Chris Klepeis Chris Klepeis - 11 months ago 92
SQL Question

SQL Query for Disabled Active Directory Accounts

I need to query AD to determine if a users account is disabled.

Using a similar query used in the answers here

FROM ''LDAP://DC=MyDC,DC=com,DC=uk''
WHERE objectCategory = ''Person''
AND objectClass = ''user'')

I believe to determine if an account is disabled I have to use the userAccountControl field somehow. I've tried several things but they don't seem to be working:

WHERE userAccountControl & 2 <> 0

Answer Source

Apparently it did work... this would be an ID-10-T :p