Active Directory Cleanup & Optimization

πŸ” 1. Assess & Inventory First (Don’t Delete Yet)

Start by understanding what you actually have.

What to collect:

  • All user accounts
  • Computer accounts
  • Groups (especially nested ones)
  • Domain Controllers
  • GPOs (Group Policy Objects)
  • OU structure

Tools:

  • Native tools like Active Directory Users and Computers
  • PowerShell (essential for reporting)
  • Optional: PingCastle (great for quick health/security insights)

πŸ‘‰ Focus on reporting only at this stageβ€”no changes.


🧹 2. Identify Stale & Unused Objects

This is usually the biggest win.

Look for:

  • Users not logged in for 90–180+ days
  • Disabled accounts that were never deleted
  • Computer accounts not active (old machines)
  • Service accounts (⚠️ handle carefully)

Example PowerShell:

Search-ADAccount -AccountInactive -UsersOnly -TimeSpan 180.00:00:00

πŸ‘‰ Move these to a β€œQuarantine OU” instead of deleting immediately.


πŸ” 3. Clean Up Groups (Huge Risk Area)

Over 10 years, group sprawl becomes a nightmare.

Actions:

  • Identify empty groups
  • Find duplicate groups
  • Review nested groups
  • Validate privileged groups (Domain Admins, etc.)

πŸ‘‰ Document before changing anything.


πŸ–₯️ 4. Review Domain Controllers & Replication

Check:

  • Old/decommissioned DCs still in metadata
  • Replication health
  • FSMO roles

Tools:

  • dcdiag
  • repadmin

πŸ“œ 5. GPO Cleanup (Often Forgotten)

Over time, GPOs pile up and conflict.

Look for:

  • Unlinked GPOs
  • Duplicate policies
  • Legacy settings (XP/2003 era)

Tool:

  • Group Policy Management Console

πŸ—‚οΈ 6. OU Structure Review

Ask:

  • Does the OU design still reflect your organization?
  • Are permissions delegated properly?

πŸ‘‰ Avoid overcomplicated nesting.


πŸ”‘ 7. Service Accounts Audit (Critical)

These are dangerous to touch blindly.

  • Identify accounts used by apps/services
  • Check:
    • Password expiration settings
    • SPNs
    • Hardcoded credentials

πŸ‘‰ Consider moving toward Managed Service Accounts (gMSA).


πŸ›‘οΈ 8. Security Baseline Check

Run a security scan:

  • Weak password policies
  • Kerberos issues
  • Delegation risks

πŸ‘‰ Tools like PingCastle or Microsoft Defender for Identity help here.


⚠️ 9. Implement a Safe Cleanup Process

Never delete directly.

Best practice:

  1. Move object β†’ Quarantine OU
  2. Disable it
  3. Wait 30–60 days
  4. Monitor impact
  5. Then delete

πŸ”„ 10. Put Maintenance in Place (Most Important)

After cleanup, avoid repeating the problem.

  • Monthly stale account review
  • Automated scripts (PowerShell)
  • Joiner/Mover/Leaver process
  • Regular AD health checks

πŸš€ Suggested Starting Point (Simple Plan)

If you want a clean starting sequence:

  1. Export all users & computers
  2. Identify inactive >180 days
  3. Create Quarantine OU
  4. Move + disable inactive objects
  5. Wait & monitor
  6. Then proceed to groups and GPOs

Leave a Reply

Your email address will not be published. Required fields are marked *