I am struggling to find a decent way to do this. For one reason or another (not important, it is what it is) we have a rather a lot of users who are disabled but are still a member of all of their pre-disable groups. This is causing a few issues such as distribution list failures, difficulty enumerating ACL's etc.
Does anyone know of an easy way to bulk remove groups from users that are disabled? For ease, they all exist in one container now so if its something that can be done on container level, that's useful.
Also, I know we could delete the accounts, but for auditing and cross linking with our HR system, that is not possible.
Best Answer
This sample batch file will do what you're asking. You'll need to edit the
dsquery
command to use your specific StartNode OU -- TheOU=SomeOU,DC=example,DC=com
bit: