Skip to content

Active Directory

Franck SALLET edited this page Sep 5, 2026 · 1 revision

Active Directory

User, group, and computer account management, auditing, replication, and site topology for Active Directory Domain Services. Requires the ActiveDirectory RSAT module.

22 function(s) in Public/activedirectory/.

Functions

Reference

Disable-ADUserAccount

Disables one or more Active Directory user accounts.

Disables Active Directory user accounts using the Disable-ADAccount cmdlet. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.

Syntax

Disable-ADUserAccount -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Disable-ADUserAccount -Identity 'jdoe'

Disables the user account jdoe in the current domain.

Disable-ADUserAccount -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'

Disables two user accounts targeting a specific domain controller.

'jdoe', 'asmith' | Disable-ADUserAccount -Credential (Get-Credential)

Disables user accounts via pipeline input with alternate credentials.

Output: PSWinOps.ADAccountDisableResult

Returns objects with Identity, UserName, Success, Message, and Timestamp properties.


Enable-ADUserAccount

Enables one or more disabled Active Directory user accounts.

Enables disabled Active Directory user accounts using the Enable-ADAccount cmdlet. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.

Syntax

Enable-ADUserAccount -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Enable-ADUserAccount -Identity 'jdoe'

Enables the disabled user account jdoe in the current domain.

Enable-ADUserAccount -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'

Enables two user accounts targeting a specific domain controller.

'jdoe', 'asmith' | Enable-ADUserAccount -Credential (Get-Credential)

Enables user accounts via pipeline input with alternate credentials.

Output: PSWinOps.ADAccountEnableResult

Returns objects with Identity, UserName, Success, Message, and Timestamp properties.


Get-ADComputerDetail

Retrieves detailed Active Directory computer account information.

Queries Active Directory for comprehensive computer account details including operating system, network information, group membership count, and organizational unit. Supports pipeline input for processing multiple computer identities at once.

Syntax

Get-ADComputerDetail -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADComputerDetail -Identity 'SRV01'

Retrieves detailed information for the computer account SRV01.

Get-ADComputerDetail -Identity 'SRV01' -Server 'dc01.contoso.com'

Retrieves computer details from a specific domain controller.

'SRV01', 'SRV02' | Get-ADComputerDetail

Retrieves details for multiple computers via pipeline input.

Output: PSWinOps.ADComputerDetail

Returns a custom object with comprehensive computer account properties including operating system, network details, group membership count, and organizational unit.


Get-ADComputerInventory

Retrieves Active Directory computer accounts with key audit properties.

Lists all Active Directory computer accounts with inventory and audit properties. Returns a typed PSWinOps.ADComputerInventory object per computer with logon, password, OS, and lifecycle metadata for review and compliance reporting.

Syntax

Get-ADComputerInventory [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>] [-IncludeDisabled]

Examples

Get-ADComputerInventory

Returns all enabled computer accounts from the current domain.

Get-ADComputerInventory -SearchBase 'OU=Servers,DC=corp,DC=local' -Server 'DC01'

Returns enabled computer accounts from the Servers OU querying DC01.

Get-ADComputerInventory -IncludeDisabled -Credential (Get-Credential)

Returns all computer accounts including disabled ones using explicit credentials.

Output: PSWinOps.ADComputerInventory

Returns objects with Name, SamAccountName, Enabled, LastLogonDate, LockedOut, PasswordExpired, PasswordLastSet, WhenChanged, WhenCreated, OperatingSystem, OrganizationalUnit, and Timestamp properties.


Get-ADDomainInfo

Retrieves a comprehensive summary of an Active Directory domain.

Returns the identity card of an Active Directory domain including functional levels, FSMO role holders, domain controller inventory, site topology, object counts (users, computers, groups, OUs), and password policy. Designed as the first command to run when discovering an unfamiliar domain. All data is gathered from a single domain context using standard AD cmdlets.

Syntax

Get-ADDomainInfo [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADDomainInfo

Returns a full summary of the current domain.

Get-ADDomainInfo -Server 'dc01.contoso.com'

Returns domain information from a specific domain controller.

Get-ADDomainInfo -Server 'child.contoso.com' -Credential (Get-Credential)

Returns domain information for a child domain using alternate credentials.

Output: PSWinOps.ADDomainInfo

Returns a single object with domain identity, functional levels, FSMO holders, DC list, site names, object counts, and default password policy.


Get-ADGroupInventory

Inventories Active Directory groups with member count and metadata.

Retrieves all Active Directory groups and returns audit-ready objects including member count, scope, category, and organizational unit path extracted from the distinguished name. By default only groups with at least one member are returned.

Syntax

Get-ADGroupInventory [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>] [-IncludeEmpty]

Examples

Get-ADGroupInventory

Returns all non-empty AD groups in the current domain sorted by name.

Get-ADGroupInventory -SearchBase 'OU=Groups,DC=corp,DC=local' -Server 'DC01'

Returns non-empty groups from a specific OU targeting a specific domain controller.

Get-ADGroupInventory -IncludeEmpty -Credential (Get-Credential)

Returns all groups including empty ones using alternate credentials.

Output: PSWinOps.ADGroupInventory

Returns objects with Name, SamAccountName, GroupScope, GroupCategory, MemberCount, Description, OrganizationalUnit, and Timestamp properties.


Get-ADGroupMembership

Retrieves members of an Active Directory group.

Queries Active Directory for group membership details with optional recursive enumeration. When the Recursive switch is used, both direct and nested members are returned with an IsDirect flag indicating membership type.

Syntax

Get-ADGroupMembership -Identity <string[]> [-Recursive] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADGroupMembership -Identity 'Domain Admins'

Retrieves direct members of the Domain Admins group.

Get-ADGroupMembership -Identity 'Domain Admins' -Recursive -Server 'dc01.contoso.com'

Retrieves all nested members from a specific domain controller with direct/nested flags.

'Domain Admins', 'Enterprise Admins' | Get-ADGroupMembership

Retrieves direct members of multiple groups via pipeline input.

Output: PSWinOps.ADGroupMember

Returns custom objects with group name, member details, object class, and IsDirect flag sorted by ObjectClass then MemberName.


Get-ADLockedAccount

Finds all currently locked Active Directory user accounts.

Searches Active Directory for user accounts that are currently locked out. Returns detailed lockout information including lockout time, bad logon count, and last bad password attempt. Results are sorted by most recent lockout first.

Syntax

Get-ADLockedAccount [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADLockedAccount

Finds all locked accounts in the domain.

Get-ADLockedAccount -Server 'dc01.contoso.com'

Finds all locked accounts from a specific domain controller.

Get-ADLockedAccount -SearchBase 'OU=Users,DC=contoso,DC=com'

Finds locked accounts within a specific OU.

Output: PSWinOps.ADLockedAccount

Returns objects with account identity, lockout time, bad password attempt details, sorted by most recent lockout first.


Get-ADNestedGroupMembership

Retrieves all nested Active Directory group memberships for a principal.

Resolves all direct and nested group memberships for one or more AD principals using a single LDAP query with the LDAP_MATCHING_RULE_IN_CHAIN OID (1.2.840.113556.1.4.1941). This approach is significantly faster than recursive Get-ADPrincipalGroupMembership calls because the domain controller performs the recursion server-side in a single round-trip. Each returned object indicates whether the membership is direct or inherited (nested).

Syntax

Get-ADNestedGroupMembership -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADNestedGroupMembership -Identity 'jdoe'

Retrieves all direct and nested group memberships for user jdoe using the default DC.

Get-ADNestedGroupMembership -Identity 'jdoe' -Server 'DC01.contoso.com'

Retrieves all group memberships for user jdoe targeting a specific domain controller.

'jdoe', 'svc-app01' | Get-ADNestedGroupMembership

Retrieves nested group memberships for multiple principals via pipeline input.

Output: PSWinOps.ADNestedGroupMembership

Returns one object per group membership with Identity, GroupName, GroupDN, GroupCategory, GroupScope, Description, IsDirect, and Timestamp properties.


Get-ADPasswordStatus

Audits password status of all Active Directory user accounts.

Returns the password status of all enabled Active Directory user accounts including password age, expiry date, applied password policy (Fine-Grained Password Policy or Default Domain Policy), and problem flags. By default all enabled accounts are returned. Use the -ProblemsOnly switch to filter to accounts with password concerns only (expired, never expires, or must change at next logon). Use the -ExpiredOnly switch to return only accounts whose password has actually expired.

Syntax

Get-ADPasswordStatus [-ProblemsOnly] [-ExpiredOnly] [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADPasswordStatus

Returns password status for all enabled user accounts in the domain.

Get-ADPasswordStatus -ProblemsOnly -Server 'dc01.contoso.com'

Returns only accounts with password concerns from a specific domain controller.

Get-ADPasswordStatus -ExpiredOnly

Returns only accounts whose password has actually expired.

Get-ADPasswordStatus -SearchBase 'OU=Users,DC=contoso,DC=com' | Where-Object DaysUntilExpiry -lt 14

Returns accounts in a specific OU whose passwords expire within 14 days.

Output: PSWinOps.ADPasswordStatus

Returns objects with account identity, password state flags, applied password policy name, password age, expiry date, and days until expiry.


Get-ADPrivilegedAccount

Lists members of privileged Active Directory groups.

Enumerates members of high-privilege AD groups such as Domain Admins, Enterprise Admins, and Schema Admins. Supports custom group lists and optional recursive enumeration. For user members, additional properties like Enabled status and last logon are retrieved.

Syntax

Get-ADPrivilegedAccount [-GroupName <string[]>] [-DirectOnly] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADPrivilegedAccount

Lists members of all default privileged groups.

Get-ADPrivilegedAccount -GroupName 'Domain Admins', 'Enterprise Admins' -Server 'dc01.contoso.com'

Audits specific groups from a targeted domain controller.

Get-ADPrivilegedAccount -DirectOnly -GroupName 'Domain Admins'

Lists only direct members of Domain Admins without recursing nested groups.

Output: PSWinOps.ADPrivilegedAccount

Returns objects with group name, member identity, object class, enabled status, and last logon date sorted by group name then member name.


Get-ADReplicationStatus

Retrieves Active Directory replication status for one or more domain controllers.

Queries replication partner metadata and failure information for Active Directory domain controllers. When no Server is specified, automatically discovers all DCs in the current domain via Get-ADDomainController. Returns one object per DC/partner/ partition combination with health status derived from replication result codes and consecutive failure counts.

Syntax

Get-ADReplicationStatus [-Server <string[]>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADReplicationStatus

Discovers all domain controllers and returns replication status for each.

Get-ADReplicationStatus -Server 'DC01.contoso.com'

Returns replication status for a specific domain controller.

'DC01', 'DC02' | Get-ADReplicationStatus -Credential (Get-Credential)

Returns replication status for multiple DCs via pipeline with alternate credentials.

Output: PSWinOps.ADReplicationStatus

Returns objects with Server, Partner, Partition, LastAttempt, LastSuccess, LastResult, ConsecutiveFailures, Status, and Timestamp properties.


Get-ADSiteTopology

Retrieves Active Directory site topology including sites, subnets, and site links.

Returns one object per AD site with associated subnets, site links, replication cost/interval, and domain controllers hosted in each site. Provides a complete picture of the AD physical topology for capacity planning, replication analysis, and subnet auditing.

Syntax

Get-ADSiteTopology [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADSiteTopology

Returns topology information for all sites in the current forest.

Get-ADSiteTopology -Server 'dc01.contoso.com'

Returns site topology from a specific domain controller.

Get-ADSiteTopology -Credential (Get-Credential) | Where-Object SubnetCount -eq 0

Finds sites with no subnets assigned, which may indicate configuration issues.

Output: PSWinOps.ADSiteTopology

Returns one object per site with site name, description, subnets, site links, replication details, and domain controller list.


Get-ADStaleAccount

Finds Active Directory accounts that have been inactive for a specified number of days.

Scans Active Directory for user and/or computer accounts that have not logged in within the specified number of days. Accounts that have never logged in are included by default. Results are sorted by days since last logon in descending order.

Syntax

Get-ADStaleAccount [-DaysInactive <int>] [-AccountType <string>] [-SearchBase <string>] [-IncludeDisabled] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADStaleAccount

Finds all enabled user and computer accounts inactive for more than 90 days (default).

Get-ADStaleAccount -DaysInactive 180 -AccountType User -Server 'dc01.contoso.com'

Finds stale user accounts only from a specific domain controller.

Get-ADStaleAccount -DaysInactive 60 -IncludeDisabled -SearchBase 'OU=Workstations,DC=contoso,DC=com'

Finds stale accounts including disabled ones within a specific OU.

Output: PSWinOps.ADStaleAccount

Returns objects with account identity, type, last logon information, and days since last logon sorted by most stale first.


Get-ADStaleComputer

Finds Active Directory computer accounts that have been inactive for a specified number of days.

Scans Active Directory for computer accounts that have not authenticated within the specified number of days. Computers that have never logged in are included by default. Returns operating system details alongside staleness information to help identify obsolete machines. Results are sorted by days since last logon in descending order.

Syntax

Get-ADStaleComputer [-DaysInactive <int>] [-SearchBase <string>] [-IncludeDisabled] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADStaleComputer

Finds all enabled computer accounts inactive for more than 90 days (default).

Get-ADStaleComputer -DaysInactive 180 -Server 'dc01.contoso.com'

Finds stale computers from a specific domain controller using a 180-day threshold.

Get-ADStaleComputer -DaysInactive 60 -IncludeDisabled -SearchBase 'OU=Workstations,DC=contoso,DC=com'

Finds stale computers including disabled ones within a specific OU.

Output: PSWinOps.ADStaleComputer

Returns objects with computer identity, operating system information, last logon date, and days since last logon sorted by most stale first.


Get-ADUserDetail

Retrieves detailed Active Directory user account information.

Queries Active Directory for comprehensive user account details including account status, password information, group membership count, and organizational unit. Supports pipeline input for processing multiple user identities at once.

Syntax

Get-ADUserDetail -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADUserDetail -Identity 'jdoe'

Retrieves detailed information for the user with SamAccountName jdoe.

Get-ADUserDetail -Identity 'jdoe' -Server 'dc01.contoso.com'

Retrieves user details from a specific domain controller.

'jdoe', 'asmith' | Get-ADUserDetail

Retrieves details for multiple users via pipeline input.

Output: PSWinOps.ADUserDetail

Returns a custom object with comprehensive user account properties including account status, password state, group membership count, and organizational unit.


Get-ADUserGroupInventory

Retrieves all group memberships including nested groups for AD users.

For one or more Active Directory users, retrieves all group memberships including nested (recursive) groups using LDAP recursive member resolution. Returns one object per user-group combination for audit and review purposes. Users can be specified by identity or discovered from an organizational unit.

Syntax

Get-ADUserGroupInventory [-Identity <string[]>] [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Get-ADUserGroupInventory -Identity 'jdoe'

Retrieves all direct and nested group memberships for user jdoe.

Get-ADUserGroupInventory -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'

Retrieves group memberships for two users targeting a specific domain controller.

'jdoe', 'asmith' | Get-ADUserGroupInventory -Credential (Get-Credential)

Retrieves group memberships via pipeline input with alternate credentials.

Output: PSWinOps.ADUserGroupInventory

Returns objects with UserName, DisplayName, GroupName, GroupDN, GroupScope, GroupCategory, and Timestamp properties.


Get-ADUserInventory

Retrieves Active Directory user accounts for inventory and audit review.

Lists Active Directory user accounts with key audit properties including login history, password status, lockout state, and organizational unit placement. By default only enabled accounts are returned unless the -IncludeDisabled switch is specified.

Syntax

Get-ADUserInventory [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>] [-IncludeDisabled]

Examples

Get-ADUserInventory

Retrieves all enabled AD user accounts from the current domain using default credentials.

Get-ADUserInventory -SearchBase 'OU=Users,DC=contoso,DC=com' -Server 'DC01.contoso.com'

Retrieves enabled AD user accounts from a specific OU on a specific domain controller.

Get-ADUserInventory -IncludeDisabled -Credential (Get-Credential)

Retrieves all AD user accounts including disabled ones using alternate credentials.

Output: PSWinOps.ADUserInventory

Returns objects with SamAccountName, UserPrincipalName, DisplayName, Enabled, LastLogonDate, LockedOut, PasswordLastSet, PasswordExpired, PasswordNeverExpires, CannotChangePassword, OrganizationalUnit, and Timestamp properties.


Invoke-ADSecurityAudit

Performs a comprehensive Active Directory security audit inspired by PingCastle.

Runs 32 security checks across four categories (Privileged Accounts, Anomalies, Configuration, and Stale Objects) against the current or specified AD domain. Each finding is returned as an individual object with category, severity, affected account, detail, and remediation guidance. No external dependencies are required; all checks use standard ActiveDirectory module cmdlets.

Syntax

Invoke-ADSecurityAudit [-Category <string[]>] [-StaleThresholdDays <int>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Invoke-ADSecurityAudit

Runs all 32 checks against the current domain and returns all findings.

Invoke-ADSecurityAudit -Category 'PrivilegedAccounts' -Server 'dc01.contoso.com'

Audits only privileged account checks against a specific domain controller.

Invoke-ADSecurityAudit | Where-Object Severity -eq 'Critical' | Export-Csv -Path 'critical-findings.csv'

Exports all critical findings to CSV for remediation tracking.

Output: PSWinOps.ADSecurityFinding

Returns one object per finding with Category, CheckId, Check, Severity, SamAccountName, ObjectType, Detail, and Recommendation properties.


Reset-ADUserPassword

Resets the password of one or more Active Directory user accounts.

Resets Active Directory user account passwords using Set-ADAccountPassword with the -Reset parameter. Optionally forces the user to change password at next logon. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.

Syntax

Reset-ADUserPassword -Identity <string[]> -NewPassword <System.Security.SecureString> [-MustChangePasswordAtLogon] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Reset-ADUserPassword -Identity 'jdoe' -NewPassword (Read-Host -AsSecureString 'New password')

Resets the password for user jdoe with a prompted secure password.

Reset-ADUserPassword -Identity 'jdoe' -NewPassword $securePass -MustChangePasswordAtLogon -Server 'DC01'

Resets password and forces change at next logon, targeting a specific DC.

'jdoe', 'asmith' | Reset-ADUserPassword -NewPassword $securePass -Credential (Get-Credential)

Resets passwords for multiple users via pipeline with alternate credentials.

Output: PSWinOps.ADPasswordResetResult

Returns objects with Identity, UserName, Success, MustChangeAtLogon, Message, and Timestamp properties.


Search-ADObject

Searches Active Directory objects using a raw LDAP filter.

Performs a flexible Active Directory search using a raw LDAP filter string. Supports configurable search base, scope, additional properties, and result set size limiting for controlled queries against large directories.

Syntax

Search-ADObject -LDAPFilter <string> [-SearchBase <string>] [-SearchScope <string>] [-Properties <string[]>] [-ResultSetSize <int>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Search-ADObject -LDAPFilter '(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2))'

Finds all disabled user accounts in the domain.

Search-ADObject -LDAPFilter '(&(objectClass=computer)(operatingSystem=*Server 2022*))' -Properties 'OperatingSystem', 'LastLogonDate' -Server 'dc01.contoso.com'

Finds computers running Server 2022 with additional properties from a specific DC.

Search-ADObject -LDAPFilter '(objectClass=group)' -SearchBase 'OU=Security Groups,DC=contoso,DC=com' -ResultSetSize 50

Searches for groups within a specific OU with a result limit of 50.

Output: PSWinOps.ADSearchResult

Returns custom objects with Name, ObjectClass, DistinguishedName, any requested additional properties, and a Timestamp field.


Unlock-ADUserAccount

Unlocks one or more Active Directory user accounts.

Unlocks locked Active Directory user accounts using the Unlock-ADAccount cmdlet. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.

Syntax

Unlock-ADUserAccount -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]

Examples

Unlock-ADUserAccount -Identity 'jdoe'

Unlocks the user account jdoe in the current domain.

Unlock-ADUserAccount -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'

Unlocks two user accounts targeting a specific domain controller.

'jdoe', 'asmith' | Unlock-ADUserAccount -Credential (Get-Credential)

Unlocks user accounts via pipeline input with alternate credentials.

Output: PSWinOps.ADAccountUnlockResult

Returns objects with Identity, UserName, Success, Message, and Timestamp properties.


PSWinOps Wiki

Home

Domains

Clone this wiki locally