Active Directory Cleanup Tool
The Active Directory Cleanup Tool will quickly identify stale and inactive users and computers in your Active Directory Domain. Inactive objects in Active Directory can provide unauthorized access to sensitive data and resources.
Download Free TrialEasily Find Inactive User and Computer Accounts
It’s important to regular check Active Directory for stale objects and then disable and remove them. Native Active Directory Tools do not provide an easy way to check the entire domain for stale accounts. With the AD Cleanup Tool, you can easily search your Active Directory environment for stale objects and move, disable and delete them.
Features
- Cleanup inactive user and computer accounts
- Find inactive users after x days of inactivity
- Bulk move, disable and delete accounts stale accounts
- Automate cleanup process with built-in schedular
- Find expired accounts and users with no logons
- Export reports to CSV, Excel or PDF
How to use the AD Cleanup Tool
To find inactive user accounts follow the steps below.
- Click on “Security tools” > AD Cleanup.
- Select an OU or leave it as the default to run on the entire domain.
- Select the time frame (default is last 90 days) and click run. This is how long the account has been inactive based on the lastLogonTimestamp of the user or computer account.
Move, delete, disable or export inactive accounts
With the AD Cleanup Tool, you can select single or multiple accounts and choose to disable, delete, move or export the accounts. The recommended way to clean up stale accounts is to move them to an inactive OU, disable them for x days and then delete the account.
To export the report, click the export button and select from CSV, Excel or PDF.
To move accounts to another OU select them from the results grid and click the move button.
To disable accounts, select them from the results grid and click the disable button.
Find Disabled Users
To find all disabled users click the “disabled users” box and click run.
Users with No Logons
Users with no logons are accounts that have no date in the lastlogonTimestamp attribute.
Click on “users with no logons” and click run.
Expired Users
Expired accounts are accounts that have a date set under the account expires settings.
To find all expired users click the “expired users” box and click run.
Find Inactive Computers
To find inactive computers click the “Inactive Computers” box select the time range and click run.
Find Empty Groups
Empty groups are groups that have no members.
To find all empty groups click the “empty groups” box and click run.
Cleanup Group Policy Objects
Just like user and computer accounts, there can be stale or unused GPOs in your environment. These unused or disabled GPOs can make a mess of your AD and cause confusion with other Administrators. The AD Pro Toolkit provides GPO reports and makes it easy to find unused GPOs.
To find unused GPOs click on Group Policy Report -> All GPOs
Any GPO that is not used will have the location blank. This means the GPO is not linked to the domain or an OU so it is currently not in use.
Automate Active Directory Cleanup
With the built-in schedular you can automate cleaning up stale accounts in Active Directory.
- Automatically disable stale accounts
- Automate moving and setting a description
- Send email reports on stale accounts
- Delete account that have been disabled for x days