Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Inactive Users

Status
Not open for further replies.

Boxalld

Technical User
Apr 20, 2004
42
GB
Hi,
Im currently trying to sift through our AD to weed out user accounts ( Including Service accounts ) that are no longer being used.

I have used a script to generate the lastlogonstamp also used dsquery user -inactive.

The script for lastlogonstamp shows a bunch of accounts that have never logged on thus dont have a lastlogontimestamp. When you run dsquery user -inactive these accounts dont show.

I know some of these accounts are active and there doing ldap lookups for applications, i have read that this type of use does not log a logontimestamp! even though the account authenticates to AD...

Has anybody else seen this and if so how did you get around this etc etc ??? ( Stalepwd is not an option as lots of these accounts have nonexpire passwords and they are never changed!!!

Cheers
 
In your ADUC / DSA.msc you can go to Saved Queries and define a new query. give it a name, then Define Query. Under Common Queries, the Users tab has a "days since last logon" that I have found extremely useful.

_______________________________________
Great knowledge can be obtained by mastering the Google algorithm.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top