{"id":189,"date":"2011-10-21T15:28:09","date_gmt":"2011-10-21T13:28:09","guid":{"rendered":"http:\/\/rexxer.kharkov.ru\/?p=189"},"modified":"2011-10-21T15:28:09","modified_gmt":"2011-10-21T13:28:09","slug":"powershell-proverka-neaktivnyx-akkauntov","status":"publish","type":"post","link":"https:\/\/dety.net.ua\/?p=189","title":{"rendered":"Powershell + \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043d\u0435\u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0430\u043a\u043a\u0430\u0443\u043d\u0442\u043e\u0432"},"content":{"rendered":"<p>\u0413\u0434\u0435-\u0442\u043e \u043d\u0430\u0448\u0435\u043b \u0441\u043a\u0440\u0438\u043f\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0438 \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043d\u0435\u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0430\u043a\u043a\u0430\u0443\u043d\u0442\u043e\u0432 &#8211; \u043f\u0435\u0440\u0435\u0434\u0435\u043b\u0430\u043b \u043f\u043e\u0434 \u0441\u0435\u0431\u044f + \u0434\u043e\u0431\u0430\u0432\u0438\u043b \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043f\u043e \u043f\u043e\u0447\u0442\u0435 (\u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u0430\u043a\u043a\u0430\u0443\u043d\u0442\u043e\u0432 \u0437\u0430\u0434\u0438\u0441\u044d\u0439\u0431\u043b\u0435\u043d\u043e).<\/p>\n<blockquote><p># Read the input parameters $Subtree and $NbDays<\/p>\n<p>param([string] $Subtree, [string] $NbDays)<\/p>\n<p># Get the current date<\/p>\n<p>$currentDate = [System.DateTime]::Now<\/p>\n<p># Convert the local time to UTC format because all dates are expressed in UTC (GMT) format in Active Directory<\/p>\n<p>$currentDateUtc = $currentDate.ToUniversalTime()<\/p>\n<p># Set the LDAP URL to the container DN specified on the command line<\/p>\n<p>#$LdapURL = &#8220;LDAP:\/\/&#8221; + $Subtree<br \/>\n$LdapURL = &#8220;LDAP:\/\/192.168.100.2:389\/dc=my,dc=domain,dc=com&#8221;<br \/>\n$NbDays = 90<br \/>\n# Initialize a DirectorySearcher object<\/p>\n<p>$searcher = New-Object System.DirectoryServices.DirectorySearcher([ADSI]$LdapURL)<\/p>\n<p># Set the attributes that you want to be returned from AD<\/p>\n<p>$searcher.PropertiesToLoad.Add(&#8220;displayName&#8221;) &gt;$null<\/p>\n<p>$searcher.PropertiesToLoad.Add(&#8220;sAMAccountName&#8221;) &gt;$null<\/p>\n<p>$searcher.PropertiesToLoad.Add(&#8220;lastLogonTimeStamp&#8221;) &gt;$null<\/p>\n<p># Calculate the time stamp in Large Integer\/Interval format using the $NbDays specified on the command line<\/p>\n<p>$lastLogonTimeStampLimit = $currentDateUtc.AddDays(- $NbDays)<\/p>\n<p>$lastLogonIntervalLimit = $lastLogonTimeStampLimit.ToFileTime()<\/p>\n<p>#Write-Host &#8220;Looking for all users that have not logged on since &#8220;$lastLogonTimeStampLimit&#8221; (&#8220;$lastLogonIntervalLimit&#8221;)&#8221;<br \/>\n$body = &#8220;Looking for all users that have not logged on since $lastLogonTimeStampLimit&#8221;<\/p>\n<p>$searcher.Filter = &#8220;(&amp;(objectCategory=person)(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(lastLogonTimeStamp&lt;=&#8221; + $lastLogonIntervalLimit + &#8220;))&#8221;<\/p>\n<p># Run the LDAP Search request against AD<\/p>\n<p>$users = $searcher.FindAll()<\/p>\n<p>if ($users.Count -eq 0)<\/p>\n<p>{<\/p>\n<p>Write-Host &#8221;\u00a0 No account needs to be disabled.\u201d<\/p>\n<p>}<\/p>\n<p>else<\/p>\n<p>{<\/p>\n<p>foreach ($user in $users)<\/p>\n<p>{<\/p>\n<p># Read the user properties<\/p>\n<p>[string]$adsPath = $user.Properties.adspath<\/p>\n<p>[string]$displayName = $user.Properties.displayname<\/p>\n<p>[string]$samAccountName = $user.Properties.samaccountname<\/p>\n<p>[string]$lastLogonInterval = $user.Properties.lastlogontimestamp<\/p>\n<p># Disable the user<\/p>\n<p>#$account=[ADSI]$adsPath<\/p>\n<p>#$account.psbase.invokeset(&#8220;AccountDisabled&#8221;, &#8220;True&#8221;)<\/p>\n<p>#$account.setinfo()<\/p>\n<p># Convert the date and time to the local time zone<\/p>\n<p>$lastLogon = [System.DateTime]::FromFileTime($lastLogonInterval)<\/p>\n<p>#\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Write-Host &#8221;\u00a0 Disabled user &#8220;$displayName&#8221; (&#8220;$samAccountName&#8221;) who last logged on &#8220;$lastLogon&#8221; (&#8220;$lastLogonInterval&#8221;)&#8221;<br \/>\n#\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Write-Host &#8221;\u00a0 &#8212;&gt; &#8220;$displayName&#8221; (&#8220;$samAccountName&#8221;) who last logged on &#8220;$lastLogon&#8221;&#8221;<br \/>\n$body = $body + &#8221; $displayName ($samAccountName) who last logged on $lastLogon &#8221; | out-string<\/p>\n<p>}<\/p>\n<p>}<\/p>\n<p>### Send mail<br \/>\n$FromAddress = &#8220;admin@domain.com&#8221;<br \/>\n$ToAddress = &#8220;ya@domain.com&#8221;<br \/>\n$MessageSubject = &#8220;Inactive Accounts Report&#8221;<br \/>\n$SendingServer = &#8220;MailServer&#8221;<\/p>\n<p>$SMTPMessage = New-Object System.Net.Mail.MailMessage $FromAddress,$ToAddress,$MessageSubject,$body<br \/>\n$SMTPClient = New-Object System.Net.Mail.SMTPClient $SendingServer<br \/>\n$SMTPClient.Send($SMTPMessage)<\/p><\/blockquote>\n<p>\u0427\u0442\u043e\u0431\u044b \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c \u0438\u0437 \u043f\u043b\u0430\u043d\u0438\u0440\u043e\u0432\u0449\u0438\u043a\u0430 \u0441\u043a\u0440\u0438\u043f\u0442, \u043d\u0443\u0436\u043d\u043e \u0443\u043a\u0430\u0437\u0430\u0442\u044c \u0438\u043c\u044f \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b:<\/p>\n<blockquote><p>C:WindowsSystem32WindowsPowerShellv1.0powershell.exe<\/p><\/blockquote>\n<p>\u0438 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u044b \u043a\u043e\u043c\u0430\u043d\u0434\u043d\u043e\u0439 \u0441\u0442\u0440\u043e\u043a\u0438:<\/p>\n<blockquote><p>-command &#8220;&amp; &#8216;C:Backuplast_logon.ps1&#8217; &#8220;<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>\u0413\u0434\u0435-\u0442\u043e \u043d\u0430\u0448\u0435\u043b \u0441\u043a\u0440\u0438\u043f\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0438 \u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043d\u0435\u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0430\u043a\u043a\u0430\u0443\u043d\u0442\u043e\u0432 &#8211; \u043f\u0435\u0440\u0435\u0434\u0435\u043b\u0430\u043b \u043f\u043e\u0434 \u0441\u0435\u0431\u044f + \u0434\u043e\u0431\u0430\u0432\u0438\u043b \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u043f\u043e \u043f\u043e\u0447\u0442\u0435 (\u043e\u0442\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u0430\u043a\u043a\u0430\u0443\u043d\u0442\u043e\u0432 \u0437\u0430\u0434\u0438\u0441\u044d\u0439\u0431\u043b\u0435\u043d\u043e). # Read the input parameters $Subtree and $NbDays param([string] $Subtree, [string] $NbDays) # Get the current date $currentDate = [System.DateTime]::Now # Convert the local time to UTC format because all dates are expressed in UTC [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,12],"tags":[],"class_list":["post-189","post","type-post","status-publish","format-standard","hentry","category-novosti","category-windows"],"_links":{"self":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=189"}],"version-history":[{"count":0,"href":"https:\/\/dety.net.ua\/index.php?rest_route=\/wp\/v2\/posts\/189\/revisions"}],"wp:attachment":[{"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dety.net.ua\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}