Why use this template?
Use this free PowerShell script when you need to find enabled users without recent logon. It is generated locally and can be reviewed before you run it yourself in your own PowerShell session.
The template uses ActiveDirectory and requires Directory read access. Output: CSV report. Level: Intermediate. Action: Read-only. Risk: Low.
Review before running
The script is generated in your browser. Read it before you run it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.
Generate the script
- Open the template in the PowerShell Builder.
- Enter the requested values and review the module, permissions, output and risk.
- Generate the script, read it carefully, and test it outside production before use.
The script is generated locally in your browser. Nothing needs to be uploaded to Opselith.
Generate Export inactive AD users →How to use this result
Use this report to build a review queue of enabled Active Directory users whose replicated logon date is blank or older than the threshold you choose.
When this helps
- Prepare an inactive-account review before disabling or removing old user accounts.
- Create a CSV of enabled users that have not shown recent replicated logon activity.
- Repeat the same inactivity threshold over time to compare the candidate population.
How to read the result
- The script calculates a cutoff date from the number of inactive days you enter and includes enabled users with a blank or older LastLogonDate.
- LastLogonDate is based on Active Directory lastLogonTimestamp replication and is intentionally approximate, not an exact last interactive sign-in time.
Things to check
- A stale or blank LastLogonDate is a review signal, not proof that an account can safely be disabled or deleted.
- Check service accounts, infrequent users, disconnected scenarios and other known exceptions with ownership evidence before changing an account.
What to do next: Review the oldest candidates with the account owner or HR source, then use a separate approved process for any disable or removal action.
Related tasks
Official references