Find disabled Active Directory User accounts

There may be times you need to find or report on disabled Active Directory user accounts. It’s best practice to do regular maintenance on AD objects and remove disabled or inactive objects (after verifying they are no longer needed of course). In this post, I will walk through three methods for finding disabled user accounts.

Method 1: Find Common Queries

1. Open Active Directory Users and Computer

2. Click the find objects button

3. In the Find Common Queries window, select “Common Queries” from the Find drop down and “Entire Directory” from the In: drop down. Check the box “Disabled accounts”

Once you have selected the above settings and clicked “Find Now” you will have a list of all the disabled accounts. Easy, right?

Method 2: Saved Queries

The saved queries in Active Directory Users and Computers can be used to create simple and complex LDAP search filters.

1. Open Active Directory Users and Computers

2. Right click Saved Queries and select New Query

3. Give the query a name then click the Define Query button. I named my query Disabled Users.

4. On the Find Common Queries box click the Disable Accounts box and click ok.

5. The query string box should now be populated with the LDAP syntax. Click OK

6. Click on the Disabled Users query under Saved Queries. You should now see all the disabled accounts.

Now every time you open AD you will have this saved query so you can quickly find disabled accounts.

Method 3: Powershell

This last example uses PowerShell to return the disabled accounts. I will show you to different PowerShell commands that display the results a bit different.

1. Open PowerShell and run the command below

Search-ADAccount -AccountDisabled

This command returns not only the username but many other attributes. In most cases, you will just want the username.

2. Run the command below to return only the username of disabled accounts.

Get-ADUser -Filter {Enabled -eq $false} | FT samAccountName

Most organizations have a policy to leave accounts disabled for a period of time, such as 30 days. If you don’t have a procedure in place to go back and delete the account, your Active Directory will become a mess. This post has provided three methods that can be used to quickly find disabled accounts in Active Directory.

You might also like:
Find Users accounts with password set to never expire
Find a user’s last logon time


  1. A on January 7, 2019 at 9:18 pm

    I am using version 10.0.17132.1 of Active Directory Users and Computers and am not seeing the options that you display above.

    When I open the find window I have two tabs: “Users, Contact and Groups” and “Advanced” – this window is titled “Find Users, Contacts and Groups” as opposed to “Find Common Queries” as you present above.

    • Robert Allen on January 8, 2019 at 1:47 pm

      First select Find Common queries from the find drop down box.

  2. krishnan on June 25, 2019 at 10:36 am

    How to export those user list

    • Robert Allen on January 1, 2021 at 5:16 pm

      Hi Krishnan,

      Get-ADUser -Filter {Enabled -eq $false} | FT samAccountName | export-csv -path c:\csvpath.csv

  3. Zhaleh on October 11, 2020 at 9:18 am

    Vary useful. Many tnx.

    • Manish kumar on June 3, 2021 at 11:27 am

      How to get those reports with disabled user date..

Leave a Comment