Why use this template?
Use this Pro PowerShell script when you need to find enabled user accounts with passwordneverexpires enabled. It can be previewed in the Builder; Pro access is required to generate it for your own environment.
The template uses ActiveDirectory and requires Directory read access. Output: CSV report. Level: Intermediate. Action: Read-only. Risk: Low.
Review before running
The script remains preview-only until Pro access is enabled. Review it before running it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.
Preview the script
- Open the template in the PowerShell Builder.
- Review the purpose, requirements, permissions, output and risk.
- Activate Pro when you are ready to generate the full script, then test it outside production.
Pro templates remain previewable before purchase or activation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.Preview Find AD passwords set to never expire →
How to use this result
Use this report to find enabled Active Directory users whose PasswordNeverExpires account flag is currently set.
When this helps
- Review password-expiration exceptions during an identity or security hygiene check.
- Create a CSV of enabled accounts that are excluded from normal password expiration.
- Compare exceptions with approved service-account or break-glass documentation.
How to read the result
- Each result is an enabled user where Active Directory reports PasswordNeverExpires as true.
- The flag tells you the configured account setting; it does not prove that the exception is unsafe or unnecessary in your environment.
Things to check
- Service accounts and other controlled identities can have documented reasons for different password handling. Review the owner and authentication design before changing anything.
- This script is read-only. Removing PasswordNeverExpires can affect sign-in behavior and should be handled through a separate approved change process.
What to do next: Match each exception to an owner and documented reason, then review your domain password policy before planning any account changes.
Related tasks
Official references