CertCities.com  -- The Ultimate Site for Certified IT Professionals
Keep on Top of the Latest Certification News: Subscribe to CertCities.com Newsletter Share share | bookmark | e-mail
 Microsoft®
 Cisco®
 Security
 Oracle®
 A+/Network+™
 Linux/Unix
 More Certs
 Newsletters
 Salary Surveys
 Forums
 News
 Exam Reviews
 Tips
 Columns
 Features
 PopQuiz
 RSS Feeds
 Press Releases
 Contributors
 About Us
 Search
 

Advanced Search
 Free Newsletter
  Sign-up for the #1 Weekly IT
Certification News
and Advice.
Subscribe to CertCities.com Free Weekly E-mail Newsletter
CertCities.com

See What's New on
Redmondmag.com!

Cover Story: IE8: Behind the 8 Ball

Tech-Ed: Let's (Third) Party!

A Secure Leap into the Cloud

Windows Mobile's New Moves

SQL Speed Secrets


CertCities.com
Let us know what you
think! E-mail us at:
ccfeedback@certcities.com


 
 
...Home ... Editorial ... Columns ..Column Story Friday: July 30, 2010
TechMentor Conferences


 Tip o'the Week  
Zubair      Alexander
Zubair Alexander


  • PRINTABLE FORMAT
  • E-MAIL STORY
  • POST YOUR COMMENTS
  • MORE COLUMNS
  •  Custom LDAP Query To Show Locked User Accounts
    How can I create a custom LDAP query that will allow me to determine locked user accounts in Windows Server 2003?
    by Zubair Alexander  
    9/12/2007 -- You can use the Saved Query feature in Active Directory Users and Computers. Here's the procedure:

    1. Go to ADUC and right-click on Saved Queries.
    2. Select New, Query.
    3. Type in the name and description of the query (e.g., Locked User Accounts) and then click on Define Query.
    4. In the Find box, select Custom Search and then click on the Advanced tab.
    5. Enter the following text for the LDAP query:
      (&(&(&(objectCategory=person)(objectClass=user)
      (lockoutTime:1.2.840.113556.1.4.804:=4294967295))))
    6. Click OK twice to close all windows.
    7. Simply highlight the "Locked User Accounts" query and press F5 to refresh. If you have any accounts that are locked, they will show up in the right-hand pane.

    If your query fails, it's most likely because you entered carriage returns in the LDAP query. The query does not contain any spaces or carriage returns.


    Zubair Alexander, MCSE, MCT, MCSA and Microsoft MVP is the founder of SeattlePro Enterprises, an IT training and consulting business. His experience covers a wide range of spectrum: trainer, consultant, systems administrator, security architect, network engineer, author, technical editor, college instructor and public speaker. Zubair holds more than 25 technical certifications and Bachelor of Science degrees in Aeronautics & Astronautics Engineering, Mathematics and Computer Information Systems. His Web site, www.techgalaxy.net, is dedicated to technical resources for IT professionals. Zubair may be reached at alexander@techgalaxy.net.

     


    More articles by Zubair Alexander:
  • FrontPage Server Extensions on 64-bit Windows Server 2008
  • Synching Outlook 2007 Contacts with SharePoint
  • Saving SharePoint Files to the Server
  • Moving, Deleting a File That's Always in Use

  • -- advertisement --


    There is 1 CertCities.com user Comments for “Custom LDAP Query To Show Locked User Accounts”
    Page 1 of 1
    2/6/08: Jakov Haimi from Finland says:How to create LDAP Query or VBS script, which lists all the groups and the members of a group in a specified domain, also in case if one of the member is a group.
    Your comment about: “Custom LDAP Query To Show Locked User Accounts”
    Name: (optional)
    Location: (optional)
    E-mail Address: (optional)
    Comment:
       

    top