# Request Help - Inactive ADUser Query and Manipulation Encountering Issues...

**URL:** https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556
**Category:** PowerShell Help
**Created:** [June 1, 2016, 10:29am UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556 "2016-06-01T10:29:22Z")
**Posts on this page:** 16
**Page:** 1

<div class="post-metadata">

### Author: ![rsmith7712](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rsmith7712](https://forums.powershell.org/u/rsmith7712)
#### Post date: [June 1, 2016, 10:29am UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/1 "2016-06-01T10:29:22Z")

</div>

I’m trying (initially) to query ADUsers in a specific OU; identify those that are 90-days inactive; document their group memberships; make a note in the Description field that the account is being Disabled as of x-date; Disable identified accounts; and move disabled accounts to a “Parking” OU.

I’ve made notes in the Gist as well, but would appreciate any help getting the Group Membership piece working (pretty please)

[https://gist.github.com/rsmith7712/fdfe025d989508102044fdbbf5d3b9a8](https://gist.github.com/rsmith7712/fdfe025d989508102044fdbbf5d3b9a8)

---

<div class="post-metadata">

### Author: ![donj](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/donj/32/137_2.png) [@donj](https://forums.powershell.org/u/donj)
#### Post date: [June 1, 2016, 2:48pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/2 "2016-06-01T14:48:53Z")

</div>

Can you be more specific about what the group membership piece should be doing, and isn’t?

---

<div class="post-metadata">

### Author: ![rsmith7712](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rsmith7712](https://forums.powershell.org/u/rsmith7712)
#### Post date: [June 1, 2016, 3:33pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/3 "2016-06-01T15:33:36Z")

</div>

Desired Result:  
The ADUsers identified inactive have their Group Memberships added in the last column, before each user's Description is updated with "Disabled as of x-date", the account is disabled, and then moved to another OU.

Here is the output in the CSV:

Name User Account Pswd Exp Pswd Nvr Exp When Created Password Last Set Last Logon Date Group  
MIT-Mickey Mouse Mmouse TRUE FALSE 4/17/2014 19:27 7/17/2014 18:06 7/10/2014 10:23

Error message:

Get-ADGroup : Cannot validate argument on parameter ‘Identity’. The argument is null. Supply a non-null argument and try the command again.  
At C:\_E\_\scripts\powerShell\helpRequested\help\_ZombieAcct\_90dayRpt\_n\_Move.ps1:62 char:37

- 

```
Groups = ($_.memberof | Get-ADGroup &lt;&lt;&lt;&lt; | Select -ExpandProperty Name) -join &quot;,&quot;

```

  - CategoryInfo : InvalidData: (🙂 [Get-ADGroup], ParameterBindingValidationException
  - FullyQualifiedErrorId : ParameterArgumentValidationError,Microsoft.ActiveDirectory.Management.Commands.GetADGroup

---

<div class="post-metadata">

### Author: ![donj](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/donj/32/137_2.png) [@donj](https://forums.powershell.org/u/donj)
#### Post date: [June 1, 2016, 4:51pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/4 "2016-06-01T16:51:38Z")

</div>

Get-ADGroup is complaining that it’s being given a null value for the -Identity parameter. So, whatever you’re piping in is either (A) empty or (B) unacceptable to the command. I will note that memberOf is a collection of objects, not just a single group; Get-ADGroup doesn’t like being given a collection. -Identity is only rigged up to accept a single value.

And that’s an appalling way to create a CSV :).

```
$objects = @()
$output = @{'Name'='whatever' ; 'Password'='this' ; 'Something' = 'Else'}
$objects += (New-Object -Type PSObject -Prop $output)
...
$objects | Export-CSV
```

Would be a lot closer. Still far from ideal. But manually forming a CSV by concatenating strings is making me cry.

---

<div class="post-metadata">

### Author: ![rsmith7712](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rsmith7712](https://forums.powershell.org/u/rsmith7712)
#### Post date: [June 3, 2016, 2:57pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/5 "2016-06-03T14:57:03Z")

</div>

Don… Any Thoughts?

Here’s the (near) final script,

Issue still having:

- Collecting ADUser Group Memberships is still for everyone in the specified $SearchBase OU, instead of being able to JUST query those ADUser accounts who meet the $xDays variable.

[https://gist.github.com/rsmith7712/fdfe025d989508102044fdbbf5d3b9a8](https://gist.github.com/rsmith7712/fdfe025d989508102044fdbbf5d3b9a8)

---

<div class="post-metadata">

### Author: ![jack-neff](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@jack-neff](https://forums.powershell.org/u/jack-neff)
#### Post date: [June 3, 2016, 9:28pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/6 "2016-06-03T21:28:26Z")

</div>

You’re not applying a filter to the Get-ADUser command on line 56. You do it on line 64, so…? But why query AD twice for the same info? C:\ADUser\_GroupMembership\_Rpt.csv will contain Names and Groups but so does your log file?

---

<div class="post-metadata">

### Author: ![rsmith7712](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rsmith7712](https://forums.powershell.org/u/rsmith7712)
#### Post date: [June 5, 2016, 2:15pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/7 "2016-06-05T14:15:35Z")

</div>

Jeff - Lines 56-61 were put in to capture the Group Memberships because the query on the end of Line 73 fails to capture the info and put it with the rest of the requested data in the CSV. I would love to simplify this to generate a single CSV with all the requested data, but so far I just haven’t figured out how.

Another issue, with the 56-61 query is that it pulls data on all the users in the specified OU instead of those that meet the requirements in the $xDays variable - Yet another reason I would love to find a way to get group memberships collection working through the main query.

Any ideas?

---

<div class="post-metadata">

### Author: ![donj](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/donj/32/137_2.png) [@donj](https://forums.powershell.org/u/donj)
#### Post date: [June 5, 2016, 2:36pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/8 "2016-06-05T14:36:48Z")

</div>

“Another issue, with the 56-61 query is that it pulls data on all the users in the specified OU instead of those that meet the requirements in the $xDays variable – Yet another reason I would love to find a way to get group memberships collection working through the main query.”

Here’s what I’d do to troubleshoot this.

First, I’d check and see what was in $xDays. It looks from your script like it’s a [datetime] object. Is that what the LastLogonDate property expects? Just running $xDays from the console doesn’t count, here, because PowerShell’s going to render it to a string for console display. But what is the shell passing to Active Directory?

I’d spend some time querying users from the command-line, using different date/time values, to verify what’s actually happening. I mean, if it’s pulling all users, then obviously your query criteria isn’t working, so I’d spend some time interactively running the command and refining it.

---

<div class="post-metadata">

### Author: ![rsmith7712](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rsmith7712](https://forums.powershell.org/u/rsmith7712)
#### Post date: [June 6, 2016, 10:15am UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/9 "2016-06-06T10:15:31Z")

</div>

Don,

So following your suggestion I spent yesterday doing searches in different formats to see what they returned. It eventually led me to an article where I replaced:

old - Ln:58 -Filter \*

new - Ln:58 -Filter {LastLogonDate -like $xDays -and Enabled -eq “true”}

Now, here’s what I don’t get… The CSV that Lines 58-63 generate is now empty (file created but no contents), whereas the end ADGroup query on Line 76 now appears to be working because the CSV that it generates now had the Group Memberships for only the ADUsers that meet the time requirement. I’m not complaining - this is exactly the result I have wanted but I would like to know WHY.

