks at AD. I'll try what you sent and see what happens.
There are north of 50k users. thousands of which are legitimately non-expiring. But I ran into a few specific user names that were set to not expire, and should not be. They all contain something that I can filter on.
Thank you.
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

LVL 16

Expert Comment

ID: 41748820
Give me what you can filter on and I will attempt to send you the correct command.  Are all the users in the same OU?  We can target the OU if they are

Author Comment

ID: 41748889
Foxluv, thanks, "priv-" or ADM- is what the accounts start with. Unfortunately, the way AD was setup in the first place, the accounts are in multiple OU's (from  geographical dispersement of sites).

odba, Thanks that is super close, It's usable, just giving me a few extra names. I tried to change -like to -contains, but that does not work at all. I tried to add or to is since the accounts start with a couple of different things.

Thanks again.
LVL 12

Expert Comment

by:Dustin Saunders
ID: 41748899
Maybe I'm not understanding by why not add your wildcard to the filter?

Get-ADUser -Properties * -Filter {PasswordNeverExpires -eq "True" -and name -like "*wildcard*"}

Open in new window

LVL 16

Assisted Solution

FOX earned 250 total points
ID: 41748912
Get-Aduser  -properties * -filter "Samaccountname -like 'priv*'" | sort PasswordNeverExpires | ft Samaccountname, DisplayName,PasswordNeverExpires

The other one would be
Get-Aduser  -properties * -filter "Samaccountname -like 'ADM*'"| sort PasswordNeverExpires |ft Samaccountname, DisplayName,PasswordNeverExpires
LVL 83

Accepted Solution

oBdA earned 250 total points
ID: 41748944
$WildCards = @('priv-*', 'adm-*')
Search-ADAccount -PasswordNeverExpires | ? {$Name = $_.Name; $WildCards | ? {$Name -like $_}} | FT Name, ObjectClass

Open in new window


Author Closing Comment

ID: 41749016
Thank you both for helping out with this.

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Need to disable SSL Cipher 7 68
How to create scheduled tasks in windows 10 via GPO 5 30
Server timing 4 20
Yes, Powershell again 5 12
OfficeMate Freezes on login or does not load after login credentials are input.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question