J
Jerry G. Young II
All,
I'm looking for a means that will allow me to automate computer object
cleanup in Active Directory.
My thought was to write a script that checks the last time a computer
account's password has been changed (by default, computer accounts change
their password every 7 days) and if this date is more than a month ago to
disable the computer account. A secondary script would then check for
disabled computer accounts and delete them if a set of other conditions had
been met.
However, I haven't had any luck in finding a scriptable means to check the
last time a computer account's password has been changed.
If anyone knows, can you let me know? Or, if there is another scriptable
means to determine if a computer account is most likely no longer used, that
would be fine, too.
Thanks in advance.
Cordially yours,
Jerry G. Young II
I'm looking for a means that will allow me to automate computer object
cleanup in Active Directory.
My thought was to write a script that checks the last time a computer
account's password has been changed (by default, computer accounts change
their password every 7 days) and if this date is more than a month ago to
disable the computer account. A secondary script would then check for
disabled computer accounts and delete them if a set of other conditions had
been met.
However, I haven't had any luck in finding a scriptable means to check the
last time a computer account's password has been changed.
If anyone knows, can you let me know? Or, if there is another scriptable
means to determine if a computer account is most likely no longer used, that
would be fine, too.
Thanks in advance.
Cordially yours,
Jerry G. Young II