[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

How long do machines stay in AD?

Posted on 2016-09-30
6
Medium Priority
?
59 Views
Last Modified: 2016-11-09
If machines have been removed off the network, is there a setting to remove the machines from AD automatically? Or do we have to do it manually?

If there is a setting, where is it?
0
Comment
Question by:Thomas N
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 17

Expert Comment

by:pjam
ID: 41823549
Interesting question.  I have always deleted them as they stay there until I do.
If there is a setting I would like to know too
0
 
LVL 17

Expert Comment

by:Ivan
ID: 41823551
Hi,

I don't think there is a setting for that. Machines not connected in 90 days loose connectivity and have to be rejoined. As far as I know, you would have to do it manually.

I guess that it could be done via some script, that would check when did machine last time connected to domain, and if it did not in past XX days, it would delete computer account.. but I would not do it.

Maybe some1 else has some idea :)

Regards,
Ivan.
0
 
LVL 22

Accepted Solution

by:
Joseph Moody earned 1336 total points
ID: 41823553
There is not a built in stale object removal feature in AD. There are many free scripts and tools though. My favorite is oldcmp. http://www.joeware.net/freetools/tools/oldcmp/index.htm

But you can also use powershell (here is an example: https://deployhappiness.com/managing-inactive-computers-and-users-in-active-directory/)
0
 
LVL 22

Assisted Solution

by:Joseph Moody
Joseph Moody earned 1336 total points
ID: 41823557
Before deleting computers, you will want to enable the AD recycle bin as a safety switch. Some people also disable the objects and move them to a special OU for X amount of time before deleting them.
0
 
LVL 56

Assisted Solution

by:McKnife
McKnife earned 664 total points
ID: 41824686
@Ivan's "Machines not connected in 90 days loose connectivity and have to be rejoined." - what are you talking about? There is no such mechanism, you can stay offline like forever an you are still able to connect, no unjoining takes place.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question