Searching for UserAccountControl settings that aren't set.

Discussion in 'Scripting' started by djmulls, Feb 2, 2011.

  1. djmulls

    djmulls Guest

    Hi guys,

    I have been asked to find all accounts in a resource domain that DON'T
    have the 'Password never expires' and 'User must change password at
    next logon' set. Accounts with these settings are giving us grief with
    the rollout of a new mail app.

    Now searching for accounts with those options is easy enough, I just
    use 65336 and I get all 'Password never expires' however I can't
    figure out how to get both of the above two options in a script and
    still get every combination of other setting. For example we have a
    lot of disabled accounts, but I still need to know if they have the
    above two options ticked.

    We are running a 2003 Native Mode domain and user accounts are all
    over the place. So we can't just point this at a single OU.

    I am scratching my head over this one so any help would be much
    djmulls, Feb 2, 2011
  djmulls


    Apr 19, 2011
    Likes Received:
    brain007, Jun 21, 2011
