-
Notifications
You must be signed in to change notification settings - Fork 0
Active Directory
User, group, and computer account management, auditing, replication, and site topology for Active Directory Domain Services. Requires the ActiveDirectory RSAT module.
22 function(s) in Public/activedirectory/.
-
Disable-ADUserAccount— Disables one or more Active Directory user accounts -
Enable-ADUserAccount— Enables one or more disabled Active Directory user accounts -
Get-ADComputerDetail— Retrieves detailed Active Directory computer account information -
Get-ADComputerInventory— Retrieves Active Directory computer accounts with key audit properties -
Get-ADDomainInfo— Retrieves a comprehensive summary of an Active Directory domain -
Get-ADGroupInventory— Inventories Active Directory groups with member count and metadata -
Get-ADGroupMembership— Retrieves members of an Active Directory group -
Get-ADLockedAccount— Finds all currently locked Active Directory user accounts -
Get-ADNestedGroupMembership— Retrieves all nested Active Directory group memberships for a principal -
Get-ADPasswordStatus— Audits password status of all Active Directory user accounts -
Get-ADPrivilegedAccount— Lists members of privileged Active Directory groups -
Get-ADReplicationStatus— Retrieves Active Directory replication status for one or more domain controllers -
Get-ADSiteTopology— Retrieves Active Directory site topology including sites, subnets, and site links -
Get-ADStaleAccount— Finds Active Directory accounts that have been inactive for a specified number of days -
Get-ADStaleComputer— Finds Active Directory computer accounts that have been inactive for a specified number of days -
Get-ADUserDetail— Retrieves detailed Active Directory user account information -
Get-ADUserGroupInventory— Retrieves all group memberships including nested groups for AD users -
Get-ADUserInventory— Retrieves Active Directory user accounts for inventory and audit review -
Invoke-ADSecurityAudit— Performs a comprehensive Active Directory security audit inspired by PingCastle -
Reset-ADUserPassword— Resets the password of one or more Active Directory user accounts -
Search-ADObject— Searches Active Directory objects using a raw LDAP filter -
Unlock-ADUserAccount— Unlocks one or more Active Directory user accounts
Disables one or more Active Directory user accounts.
Disables Active Directory user accounts using the Disable-ADAccount cmdlet. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.
Syntax
Disable-ADUserAccount -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Disable-ADUserAccount -Identity 'jdoe'Disables the user account jdoe in the current domain.
Disable-ADUserAccount -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'Disables two user accounts targeting a specific domain controller.
'jdoe', 'asmith' | Disable-ADUserAccount -Credential (Get-Credential)Disables user accounts via pipeline input with alternate credentials.
Output: PSWinOps.ADAccountDisableResult
Returns objects with Identity, UserName, Success, Message, and Timestamp properties.
Enables one or more disabled Active Directory user accounts.
Enables disabled Active Directory user accounts using the Enable-ADAccount cmdlet. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.
Syntax
Enable-ADUserAccount -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Enable-ADUserAccount -Identity 'jdoe'Enables the disabled user account jdoe in the current domain.
Enable-ADUserAccount -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'Enables two user accounts targeting a specific domain controller.
'jdoe', 'asmith' | Enable-ADUserAccount -Credential (Get-Credential)Enables user accounts via pipeline input with alternate credentials.
Output: PSWinOps.ADAccountEnableResult
Returns objects with Identity, UserName, Success, Message, and Timestamp properties.
Retrieves detailed Active Directory computer account information.
Queries Active Directory for comprehensive computer account details including operating system, network information, group membership count, and organizational unit. Supports pipeline input for processing multiple computer identities at once.
Syntax
Get-ADComputerDetail -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADComputerDetail -Identity 'SRV01'Retrieves detailed information for the computer account SRV01.
Get-ADComputerDetail -Identity 'SRV01' -Server 'dc01.contoso.com'Retrieves computer details from a specific domain controller.
'SRV01', 'SRV02' | Get-ADComputerDetailRetrieves details for multiple computers via pipeline input.
Output: PSWinOps.ADComputerDetail
Returns a custom object with comprehensive computer account properties including operating system, network details, group membership count, and organizational unit.
Retrieves Active Directory computer accounts with key audit properties.
Lists all Active Directory computer accounts with inventory and audit properties. Returns a typed PSWinOps.ADComputerInventory object per computer with logon, password, OS, and lifecycle metadata for review and compliance reporting.
Syntax
Get-ADComputerInventory [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>] [-IncludeDisabled]Examples
Get-ADComputerInventoryReturns all enabled computer accounts from the current domain.
Get-ADComputerInventory -SearchBase 'OU=Servers,DC=corp,DC=local' -Server 'DC01'Returns enabled computer accounts from the Servers OU querying DC01.
Get-ADComputerInventory -IncludeDisabled -Credential (Get-Credential)Returns all computer accounts including disabled ones using explicit credentials.
Output: PSWinOps.ADComputerInventory
Returns objects with Name, SamAccountName, Enabled, LastLogonDate, LockedOut, PasswordExpired, PasswordLastSet, WhenChanged, WhenCreated, OperatingSystem, OrganizationalUnit, and Timestamp properties.
Retrieves a comprehensive summary of an Active Directory domain.
Returns the identity card of an Active Directory domain including functional levels, FSMO role holders, domain controller inventory, site topology, object counts (users, computers, groups, OUs), and password policy. Designed as the first command to run when discovering an unfamiliar domain. All data is gathered from a single domain context using standard AD cmdlets.
Syntax
Get-ADDomainInfo [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADDomainInfoReturns a full summary of the current domain.
Get-ADDomainInfo -Server 'dc01.contoso.com'Returns domain information from a specific domain controller.
Get-ADDomainInfo -Server 'child.contoso.com' -Credential (Get-Credential)Returns domain information for a child domain using alternate credentials.
Output: PSWinOps.ADDomainInfo
Returns a single object with domain identity, functional levels, FSMO holders, DC list, site names, object counts, and default password policy.
Inventories Active Directory groups with member count and metadata.
Retrieves all Active Directory groups and returns audit-ready objects including member count, scope, category, and organizational unit path extracted from the distinguished name. By default only groups with at least one member are returned.
Syntax
Get-ADGroupInventory [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>] [-IncludeEmpty]Examples
Get-ADGroupInventoryReturns all non-empty AD groups in the current domain sorted by name.
Get-ADGroupInventory -SearchBase 'OU=Groups,DC=corp,DC=local' -Server 'DC01'Returns non-empty groups from a specific OU targeting a specific domain controller.
Get-ADGroupInventory -IncludeEmpty -Credential (Get-Credential)Returns all groups including empty ones using alternate credentials.
Output: PSWinOps.ADGroupInventory
Returns objects with Name, SamAccountName, GroupScope, GroupCategory, MemberCount, Description, OrganizationalUnit, and Timestamp properties.
Retrieves members of an Active Directory group.
Queries Active Directory for group membership details with optional recursive enumeration. When the Recursive switch is used, both direct and nested members are returned with an IsDirect flag indicating membership type.
Syntax
Get-ADGroupMembership -Identity <string[]> [-Recursive] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADGroupMembership -Identity 'Domain Admins'Retrieves direct members of the Domain Admins group.
Get-ADGroupMembership -Identity 'Domain Admins' -Recursive -Server 'dc01.contoso.com'Retrieves all nested members from a specific domain controller with direct/nested flags.
'Domain Admins', 'Enterprise Admins' | Get-ADGroupMembershipRetrieves direct members of multiple groups via pipeline input.
Output: PSWinOps.ADGroupMember
Returns custom objects with group name, member details, object class, and IsDirect flag sorted by ObjectClass then MemberName.
Finds all currently locked Active Directory user accounts.
Searches Active Directory for user accounts that are currently locked out. Returns detailed lockout information including lockout time, bad logon count, and last bad password attempt. Results are sorted by most recent lockout first.
Syntax
Get-ADLockedAccount [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADLockedAccountFinds all locked accounts in the domain.
Get-ADLockedAccount -Server 'dc01.contoso.com'Finds all locked accounts from a specific domain controller.
Get-ADLockedAccount -SearchBase 'OU=Users,DC=contoso,DC=com'Finds locked accounts within a specific OU.
Output: PSWinOps.ADLockedAccount
Returns objects with account identity, lockout time, bad password attempt details, sorted by most recent lockout first.
Retrieves all nested Active Directory group memberships for a principal.
Resolves all direct and nested group memberships for one or more AD principals using a single LDAP query with the LDAP_MATCHING_RULE_IN_CHAIN OID (1.2.840.113556.1.4.1941). This approach is significantly faster than recursive Get-ADPrincipalGroupMembership calls because the domain controller performs the recursion server-side in a single round-trip. Each returned object indicates whether the membership is direct or inherited (nested).
Syntax
Get-ADNestedGroupMembership -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADNestedGroupMembership -Identity 'jdoe'Retrieves all direct and nested group memberships for user jdoe using the default DC.
