Find Disabled Users in Active Directory using Perl

A Script to Find Disabled Users in Active Directory:  Here a very simple Perl script that will locate disabled users in your Active Directory. To see the VBscript version of this script, click here, and click here to see the PowerShell version. The script uses our typical ADODB search code to search AD. The key, as always is the search filter. In this case, we're searching for disabled users. Unfortunately, there is no attribute that holds the enabled/disabled status of the user. Suprising. It turns out that the disabled status is stored as a bit in the useraccountcontrol attribute. This attribute contains a number that is made up of binary bits, each having a different meaning. You can look up the meaning of each bit on MSDN at

Anyway, the second bit (2) is the account disabled bit.

Microsoft has given us a way to make a search filter that can search against a bit in an attribute, called LDAP matching rules. They are specified by OID's (long ugly numbers). According to the Search Filter Syntax page (, 1.2.840.113556.1.4.803 is equivelant to a bitwise AND.

So here's the script. The search filter does a bitwise AND of the contents of the useraccountcontrol attribute and the number 2 (remember the 2 bit means disabled). So the script searches for everyone in your AD that has the 2 bit set (disabled users).

use Win32::OLE;
$connection = Win32::OLE->new("ADODB.Connection");
$connection->{Provider} = "ADsDSOObject";
$connection->Open("ADSI Provider");
$command->{Properties}->{'Page Size'}=1000;
$rs = Win32::OLE->new("ADODB.RecordSet");
until ($rs->EOF){
print "$displayName\n";


Post a Comment

Related Posts Plugin for WordPress, Blogger...