How to clean up dormant accunts in active directory

5 pts.
Tags:
Active Directory
Active Directory Users and Computers
Implementation plan for cleaning up dormant accounts and inactive acounts in an active dierectory

Answer Wiki

Thanks. We'll let you know when a new response is added.

You could use the queries tool in aduc to find accounts that have not been used for x amount of days and then use a dsquery string to disable those accounts.

I suppose it depends on the size of your organisation and how much user knowledge you have, as you have to think about the possibility of accidentally disabling then deleting a user account who is mearly on maternity leave of extended sickness.

One thing I think would be a good idea is to look for accounts dormant for more than 3 months say, disable them and then send an email to the head of department asking about the status of the user, if they’ve left then bingo delete it, if not leave it disabled, and always say in the email that if you dont hear anything back within 2 weeks then the account WILL be deleted (otherwise you know they will ignore your email).

Discuss This Question: 4  Replies

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
  • Wrobinson
    You may be able to cross-reference some of the accounts with human resources for terminated employees. It is important to consider that all of the domain controllers in the environment must be polled to determine the last log on time for a user. There are some tools that can automate the process such as DumpSec (http://www.somarsoft.com).
    5,625 pointsBadges:
    report
  • RoninV
    Netwrix has a small app (Inactive Users Tracker) that will aid in your situation.
    205 pointsBadges:
    report
  • Mvuyi
    [...] How to clean up dormant accunts in active directoryImplementation plan for cleaning up dormant accounts and inactive acounts in an active dierectory… [...]
    0 pointsBadges:
    report
  • Techdude2723
    RonniV is right, netwrix inactive users tracker should do the trick for you—it’s a very handy tool. The tool automatically detects, reports and deactivates all user accounts that have been inactive for a specified number of days. I know they also offer a freeware version that detects and reports on inactive accounts, but doesn’t automatically deactivate them.
    30 pointsBadges:
    report

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following