Get-ADNestedGroupMembership -Identity 'jdoe' -Server 'DC01.contoso.com'Retrieves all group memberships for user jdoe targeting a specific domain controller.
'jdoe', 'svc-app01' | Get-ADNestedGroupMembershipRetrieves nested group memberships for multiple principals via pipeline input.
Output: PSWinOps.ADNestedGroupMembership
Returns one object per group membership with Identity, GroupName, GroupDN, GroupCategory, GroupScope, Description, IsDirect, and Timestamp properties.
Audits password status of all Active Directory user accounts.
Returns the password status of all enabled Active Directory user accounts including password age, expiry date, applied password policy (Fine-Grained Password Policy or Default Domain Policy), and problem flags. By default all enabled accounts are returned. Use the -ProblemsOnly switch to filter to accounts with password concerns only (expired, never expires, or must change at next logon). Use the -ExpiredOnly switch to return only accounts whose password has actually expired.
Syntax
Get-ADPasswordStatus [-ProblemsOnly] [-ExpiredOnly] [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADPasswordStatusReturns password status for all enabled user accounts in the domain.
Get-ADPasswordStatus -ProblemsOnly -Server 'dc01.contoso.com'Returns only accounts with password concerns from a specific domain controller.
Get-ADPasswordStatus -ExpiredOnlyReturns only accounts whose password has actually expired.
Get-ADPasswordStatus -SearchBase 'OU=Users,DC=contoso,DC=com' | Where-Object DaysUntilExpiry -lt 14Returns accounts in a specific OU whose passwords expire within 14 days.
Output: PSWinOps.ADPasswordStatus
Returns objects with account identity, password state flags, applied password policy name, password age, expiry date, and days until expiry.
Lists members of privileged Active Directory groups.
Enumerates members of high-privilege AD groups such as Domain Admins, Enterprise Admins, and Schema Admins. Supports custom group lists and optional recursive enumeration. For user members, additional properties like Enabled status and last logon are retrieved.
Syntax
Get-ADPrivilegedAccount [-GroupName <string[]>] [-DirectOnly] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADPrivilegedAccountLists members of all default privileged groups.
Get-ADPrivilegedAccount -GroupName 'Domain Admins', 'Enterprise Admins' -Server 'dc01.contoso.com'Audits specific groups from a targeted domain controller.
Get-ADPrivilegedAccount -DirectOnly -GroupName 'Domain Admins'Lists only direct members of Domain Admins without recursing nested groups.
Output: PSWinOps.ADPrivilegedAccount
Returns objects with group name, member identity, object class, enabled status, and last logon date sorted by group name then member name.
Retrieves Active Directory replication status for one or more domain controllers.
Queries replication partner metadata and failure information for Active Directory domain controllers. When no Server is specified, automatically discovers all DCs in the current domain via Get-ADDomainController. Returns one object per DC/partner/ partition combination with health status derived from replication result codes and consecutive failure counts.
Syntax
Get-ADReplicationStatus [-Server <string[]>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADReplicationStatusDiscovers all domain controllers and returns replication status for each.
Get-ADReplicationStatus -Server 'DC01.contoso.com'Returns replication status for a specific domain controller.
'DC01', 'DC02' | Get-ADReplicationStatus -Credential (Get-Credential)Returns replication status for multiple DCs via pipeline with alternate credentials.
Output: PSWinOps.ADReplicationStatus
Returns objects with Server, Partner, Partition, LastAttempt, LastSuccess, LastResult, ConsecutiveFailures, Status, and Timestamp properties.
Retrieves Active Directory site topology including sites, subnets, and site links.
Returns one object per AD site with associated subnets, site links, replication cost/interval, and domain controllers hosted in each site. Provides a complete picture of the AD physical topology for capacity planning, replication analysis, and subnet auditing.
Syntax
Get-ADSiteTopology [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADSiteTopologyReturns topology information for all sites in the current forest.
Get-ADSiteTopology -Server 'dc01.contoso.com'Returns site topology from a specific domain controller.
Get-ADSiteTopology -Credential (Get-Credential) | Where-Object SubnetCount -eq 0Finds sites with no subnets assigned, which may indicate configuration issues.
Output: PSWinOps.ADSiteTopology
Returns one object per site with site name, description, subnets, site links, replication details, and domain controller list.
Finds Active Directory accounts that have been inactive for a specified number of days.
Scans Active Directory for user and/or computer accounts that have not logged in within the specified number of days. Accounts that have never logged in are included by default. Results are sorted by days since last logon in descending order.
