When an employee leaves our organizations for any reason, currently we disable their AD account but do not immediately delete it. However, the problem with this is that these users still show up in the Global Address List.
I'm sure there is a PowerShell script to remove them but I would like to make things more streamlined.
I'm hoping somebody here might be able to provide a better way to go about disabling users which will automatically remove them from the GAL in the process.
So far I can think of two potential solutions.
-
Create a script that runs a PS script every hour that will remove disabled users from the GAL.
-
Use a PS command that will simultaneously disable a user and remove them from the GAL.
Option 2 is likely the better option so if somebody could assist with that, I would greatly appreciate it.
Thanks in advance.
Best Answer
No need to re-invent the wheel, found this elegant solution over at petri.co.il:
Save it as
Disable-User.ps1
and run.\Disable-User.ps1 SAMaccountname disable