Blog
  • Blogs home
  • ManageEngine Products
  • About us
  • Subscribe
ManageEngineADManager Plus
  • Overview
  • Features
  • Pricing
  • Download

How to Find Active Directory Accounts with Expiring Passwords

ADManager Plus | June 5, 2014 | 2 min read

Every organization has one or more user accounts —  used for services, applications, development, kiosks, or even standard employees — which need to ensure the password changes or the account will lock. For these user accounts (which might not be used by a human), if the password is not changed by the time the password expiration hits, the account will fail to logon and prevent the associated use of the account.

The property that controls the password expiration is part of the user account object. However, that value is not displayed in any GUI related to the Active Directory Users and Computers (ADUC). It is also not a default search option if you were to try and use the Saved Queries option in ADUC. You could write a script, use PowerShell, or some LDAP query to find these objects. Or you could just use a tool that has a pre-built query and report around it!

For error-free Password Management and excellent Active Directory Administration. Try ADManager Plus

ManageEngine’s ADManager Plus is built for just these types of requests. Figure 1 shows you what the pre-built query looks like and what options you have in narrowing down your search.

soon-to-expire-AD-user-passwords

Figure 1. Searching for user accounts that have soon-to-expire passwords.

First, you can see that you can narrow down your search by selecting just the OU or OUs where you want to search for users. Next, you can change the range of days for which the password will expire.

Finally, once you get a listing of user accounts that have soon-to-expire passwords, you can change the passwords for them directly in the report.

Sure, creating a script that can find the users is a pretty easy task. However, working with the users after you get the list back from the script is not so  easy. ADManager is simple, easy, and efficient for tasks like these.

Tags : active directory articles / Active Directory Auditing / Active Directory blog / Active Directory Management / active directory password expiry script / active directory password reset / active directory password reset tool / active directory security / active directory solutions / active directory tips / active directory tips and tricks / active directory training / Active Directory tutorial / check when active directory account passwords expire / check when AD password expires / Derek Melber / Derek Melber Group Policy / derek melber group policy mvp / derek melber windows security articles / finding soon to expire Active Directory passwords / Group policy / MCSE / MVP / reset expired password active directory / reset expired windows password / script to find expiring active directory passwords / script to find expiring windows passwords / script to find soon to expire windows passwords / script to track password expiration / soon to expire Active Directory passwords / tracking password expiration in active directory / windows security
Derek Melber

Cancel reply

Related Posts

Active Directory security: Exploiting certificate services

Active Directory (AD) is crucial for an organization’s identity and access management strategy, but its complex architecture is also a prime zone for overlooked vulnerabilities....

AD360 2 min read Read

©   Zoho Corporation Pvt. Ltd. All Rights Reserved.