I updated the Gist and it can be referenced from an earlier post (instead of posting it again) - pls forgive, still learning

---

<div class="post-metadata">

### Author: ![dan-potter](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/dan-potter/32/138_2.png) [@dan-potter](https://forums.powershell.org/u/dan-potter)
#### Post date: [June 6, 2016, 10:59am UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/10 "2016-06-06T10:59:13Z")

</div>

((get-aduser me -Properties memberof).memberof.trimstart(‘CN=’)|%{$\_.split(‘,’)[0]}) -join [char]9786

---

<div class="post-metadata">

### Author: ![rsmith7712](https://avatars.discourse-cdn.com/v4/letter/r/e95f7d/32.png) [@rsmith7712](https://forums.powershell.org/u/rsmith7712)
#### Post date: [June 6, 2016, 11:26am UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/11 "2016-06-06T11:26:33Z")

</div>

Dan - Where would that line go? At the end of Ln:76 or after the -Filter and before the -Properties on Ln:58?

---

<div class="post-metadata">

### Author: ![dan-potter](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/dan-potter/32/138_2.png) [@dan-potter](https://forums.powershell.org/u/dan-potter)
#### Post date: [June 6, 2016, 12:19pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/12 "2016-06-06T12:19:48Z")

</div>

That was an example of how to turn the memberof attribute into a string without using get-adgroup.

I suspect you are feeding something to get-adgroup that can’t be enumerated under the current domain.

---

<div class="post-metadata">

### Author: ![dan-potter](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/dan-potter/32/138_2.png) [@dan-potter](https://forums.powershell.org/u/dan-potter)
#### Post date: [June 6, 2016, 12:31pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/13 "2016-06-06T12:31:45Z")

</div>

btw, the correct comparison operators for your filter are gt and lt.

```
((get-aduser me -Properties lastlogondate).lastlogondate -gt [datetime]::today)
```

---

<div class="post-metadata">

### Author: ![dan-potter](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/dan-potter/32/138_2.png) [@dan-potter](https://forums.powershell.org/u/dan-potter)
#### Post date: [June 6, 2016, 1:26pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/14 "2016-06-06T13:26:03Z")

</div>

Here you go, play with this. Still room for improvement.

```
function get-oldpeeps {
	
	param (
		
		[Parameter(Mandatory = $True)]
		[string]$searchbase,
		[Parameter(Mandatory = $False)]
		[Int]$xdays,
		[Parameter(Mandatory = $False)]
		[Switch]$allusers
		
	)
	
	$today = get-date -uformat "%Y/%m/%d"
	if ($xdays) { $age = (get-date).AddDays(- $xdays) } else { $age = (get-date).AddDays(-365) }
	$expire = (get-date).AddDays(-1)
	$ParkingOU = "OU=30Days, OU=Disabled Accounts, OU=Domain Services, DC=Domain, DC=com"
	
	#use a switch statement so you don't have to continuously comment sections of code. 
	
	switch ($searchbase) {
		
		MIT{ $ou = "OU=MIT, OU=Service Accounts, OU=Domain Services, DC=Domain, DC=com" }
		Laptop{ $ou = "OU=Laptop, OU=IS, OU=Corporate Computers, DC=Domain, DC=com" }
		Remote{ $ou = "OU=Remote Accounts, DC=Domain, DC=com" }
		All{ $ou = "DC=Domain, DC=com" }
		
	}
	
	#This is called a here string. Play with it. Easier to code without losing track of qoutes and plus's
	
	$userDesc = @"
Disabled Inactive $today Moved From OU $SearchBase
"@
	
	if ($allusers) {
		Get-ADUser -SearchBase $ou -Filter * -Properties DisplayName, MemberOf | % {
			
			[PSCustomObject]@{
				UserName = $_.DisplayName
				Groups = ($_.MemberOf | Get-ADGroup | Select -ExpandProperty Name) -join ","
			}
			
		}
		
		#dont hardcode export file into scripts. return info from function then | Export-Csv C:\ADUser_GroupMembership_Rpt.csv -NTI
		
	} else {
		
		$Users = Get-ADUser -SearchBase $ou -Properties memberof, PasswordNeverExpires, WhenCreated, PasswordLastSet, LastLogonDate -Filter {
			(LastLogonDate -gt $age)
			-AND (PasswordLastSet -gt $age)
			-AND (Enabled -eq $True)
			-AND (PasswordNeverExpires -eq $false)
			-AND (WhenCreated -le $age)
		}
		
		#revise filter whencreated less than 90 could not result in users lastlogondate being greater than 90?
		
		$users | ForEach-Object {
			
			Set-ADUser $_ -AccountExpirationDate $expire -Description $userdesc -WhatIf
			Move-ADObject $_ -TargetPath $ParkingOU -WhatIf
			$_ | select *, @{ l = 'Groups'; e = { (($_.memberof | Get-ADGroup).Name) -join '; ' } }
		}
		
	}
	
	
}
```

