How to Disable old computer accounts in AD
- May 6th, 2010
- Posted in Microsoft . Tricks . windows
- Write comment
Becuase ‘dsmod‘ & ‘dsquery‘ support piping (passing results to a new command) you can easliy send results from dsquery to dsmod.
I wanted to disable old computer accounts, then after 60 days I will delete them.
dsquery computer -inactive 8 -limit 0 | dsmod computer -disabled yes
The above will search for computers that have not connected for 8 weeks, say after being removed, destroyed etc. then it will disable the computer account.
I a few weeks I will then search for disabled accounts, might export a list and then delete them form AD.
you could expand this and createa a weekly task that would check and disable/delete accounts, or move them to a locked down part of AD etc.
J
No comments yet.