troubleshooting Question

Windows batch script to list / disable /delete dormant AD accounts

Avatar of sunhux
sunhux asked on
PowershellWindows BatchVB ScriptActive Directory
5 Comments2 Solutions124 ViewsLast Modified:
Does GPO / AD has feature or policy that could disable accounts that are inactive
for a certain number of days?

There are PowerShell scripts around but we are told to disable/remove Powershell
due to fileless attacks.

Ideally a windows batch or VB script.

I noticed  ' net user /domain  userid | find "Last logon"  '  has a date : if we could
iterate through all domain IDs & calculate based on this date, it will help.

There's oldcmp tool which seems to work for Win 2012 R2 AD but the csv output
it gives doesn't seem to provide any domain id in it or I've used it wrongly?
austin minor

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 2 Answers and 5 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 5 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros