Active Directory Cleaner

1. Introduction

The Active Directory Cleaner enables you to configure alerts and remedial actions for inactive users. It can be configured while adding a domain or modifying an existing domain.

2. Permissions Requirement

  • The user through which the Active Directory component is added should be assigned permissions as follows:

    • The minimum permission is Read to allow the user to see Active Directory Cleaner Reports and get notifications.

    • By having Full Control permission, Active Directory Cleaner will be able to perform actions on inactive accounts for example, Set Password, Move to OU, Disable and Delete.

3. Configuring the Active Directory Cleaner

The Active Directory Cleaner option is found in Advanced Domain Configuration.

To display the Advanced Domain Configuration screen:

  • Click the Settings icon

  • Click on the Active Directory Component and the following screen will be displayed:

Graphical user interface, application

Description automatically generated
Active Directory Settings

  • Click Properties (found on the right-hand side of the screen)

The Domain Credentials dialog box is displayed:

Graphical user interface, application

Description automatically generated
Domain Credentials
  • Choose Advanced Domain Configuration (from the left-hand list of options) and the Advanced Domain Configuration dialog box is displayed:

Graphical user interface, application, table

Description automatically generated
Advanced Domain Configuration

  • Check the Active Directory Cleaner option to enable it

  • Once enabled, click the adjacent icon to open the Active Directory Cleaner settings dialog box.

3.1 Active Directory Cleaner Settings

Here you can configure settings to send notifications to inactive accounts and set up cleanup actions.

Graphical user interface, application

Description automatically generated
Active Directory Cleaner Settings

  • Click the Advanced Server Settings link (top right of the dialog box) to select the domain controllers for which you want to enable the Active Directory Cleaner:

Graphical user interface, text, application, email

Description automatically generated
Select Domain Controllers

  • Check the domain controllers where you want to enable the cleanup feature. Uncheck the domain controllers where this feature is not required.

  • Click OK to apply the settings. It takes you back to the Active Directory Cleaner Settings dialog box.

  • Organizational Unit: You need to select the Organizational Units (OU’s) for which the alerts will be generated. You can select All to select all Organizational Units.

image-20260929-083420.png
Option to select Organizational Unit

To select specific Organizational Units, click the icon. The Organizational Unit Selection dialog box is displayed:

Graphical user interface, text, application

Description automatically generated
Select the Organizational Units

  • Check the boxes of Organizational Units to enable the cleanup for them. Uncheck the OUs where this feature is not required.

  • Click OK to apply the settings.

It takes you back to the Active Directory Cleaner Settings dialog box:

Graphical user interface, application

Description automatically generated
Active Directory Cleaner Settings
  • Set Time: Select the time at which either the action is to be performed, or the notification email sent.

  • Notification Settings: This section lets you configure the notification settings. It contains the following options.

    • Sender's Email Account: Select the email account from which you want to send the alert emails. The added email accounts of Message Delivery Settings will be listed here in the drop-down menu. You can also click the icon to add another account.

    • Recipient Email Address: Enter the email addresses of the recipients to which you want to send the notifications about the inactive accounts, their inactive period, and actions taken on inactive accounts.

  • Action Settings: Here, you can configure the action settings.

    • Select Action Template: An Action Template allows you to perform actions such as random password setting, disabling accounts, moving accounts to a particular OU, and deleting accounts, after a specified number of days. You can also set notifications to inform the Administrator when the application automatically performs these actions.

      See Section 2.2 below for more information on how to create, modify and delete Action Templates.

  • Send Daily Reports: Check this option to send daily reports for inactive accounts. With this option checked, the following settings become available:

    • Select Account Inactivity Period: Enter the number of days after which an account will be termed as an Inactive Account.

    • Select Email Template: Specify the email template which will be used when sending the alert email to the recipients. You can use the default email template, modify it, or create a new custom one. See section 1.1 for further information about email templates.

    • Select Account Status: This can be All, Enabled Only or Disabled Only

3.2 Action Templates

3.2.1 To Create a new Action Template:

  • Click the icon (within the Action Settings area of the Active Directory Cleaner Settings dialog box) to add a new action template.

The following dialog box is displayed:

image-20260929-085751.png
Creating an Action Template
  • Follow the steps below to create a new template:

  • Select Action Template: Select New in the drop-down menu.
    Type a name for the Action Template in the Template Name text box.

  • Select Account Status: Select from All, Enabled only or Disabled only

  • Account Type: Select the account types to apply the action to:

    • User/Computer: Select this to apply the action on both user and computer accounts.

    • User Only: Select this to apply the action only on user accounts.

    • Computer Only: Select this to apply the action only on computer accounts.

  • Exclude Accounts: Click the icon to add accounts to exclude.

  • Follow the steps below to choose which accounts to exclude:

Graphical user interface, application

Description automatically generated
Excluding the Users from AD Cleanup

    • All user and computer accounts are listed in the left column under Select Account(s).

    • Administrator is by default excluded from the cleanup.

    • From the left column, select the accounts to be excluded.

  • Click the button to add them to the Selected Accounts column.

  • Click the button to remove the selected account from the exclusion list.

  • Click OK to apply the settings.

image-20260929-090115.png
Creating an Action Template
  • From the Create or Modify Action Template dialog box:

    • Select any of the following actions as required. You need to specify the number of days for an inactivity period for each option:

      • Set Random Password After: Select this option to apply a random password to the inactive account.

      • Disable Account After: Select this option to disable the inactive account.

      • Move to OU After: Select this option to move the inactive account to an Organizational Unit. You can select the Organizational Unit where the account will be moved to.

      • Delete Account After: Select this option to delete the inactive accounts.

NOTE: For each action, you can select the Notify Administrator option to send a notification to the Administrator about the action taken on an inactive account.

  • Click OK to return to the Active Directory Cleaner dialog box:

Graphical user interface, application

Description automatically generated
Active Directory Cleaner

To Modify an Action Template:

Graphical user interface, application

Description automatically generated
Modify an Action Template
  • Click the icon to icon (within the Action Settings area of the Active Directory Cleaner Settings dialog box) to modify the selected action template

You can change the actions to be taken on inactive accounts and set them for users, computers, or both. However, you cannot change the template name.

To Delete an Action Template:

  • Click the icon (within the Action Settings area of the Active Directory Cleaner Settings dialog box) to remove the selected template.

3.3 Email Templates

3.3.1 To Create an Email Template:

Graphical user interface, application

Description automatically generated
Active Directory Cleaner

  • Click the icon (next to the Select Email Template option) to add a new email template. The following dialog box will be displayed:

image-20260929-091308.png
Creating a New Alert Email Template
  • Follow the steps below to add a new email template:

    • Provide a name for the template.

    • The Column Name section lets you select which columns you want to be added to the email.

    • Check the boxes of information to be included and uncheck the boxes to be excluded.

    • Click OK to add the template.

3.3.2 To Modify an Email Template:

  • Select a template from the drop-down menu (from the Active Directory Cleaner Settings dialog box) and click the icon to modify it. You can change the columns to be included in the email template by checking or unchecking the boxes.

3.3.3 To Delete an Email Template:

  • Select a template from the drop-down menu (from the Active Directory Cleaner Settings dialog box) and click the icon to remove the email template.

The following is a screenshot of the sample details filled in Active Directory Cleaner Settings:

Graphical user interface, application

Description automatically generated
Sample Details
  • Click Apply to apply the Active Directory Cleaner Settings.

The following message box appears to confirm the successful configuration:

image-20260929-091617.png
Successful Configuration of the Alert
  • Click OK.