Probably could get some of this out of a Quest Reporter type tool. Personally I’d just write a bunch of small .net apps (or use adfind if appropriate) that pump out csv files. Then I import them into a SQL database and make my queries and voila.

 

Thanks,

Brian Desmond

[EMAIL PROTECTED]

 

c - 312.731.3132

 

From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Merry, Joel (US - Philadelphia)
Sent: Tuesday, November 14, 2006 4:45 PM
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] AD Audit/Compliance Tool

 

Hi All ... I'm looking for a tool that will query all of the domains in a single forest and show me expired accounts, accounts with passwords older than xx days, duplicate accounts (accounts with the same samaccountname in different domains), accounts with primary SMTP address of something other than @domain.com, @domain1.com, @domain2.com, etc.

 

I'm scripting most of it now, but it's a pain. Any suggestions?

 

Thanks,

Joel

 

 

This message (including any attachments) contains confidential information intended for a specific individual and purpose, and is protected by law. If you are not the intended recipient, you should delete this message and are hereby notified that any disclosure, copying, or distribution of this message, or the taking of any action based on it, is strictly prohibited.

Reply via email to