Summary: Easily find disabled user accounts in Active Directory Domain Services (AD DS) by using Windows PowerShell.

Hey, Scripting Guy! Question How can I easily use Windows PowerShell to find disabled user accounts?

Hey, Scripting Guy! Answer Use the Search-ADAccount cmdlet from the Active Directory module in the RSAT tools, and specify the AccountDisabled and UsersOnly switches:

Search-ADAccount -AccountDisabled -UsersOnly

  1. David Wyatt says:

    You can also use this command:

    Get-ADUser -Filter 'Enabled -eq $false'

    The main difference is that Get-ADUser returns ADUser objects (and you can specifiy which properties to fetch via the -Properties parameter), whereas Search-ADAccount returns ADAccount objects with a fixed set of properties (AccountExpirationDate, DistinguishedName, Enabled, LastLogonDate, LockedOut, Name, ObjectClass, ObjectGUID, PasswordExpired, PasswordNeverExpires, SamAccountName, SID, and UserPrincipalName.)

  2. AllenRich says:

  3. joseph says:

  4. Mahesh Adate says:

