ADMIN WORKFLOW / FREEFREE WORKFLOW

Active Directory Cleanup Review

Run a bounded read-only Active Directory hygiene review across users, computers, groups and domain policy.

read-only8 guided stepsActive Directory
WHEN TO USE IT

Use this workflow when the job is clear and bounded.

This guide is designed for a single administrative task rather than a broad tenant-wide assessment. It keeps discovery, preparation, any manual change and final verification separate so you can review each step before moving on.

Consolidated local summary of the selected cleanup checks
RUNBOOK

The workflow, in order.

Opselith does not execute these steps against your environment. Script steps open a reviewed Opselith template; change steps remain explicit so nothing is hidden behind a browser action.

  1. 01 · SCRIPT

    Find inactive enabled users

    Review enabled accounts without recent logon before making any cleanup decision.

    Open Export inactive AD users →
  2. 02 · SCRIPT

    Export disabled users

    Inventory already-disabled users so stale lifecycle records are visible.

    Open Export disabled AD users →
  3. 03 · SCRIPT

    Find stale computers

    Identify enabled computers that have not logged on recently.

    Open Find stale AD computers →
  4. 04 · SCRIPT

    Find disabled computers

    Review disabled computer accounts separately from stale enabled devices.

    Open Find disabled AD computers →
  5. 05 · SCRIPT

    Find empty groups

    Locate groups with no direct members for ownership and purpose review.

    Open Find empty AD groups →
  6. 06 · SCRIPT

    Export domain password policy

    Capture the current domain password and lockout policy as context for the hygiene review.

    Open Export AD domain password policy →
  7. 07 · SCRIPT

    Review locked-out users

    Check current lockouts so transient incidents are not confused with stale identities.

    Open Find locked-out AD users →
  8. 08 · REVIEW

    Review findings before cleanup

    Classify findings in your change process. This Free workflow deliberately performs no deletion, disable or membership change.

PRIVACY & CONTROL

Your tenant stays outside Opselith.

No tenant connection

The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.

Local progress only

Completed workflow step IDs can be stored in your browser. Identity values, tickets, usernames, domains and generated output are not part of that progress record.

Manual changes stay manual

Where no suitable reviewed script exists, the guide labels the action as a manual change rather than pretending the website performed it.

TRUST / EVIDENCE

Recorded trust facts, not a certification.

Opselith separates metadata review, static QA, analyzer evidence and runtime evidence. A missing runtime result or a Pending analyzer state is shown as-is rather than converted into a pass claim.

Static QAPassed

Workflow catalog, ordered runbook, local-progress and manual-change boundary QA.

PSScriptAnalyzerNot applicable

A guided workflow is not itself a PowerShell artifact.

Runtime evidenceNot yet recorded

No accepted runtime result is recorded for this workflow yet.

Execution boundaryRead-only

browser-guided-runbook · no website tenant connection · tenant output stays outside Opselith.

Last reviewed28 Aug 2026

Trust metadata reviewed for the current 3.0 development contract.

Referenced scripts7

7 referenced scripts · 7 analyzer Passed · 0 Pending

Pending and Not yet recorded are evidence states, not failures. Review the generated script or runbook and validate it in your own environment before production use.

RELATED POWERSHELL

Scripts used by this workflow.

BEFORE YOU CLOSE THE JOB

Verify in the authoritative admin tools.

Use the final verification step to confirm the resulting account, membership, licensing or service state in the relevant Microsoft administration portal or Active Directory tooling. Opselith is a runbook and script-generation layer, not the system of record.