---

<div class="post-metadata">

### Author: ![dan-potter](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/dan-potter/32/138_2.png) [@dan-potter](https://forums.powershell.org/u/dan-potter)
#### Post date: [June 6, 2016, 3:01pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/15 "2016-06-06T15:01:25Z")

</div>

Looks like I started with the switch idea + the searchbase param and didn’t implement it correctly down the line. Searchbase not mandatory. No need to define ou with AllUsers switch.

```
function get-oldpeeps {
	
	param (
		
		[Parameter(Mandatory = $False)]
		[string]$searchbase,
		[Parameter(Mandatory = $False)]
		[Int]$xdays,
		[Parameter(Mandatory = $False)]
		[Switch]$allusers
		
	)
	

	$today = get-date -uformat "%Y/%m/%d"
	if ($xdays) { $age = (get-date).AddDays(- $xdays) } else { $age = (get-date).AddDays(-365) }
	$expire = (get-date).AddDays(-1)
	$ParkingOU = "OU=30Days, OU=Disabled Accounts, OU=Domain Services, DC=Domain, DC=com"
	
	#use a switch statement so you don't have to continuously comment sections of code. 
	
	switch ($searchbase) {
		
		MIT{ $ou = "OU=MIT, OU=Service Accounts, OU=Domain Services, DC=Domain, DC=com" }
		Laptop{ $ou = "OU=Laptop, OU=IS, OU=Corporate Computers, DC=Domain, DC=com" }
		Remote{ $ou = "OU=Remote Accounts, DC=Domain, DC=com" }
	        ''{$ou = 'dc=domain,dc=com'}
		
	}
	
	#This is called a here string. Play with it. Easier to code without losing track of qoutes and plus's
	
	$userDesc = @"
Disabled Inactive $today Moved From OU $ou
"@
	
	if ($allusers) {
		Get-ADUser -Filter * -Properties DisplayName, MemberOf | % {
			
			[PSCustomObject]@{
				UserName = $_.DisplayName
				Groups = ($_.MemberOf | Get-ADGroup | Select -ExpandProperty Name) -join ","
			}
			
		}
		
		#dont hardcode export file into scripts. return info from function then | Export-Csv C:\ADUser_GroupMembership_Rpt.csv -NTI
		
	} else {
		
		$Users = Get-ADUser -SearchBase $ou -Properties memberof, PasswordNeverExpires, WhenCreated, PasswordLastSet, LastLogonDate -Filter {
			(LastLogonDate -gt $age)
			-AND (PasswordLastSet -gt $age)
			-AND (Enabled -eq $True)
			-AND (PasswordNeverExpires -eq $false)
			-AND (WhenCreated -le $age)
		}
		
		#revise filter whencreated less than 90 could not result in users lastlogondate being greater than 90?
		
		$users | ForEach-Object {
			
			Set-ADUser $_ -AccountExpirationDate $expire -Description $userdesc -WhatIf
			Move-ADObject $_ -TargetPath $ParkingOU -WhatIf
			$_ | select *, @{ l = 'Groups'; e = { (($_.memberof | Get-ADGroup).Name) -join '; ' } }
		}
		
	}
	
	
}
```

---

<div class="post-metadata">

### Author: ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)
#### Post date: [May 16, 2024, 8:41pm UTC](https://forums.powershell.org/t/request-help-inactive-aduser-query-and-manipulation-encountering-issues/6556/16 "2024-05-16T20:41:06Z")

</div>