Syntax
Get-ADStaleAccount [-DaysInactive <int>] [-AccountType <string>] [-SearchBase <string>] [-IncludeDisabled] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADStaleAccountFinds all enabled user and computer accounts inactive for more than 90 days (default).
Get-ADStaleAccount -DaysInactive 180 -AccountType User -Server 'dc01.contoso.com'Finds stale user accounts only from a specific domain controller.
Get-ADStaleAccount -DaysInactive 60 -IncludeDisabled -SearchBase 'OU=Workstations,DC=contoso,DC=com'Finds stale accounts including disabled ones within a specific OU.
Output: PSWinOps.ADStaleAccount
Returns objects with account identity, type, last logon information, and days since last logon sorted by most stale first.
Finds Active Directory computer accounts that have been inactive for a specified number of days.
Scans Active Directory for computer accounts that have not authenticated within the specified number of days. Computers that have never logged in are included by default. Returns operating system details alongside staleness information to help identify obsolete machines. Results are sorted by days since last logon in descending order.
Syntax
Get-ADStaleComputer [-DaysInactive <int>] [-SearchBase <string>] [-IncludeDisabled] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADStaleComputerFinds all enabled computer accounts inactive for more than 90 days (default).
Get-ADStaleComputer -DaysInactive 180 -Server 'dc01.contoso.com'Finds stale computers from a specific domain controller using a 180-day threshold.
Get-ADStaleComputer -DaysInactive 60 -IncludeDisabled -SearchBase 'OU=Workstations,DC=contoso,DC=com'Finds stale computers including disabled ones within a specific OU.
Output: PSWinOps.ADStaleComputer
Returns objects with computer identity, operating system information, last logon date, and days since last logon sorted by most stale first.
Retrieves detailed Active Directory user account information.
Queries Active Directory for comprehensive user account details including account status, password information, group membership count, and organizational unit. Supports pipeline input for processing multiple user identities at once.
Syntax
Get-ADUserDetail -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADUserDetail -Identity 'jdoe'Retrieves detailed information for the user with SamAccountName jdoe.
Get-ADUserDetail -Identity 'jdoe' -Server 'dc01.contoso.com'Retrieves user details from a specific domain controller.
'jdoe', 'asmith' | Get-ADUserDetailRetrieves details for multiple users via pipeline input.
Output: PSWinOps.ADUserDetail
Returns a custom object with comprehensive user account properties including account status, password state, group membership count, and organizational unit.
Retrieves all group memberships including nested groups for AD users.
For one or more Active Directory users, retrieves all group memberships including nested (recursive) groups using LDAP recursive member resolution. Returns one object per user-group combination for audit and review purposes. Users can be specified by identity or discovered from an organizational unit.
Syntax
Get-ADUserGroupInventory [-Identity <string[]>] [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Get-ADUserGroupInventory -Identity 'jdoe'Retrieves all direct and nested group memberships for user jdoe.
Get-ADUserGroupInventory -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'Retrieves group memberships for two users targeting a specific domain controller.
'jdoe', 'asmith' | Get-ADUserGroupInventory -Credential (Get-Credential)Retrieves group memberships via pipeline input with alternate credentials.
Output: PSWinOps.ADUserGroupInventory
Returns objects with UserName, DisplayName, GroupName, GroupDN, GroupScope, GroupCategory, and Timestamp properties.
Retrieves Active Directory user accounts for inventory and audit review.
Lists Active Directory user accounts with key audit properties including login history, password status, lockout state, and organizational unit placement. By default only enabled accounts are returned unless the -IncludeDisabled switch is specified.
Syntax
Get-ADUserInventory [-SearchBase <string>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>] [-IncludeDisabled]Examples
Get-ADUserInventoryRetrieves all enabled AD user accounts from the current domain using default credentials.
Get-ADUserInventory -SearchBase 'OU=Users,DC=contoso,DC=com' -Server 'DC01.contoso.com'Retrieves enabled AD user accounts from a specific OU on a specific domain controller.
Get-ADUserInventory -IncludeDisabled -Credential (Get-Credential)Retrieves all AD user accounts including disabled ones using alternate credentials.
Output: PSWinOps.ADUserInventory
Returns objects with SamAccountName, UserPrincipalName, DisplayName, Enabled, LastLogonDate, LockedOut, PasswordLastSet, PasswordExpired, PasswordNeverExpires, CannotChangePassword, OrganizationalUnit, and Timestamp properties.
Performs a comprehensive Active Directory security audit inspired by PingCastle.
Runs 32 security checks across four categories (Privileged Accounts, Anomalies, Configuration, and Stale Objects) against the current or specified AD domain. Each finding is returned as an individual object with category, severity, affected account, detail, and remediation guidance. No external dependencies are required; all checks use standard ActiveDirectory module cmdlets.
Syntax
Invoke-ADSecurityAudit [-Category <string[]>] [-StaleThresholdDays <int>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Invoke-ADSecurityAuditRuns all 32 checks against the current domain and returns all findings.
Invoke-ADSecurityAudit -Category 'PrivilegedAccounts' -Server 'dc01.contoso.com'Audits only privileged account checks against a specific domain controller.
Invoke-ADSecurityAudit | Where-Object Severity -eq 'Critical' | Export-Csv -Path 'critical-findings.csv'Exports all critical findings to CSV for remediation tracking.
Output: PSWinOps.ADSecurityFinding
Returns one object per finding with Category, CheckId, Check, Severity, SamAccountName, ObjectType, Detail, and Recommendation properties.
Resets the password of one or more Active Directory user accounts.
Resets Active Directory user account passwords using Set-ADAccountPassword with the -Reset parameter. Optionally forces the user to change password at next logon. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.
Syntax
Reset-ADUserPassword -Identity <string[]> -NewPassword <System.Security.SecureString> [-MustChangePasswordAtLogon] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Reset-ADUserPassword -Identity 'jdoe' -NewPassword (Read-Host -AsSecureString 'New password')Resets the password for user jdoe with a prompted secure password.
Reset-ADUserPassword -Identity 'jdoe' -NewPassword $securePass -MustChangePasswordAtLogon -Server 'DC01'Resets password and forces change at next logon, targeting a specific DC.
'jdoe', 'asmith' | Reset-ADUserPassword -NewPassword $securePass -Credential (Get-Credential)Resets passwords for multiple users via pipeline with alternate credentials.
Output: PSWinOps.ADPasswordResetResult
Returns objects with Identity, UserName, Success, MustChangeAtLogon, Message, and Timestamp properties.
Searches Active Directory objects using a raw LDAP filter.
Performs a flexible Active Directory search using a raw LDAP filter string. Supports configurable search base, scope, additional properties, and result set size limiting for controlled queries against large directories.
Syntax
Search-ADObject -LDAPFilter <string> [-SearchBase <string>] [-SearchScope <string>] [-Properties <string[]>] [-ResultSetSize <int>] [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Search-ADObject -LDAPFilter '(&(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2))'Finds all disabled user accounts in the domain.
Search-ADObject -LDAPFilter '(&(objectClass=computer)(operatingSystem=*Server 2022*))' -Properties 'OperatingSystem', 'LastLogonDate' -Server 'dc01.contoso.com'Finds computers running Server 2022 with additional properties from a specific DC.
Search-ADObject -LDAPFilter '(objectClass=group)' -SearchBase 'OU=Security Groups,DC=contoso,DC=com' -ResultSetSize 50Searches for groups within a specific OU with a result limit of 50.
Output: PSWinOps.ADSearchResult
Returns custom objects with Name, ObjectClass, DistinguishedName, any requested additional properties, and a Timestamp field.
Unlocks one or more Active Directory user accounts.
Unlocks locked Active Directory user accounts using the Unlock-ADAccount cmdlet. Returns a result object per user indicating success or failure for audit logging. Supports ShouldProcess for WhatIf and Confirm scenarios.
Syntax
Unlock-ADUserAccount -Identity <string[]> [-Server <string>] [-Credential <System.Management.Automation.PSCredential>]Examples
Unlock-ADUserAccount -Identity 'jdoe'Unlocks the user account jdoe in the current domain.
Unlock-ADUserAccount -Identity 'jdoe', 'asmith' -Server 'DC01.contoso.com'Unlocks two user accounts targeting a specific domain controller.
'jdoe', 'asmith' | Unlock-ADUserAccount -Credential (Get-Credential)Unlocks user accounts via pipeline input with alternate credentials.
Output: PSWinOps.ADAccountUnlockResult
Returns objects with Identity, UserName, Success, Message, and Timestamp properties.
Domains
- Active Directory (22)
- Certificate (1)
- Event Log (9)
- Health Check (16)
- IIS (9)
- Network (26)
- NTP (5)
- Proxy (4)
- RDP (6)
- Security (1)
- System (20)
- Utils (4)
- VSS (Shadow Copy) (6)
- Windows Update (10)