1.在ADUC中使用“创建自定义筛选器”-》高级-》LDAP查询,中输入以下字查询语句:
(&(objectClass=User)(userAccountControl:1.2.840.113556.1.4.803:=2))
2.在Power Shell中复制输入以下全部,这样在C盘下就有一个disableuser.csv文件产生:
$adobjroot = [adsi]''
$objdisabsearcher = New-Object System.DirectoryServices.DirectorySearcher($adobjroot)
$objdisabsearcher.filter = "(&(objectCategory=person)(objectClass=user)(userAccountControl:1.2.840.113556.1.4.803:=2))"
$resultdisabaccn = $objdisabsearcher.findall() | sort path
$resultdisabaccn | ft -wrap path > c:\disableuser.csv
3.以下Power Shell可以显示disable的AD账户:
get-Mailbox | where { $_.UserAccountControl -match "AccountDisabled"}
4.以下Powershell 用于禁用邮箱:
disable-mailbox -identity user@domain.com