Ask the Expert

Checking inactive accounts with Active Directory

How can I check what users have not logged into their accounts > 60 days using Active Directory and Windows 2000?

Requires Free Membership to View

There are several ways to perform this. A simple way to perform this would be to run the NET USER command on any user that you would like to know. You could also use ADSI scripting to produce the output a little cleaner. . Output a list of the names by exporting them from AD. Then you can use a simply FOR statement to reset the accounts. Let's say your text file is names.txt. Create a batch file called CheckUser.bat. Put in the batch file the following:
FOR /F %%I in (names.txt) do SHOWUSER

Echo %%I 
NET USER %%I /DOMAIN | FIND "Last logon"

This was first published in August 2004

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: